From a67a2b18e02c6a46f11b5476cdd00b8c1d51fc18 Mon Sep 17 00:00:00 2001 From: divious1 Date: Fri, 22 Oct 2021 23:29:45 -0400 Subject: [PATCH] added check if detections are present or not --- .../doc_playbooks_page_markdown.j2 | 4 + docs/_pages/abuse.md | 4 +- docs/_pages/adversary_tactics.md | 56 +- docs/_pages/best_practices.md | 4 +- docs/_pages/cloud_security.md | 8 +- docs/_pages/detections.md | 715 +-- docs/_pages/lateral_movement.md | 2 +- docs/_pages/malware.md | 28 +- docs/_pages/playbooks.md | 2 +- docs/_pages/stories.md | 102 +- .../ransomware_investigate_and_contain.md | 21 + ...7-09-20-large_volume_of_dns_any_queries.md | 6 +- ...credential_dumping_through_lsass_access.md | 8 +- ...-03-detect_mimikatz_using_loaded_images.md | 8 +- ...6-access_lsass_memory_for_dump_creation.md | 8 +- ...9-12-06-create_remote_thread_into_lsass.md | 8 +- .../2019-12-10-creation_of_shadow_copy.md | 8 +- ...-01-22-dns_query_length_outliers_-_mltk.md | 8 +- ...-03-creation_of_lsass_dump_with_taskmgr.md | 8 +- .../2020-02-21-dump_lsass_via_comsvcs_dll.md | 8 +- ...interception_by_creation_of_program_exe.md | 10 +- ...2020-07-06-short_lived_windows_accounts.md | 8 +- .../2020-07-06-windows_event_log_cleared.md | 6 +- ...20-07-07-remote_desktop_network_traffic.md | 8 +- ...20-07-08-detect_new_local_admin_account.md | 8 +- ...-07-21-attempt_to_stop_security_service.md | 8 +- ...-detect_excessive_user_account_lockouts.md | 9 +- .../2020-07-21-detect_outbound_smb_traffic.md | 8 +- ...1-detect_outlook_exe_writing_a_zip_file.md | 6 +- ...f_cmd_exe_to_launch_script_interpreters.md | 6 +- ...ritten_outside_of_the_outlook_directory.md | 6 +- ...rs_sending_high_volume_traffic_to_hosts.md | 6 +- .../2020-07-21-excessive_dns_failures.md | 8 +- ...first_time_seen_running_windows_service.md | 6 +- ...g_files_and_directories_with_attrib_exe.md | 6 +- ...me_of_network_traffic_from_email_server.md | 8 +- ...shell_process_-_execution_policy_bypass.md | 6 +- ...th_invalid_credentials_from_the_same_ip.md | 9 +- .../2020-07-21-okta_account_lockout_events.md | 9 +- .../2020-07-21-okta_failed_sso_attempts.md | 9 +- ...1-okta_user_logins_from_multiple_cities.md | 9 +- ...7-21-overwriting_accessibility_binaries.md | 7 +- .../2020-07-21-protocol_or_port_mismatch.md | 8 +- ...07-21-remote_desktop_network_bruteforce.md | 8 +- ...emote_desktop_process_running_on_system.md | 8 +- ...21-sc_exe_manipulating_windows_services.md | 9 +- ...chtasks_scheduling_job_on_remote_system.md | 10 +- docs/_posts/2020-07-22-smb_traffic_spike.md | 8 +- .../2020-07-22-smb_traffic_spike_-_mltk.md | 8 +- ...-suspicious_email_attachment_extensions.md | 8 +- docs/_posts/2020-07-22-tor_traffic.md | 6 +- .../2020-07-22-unload_sysmon_filter_driver.md | 8 +- ...ance_modified_by_previously_unseen_user.md | 11 +- .../_posts/2020-08-11-detect_arp_poisoning.md | 7 +- ...igh_number_of_cloud_instances_destroyed.md | 11 +- ...high_number_of_cloud_instances_launched.md | 11 +- ...umber_of_cloud_infrastructure_api_calls.md | 11 +- ...umber_of_cloud_security_group_api_calls.md | 11 +- ...-detect_dump_lsass_memory_using_comsvcs.md | 8 +- ..._or_delete_windows_shares_using_net_exe.md | 6 +- ...tivity_related_to_pass_the_hash_attacks.md | 7 +- ...oasting_spn_request_with_rc4_encryption.md | 8 +- .../_posts/2020-10-21-detect_kerberoasting.md | 8 +- .../_posts/2020-10-21-detect_pass_the_hash.md | 7 +- ...ect_ipv6_network_infrastructure_threats.md | 7 +- ...20-10-28-detect_port_security_violation.md | 7 +- ...ect_software_download_to_network_device.md | 9 +- .../2020-10-28-detect_traffic_mirroring.md | 6 +- ...tores_and_services_via_mimikatz_modules.md | 40 +- ...defensive_tools_via_powersploit_modules.md | 16 +- ...system_elements_via_powersploit_modules.md | 46 +- ...o_shared_resources_via_mimikatz_modules.md | 20 +- ...hared_resources_via_powersploit_modules.md | 20 +- ...of_connectivity_via_powersploit_modules.md | 20 +- ...cution_policy_to_unrestricted_or_bypass.md | 6 +- ...xcessive_account_lockouts_from_endpoint.md | 9 +- ...rohibited_applications_spawning_cmd_exe.md | 6 +- ...8-disabling_remote_user_account_control.md | 9 +- ...cution_of_file_with_multiple_extensions.md | 6 +- ...onitor_registry_keys_for_print_monitors.md | 9 +- ...installation_with_suspicious_parameters.md | 9 +- ...pulating_windows_services_registry_keys.md | 10 +- ...gistry_keys_for_creating_shim_databases.md | 9 +- ...stry_keys_used_for_privilege_escalation.md | 9 +- ...020-11-30-rundll_loading_dll_by_ordinal.md | 6 +- ...2-07-schtasks_used_for_forcing_a_reboot.md | 10 +- .../2020-12-08-shim_database_file_creation.md | 9 +- ...12-08-single_letter_process_on_endpoint.md | 6 +- ...processes_run_from_unexpected_locations.md | 6 +- ...i_permanent_event_subscription_-_sysmon.md | 9 +- ...12-15-o365_suspicious_rights_delegation.md | 8 +- ..._of_login_failures_from_a_single_source.md | 8 +- ...-o365_suspicious_admin_email_forwarding.md | 8 +- ...6-o365_suspicious_user_email_forwarding.md | 8 +- ...heduled_task_deleted_or_created_via_cmd.md | 10 +- ...ontrol_list_created_with_all_open_ports.md | 8 +- ...aws_network_access_control_list_deleted.md | 8 +- .../2021-01-12-suspicious_msbuild_path.md | 16 +- .../2021-01-12-suspicious_msbuild_rename.md | 16 +- .../2021-01-12-suspicious_msbuild_spawn.md | 6 +- ...21-01-12-suspicious_mshta_child_process.md | 6 +- ...ell_process_with_obfuscation_techniques.md | 6 +- ...20-detect_rundll32_inline_hta_execution.md | 6 +- .../2021-01-20-suspicious_mshta_spawn.md | 6 +- ...o365_add_app_role_assignment_grant_user.md | 8 +- ...2021-01-26-o365_added_service_principal.md | 8 +- ...1-01-26-o365_new_federated_domain_added.md | 8 +- ...ect_regsvr32_application_control_bypass.md | 6 +- .../_posts/2021-01-28-ntdsutil_export_ntds.md | 8 +- ...cious_regsvr32_register_suspicious_path.md | 6 +- ...32_application_control_bypass_-_advpack.md | 6 +- ...2_application_control_bypass_-_setupapi.md | 6 +- ...2_application_control_bypass_-_syssetup.md | 6 +- .../2021-02-04-suspicious_rundll32_rename.md | 10 +- .../2021-02-04-suspicious_rundll32_startw.md | 6 +- ...9-suspicious_rundll32_dllregisterserver.md | 6 +- ...11-detect_html_help_spawn_child_process.md | 6 +- ...-02-12-detect_regasm_spawning_a_process.md | 6 +- ...02-12-detect_regsvcs_spawning_a_process.md | 6 +- ...6-detect_regasm_with_network_connection.md | 6 +- ...-detect_regsvcs_with_network_connection.md | 6 +- ...e_policy_version_to_allow_all_resources.md | 11 +- .../2021-02-22-suspicious_plistbuddy_usage.md | 9 +- ...suspicious_plistbuddy_usage_via_osquery.md | 9 +- .../2021-03-01-any_powershell_downloadfile.md | 6 +- ...021-03-01-any_powershell_downloadstring.md | 6 +- docs/_posts/2021-03-01-eventvwr_uac_bypass.md | 9 +- .../_posts/2021-03-01-fodhelper_uac_bypass.md | 9 +- .../2021-03-01-ryuk_wake_on_lan_command.md | 6 +- ...us_scheduled_task_from_public_directory.md | 10 +- .../2021-03-02-aws_setdefaultpolicyversion.md | 11 +- ...-02-windows_disableantispyware_registry.md | 8 +- ...2021-03-03-nishang_powershelltcponeline.md | 6 +- docs/_posts/2021-03-03-w3wp_spawning_shell.md | 6 +- ...-create_service_in_suspicious_file_path.md | 6 +- ...03-31-aws_iam_successful_group_deletion.md | 6 +- .../2021-03-31-disable_registry_tool.md | 8 +- .../2021-03-31-disable_show_hidden_files.md | 12 +- ...-31-disable_windows_behavior_monitoring.md | 8 +- ...-disable_windows_smartscreen_protection.md | 8 +- .../2021-03-31-disabling_cmd_application.md | 8 +- .../2021-03-31-disabling_controlpanel.md | 8 +- ...021-03-31-disabling_firewall_with_netsh.md | 8 +- ...disabling_folderoptions_windows_feature.md | 8 +- .../2021-03-31-disabling_norun_windows_app.md | 8 +- ...-31-disabling_systemrestore_in_registry.md | 8 +- .../2021-03-31-disabling_task_manager.md | 8 +- ...icious_powershell_executed_as_a_service.md | 6 +- ...o_authenticate_from_host_using_kerberos.md | 8 +- ...heduled_task_created_within_public_path.md | 10 +- .../2021-04-12-excel_spawning_powershell.md | 8 +- ...4-12-excel_spawning_windows_script_host.md | 8 +- ...t_scheduled_task_created_to_spawn_shell.md | 10 +- .../2021-04-12-winword_spawning_powershell.md | 6 +- ...12-winword_spawning_windows_script_host.md | 6 +- ...authenticate_using_explicit_credentials.md | 8 +- ...ng_to_authenticate_from_host_using_ntlm.md | 8 +- ...rs_failing_to_authenticate_from_process.md | 8 +- ...otely_failing_to_authenticate_from_host.md | 8 +- ...fice_application_spawn_rundll32_process.md | 6 +- ...o_authenticate_from_host_using_kerberos.md | 8 +- ...o_authenticate_from_host_using_kerberos.md | 8 +- ...-office_document_creating_schedule_task.md | 6 +- ...14-office_document_executing_macro_code.md | 6 +- ...ng_to_authenticate_from_host_using_ntlm.md | 8 +- ..._no_command_line_arguments_with_network.md | 8 +- ...ess_connecting_to_ip_check_web_services.md | 6 +- ...ultiple_archive_files_http_post_traffic.md | 8 +- .../2021-04-22-anomalous_usage_of_7zip.md | 8 +- ...e_product_spawning_rundll32_with_no_dll.md | 6 +- ...-04-22-plain_http_post_exfiltrated_data.md | 8 +- .../_posts/2021-04-22-winword_spawning_cmd.md | 6 +- ...021-04-23-write_executable_in_smb_share.md | 6 +- ...04-26-office_product_spawning_bitsadmin.md | 6 +- ...-04-26-office_product_spawning_certutil.md | 6 +- ...021-04-26-office_product_spawning_mshta.md | 6 +- ...021-04-29-suspicious_driver_loaded_path.md | 9 +- docs/_posts/2021-04-29-xmrig_driver_loaded.md | 9 +- .../2021-05-04-excessive_usage_of_taskkill.md | 8 +- ...21-05-04-process_kill_base_on_file_path.md | 8 +- .../2021-05-05-disable_windows_app_hotkeys.md | 8 +- ...5-hide_user_account_from_sign-in_screen.md | 8 +- ...2021-05-13-cmlua_or_cmstplua_uac_bypass.md | 6 +- docs/_posts/2021-05-13-slui_runas_elevated.md | 9 +- .../2021-05-13-slui_spawning_a_process.md | 9 +- ...-allow_inbound_traffic_in_firewall_rule.md | 8 +- .../2021-05-19-mailsniper_invoke_functions.md | 6 +- .../2021-05-20-cmd_echo_pipe_-_escalation.md | 13 +- ...bound_traffic_by_firewall_rule_registry.md | 8 +- ...6-secretdumps_offline_ntds_dumping_tool.md | 8 +- ...27-detect_sharphound_file_modifications.md | 22 +- .../2021-05-27-detect_sharphound_usage.md | 22 +- ...etect_azurehound_command-line_arguments.md | 22 +- ...01-detect_azurehound_file_modifications.md | 22 +- ...etect_sharphound_command-line_arguments.md | 22 +- ...021-06-02-wbemprox_com_object_execution.md | 6 +- ...ss_process_injection_via_getprocaddress.md | 6 +- ..._script_contains_base64_encoded_content.md | 6 +- ...re_with_powershell_script_block_logging.md | 6 +- ...ear_unallocated_sector_using_cipher_app.md | 8 +- .../2021-06-10-disable_logs_using_wevtutil.md | 6 +- ...-06-10-powershell_creating_thread_mutex.md | 6 +- ...021-06-10-powershell_domain_enumeration.md | 6 +- ...o_memory_via_system_reflection_assembly.md | 6 +- ...10-powershell_processing_stream_of_data.md | 6 +- ...21-06-10-start_up_during_safe_mode_boot.md | 9 +- ...2021-06-15-wevtutil_usage_to_clear_logs.md | 6 +- ...21-06-15-wevtutil_usage_to_disable_logs.md | 6 +- ...tect_wmi_event_subscription_persistence.md | 9 +- ...7-suspicious_event_log_service_behavior.md | 6 +- .../2021-06-21-attacker_tools_on_endpoint.md | 14 +- ...021-06-22-disable_amsi_through_registry.md | 8 +- ...2021-06-22-disable_etw_through_registry.md | 8 +- ...ecute_javascript_with_jscript_com_clsid.md | 6 +- ...-powershell_enable_smb1protocol_feature.md | 6 +- ...ursive_delete_of_directory_in_batch_cmd.md | 8 +- ...w_file_and_printing_sharing_in_firewall.md | 8 +- ...-23-allow_network_discovery_in_firewall.md | 8 +- ...4-excessive_usage_of_sc_service_utility.md | 6 +- ...er_of_service_control_start_as_disabled.md | 8 +- ...1-print_spooler_adding_a_printer_driver.md | 9 +- ...-print_spooler_failed_to_load_a_plug-in.md | 9 +- docs/_posts/2021-07-01-sdclt_uac_bypass.md | 9 +- .../2021-07-01-silentcleanup_uac_bypass.md | 9 +- .../2021-07-01-spoolsv_spawning_rundll32.md | 9 +- ...07-01-spoolsv_suspicious_loaded_modules.md | 9 +- .../2021-07-01-spoolsv_writing_a_dll.md | 9 +- ...21-07-01-spoolsv_writing_a_dll_-_sysmon.md | 9 +- docs/_posts/2021-07-01-wsreset_uac_bypass.md | 9 +- ...05-msmpeng_application_dll_side_loading.md | 10 +- ...-powershell_disable_security_monitoring.md | 8 +- .../2021-07-12-net_profiler_uac_bypass.md | 9 +- ...-07-12-uac_bypass_mmc_load_unsigned_dll.md | 9 +- ...tance_created_by_previously_unseen_user.md | 11 +- docs/_posts/2021-07-19-aws_createaccesskey.md | 8 +- .../2021-07-19-aws_createloginprofile.md | 8 +- .../2021-07-19-aws_updateloginprofile.md | 8 +- ...a_spawning_rundll32_or_regsvr32_process.md | 6 +- ...21-07-19-o365_bypass_mfa_via_trusted_ip.md | 8 +- ...-07-19-office_product_spawn_cmd_process.md | 6 +- ...of_shadowcopy_with_script_block_logging.md | 8 +- ...-07-23-sam_database_file_access_attempt.md | 8 +- docs/_posts/2021-07-26-rundll32_dnsquery.md | 6 +- ...rundll32_process_creating_exe_dll_files.md | 6 +- ...7-26-suspicious_icedid_rundll32_cmdline.md | 6 +- ...21-07-26-suspicious_rundll32_plugininit.md | 6 +- ...7-27-suspicious_icedid_regsvr32_cmdline.md | 6 +- .../2021-07-30-drop_icedid_license_dat.md | 6 +- ...edid_exfiltrated_archived_file_creation.md | 8 +- ...fice_application_spawn_regsvr32_process.md | 6 +- .../2021-08-09-uninstall_app_using_msiexec.md | 8 +- ...021-08-10-powershell_execute_com_object.md | 9 +- ...8-13-uac_bypass_with_colorui_com_object.md | 6 +- ...16-gsuite_drive_share_in_external_email.md | 12 +- ...8-16-gsuite_email_suspicious_attachment.md | 10 +- ...8-17-7zip_commandline_to_smb_share_path.md | 8 +- ...ws_ecr_container_scanning_findings_high.md | 8 +- ...ning_findings_low_informational_unknown.md | 8 +- ..._ecr_container_scanning_findings_medium.md | 8 +- ...mail_with_attachment_to_external_domain.md | 10 +- docs/_posts/2021-08-18-esentutl_sam_copy.md | 8 +- .../2021-08-18-powershell_4104_hunting.md | 6 +- ...container_upload_outside_business_hours.md | 8 +- ...9-aws_ecr_container_upload_unknown_user.md | 8 +- ...mail_suspicious_subject_with_attachment.md | 10 +- ...1-08-20-github_commit_changes_in_master.md | 2 +- ...2021-08-23-getlocaluser_with_powershell.md | 6 +- ...tlocaluser_with_powershell_script_block.md | 6 +- ...twmiobject_user_account_with_powershell.md | 6 +- ...er_account_with_powershell_script_block.md | 6 +- ...email_with_known_abuse_web_service_link.md | 10 +- ...8-23-gsuite_suspicious_shared_file_name.md | 12 +- ...21-08-24-adsisearcher_account_discovery.md | 8 +- ...4-domain_account_discovery_with_dsquery.md | 8 +- ...4-domain_account_discovery_with_net_app.md | 8 +- ...8-24-domain_account_discovery_with_wmic.md | 8 +- .../2021-08-24-get_aduser_with_powershell.md | 8 +- ...get_aduser_with_powershell_script_block.md | 8 +- ...21-08-24-get_domainuser_with_powershell.md | 8 +- ...domainuser_with_powershell_script_block.md | 8 +- ...24-getwmiobject_ds_user_with_powershell.md | 8 +- ...ct_ds_user_with_powershell_script_block.md | 8 +- ...omain_group_discovery_with_adsisearcher.md | 6 +- ...1-08-25-domain_group_discovery_with_net.md | 6 +- ...-08-25-domain_group_discovery_with_wmic.md | 6 +- ...08-25-elevated_group_discovery_with_net.md | 6 +- ...elevated_group_discovery_with_powerview.md | 6 +- ...8-25-elevated_group_discovery_with_wmic.md | 6 +- .../2021-08-25-getadgroup_with_powershell.md | 6 +- ...getadgroup_with_powershell_script_block.md | 6 +- ...21-08-25-getdomaingroup_with_powershell.md | 6 +- ...5-getwmiobject_ds_group_with_powershell.md | 6 +- ...t_ds_group_with_powershell_script_block.md | 6 +- ...omaingroup_with_powershell_script_block.md | 6 +- ...reating_lnk_file_in_suspicious_location.md | 6 +- ...-08-27-exchange_powershell_module_usage.md | 6 +- ...-01-domain_group_discovery_with_dsquery.md | 6 +- .../2021-09-01-github_commit_in_develop.md | 2 +- .../2021-09-01-github_dependabot_alert.md | 8 +- ...1-github_pull_request_from_unknown_user.md | 8 +- ...hash_observed_at_the_destination_device.md | 7 +- ..._observed_by_an_event_collecting_device.md | 7 +- ...dd_defaultuser_and_password_in_registry.md | 8 +- ...1-09-06-auto_admin_logon_registry_entry.md | 8 +- ...9-06-correlation_by_repository_and_risk.md | 8 +- ...2021-09-06-correlation_by_user_and_risk.md | 8 +- ...9-07-registry_keys_used_for_persistence.md | 11 +- ...e_by_app_connect_and_create_adsi_object.md | 8 +- ...l_loading_from_world_writable_directory.md | 6 +- ...eate_local_admin_accounts_using_net_exe.md | 8 +- .../2021-09-08-office_spawning_control.md | 6 +- ...2021-09-08-rundll32_control_rundll_hunt.md | 6 +- ...control_rundll_world_writable_directory.md | 6 +- ...2021-09-09-extraction_of_registry_hives.md | 8 +- ...09-mshtml_module_load_in_office_product.md | 6 +- ...09-10-office_product_writing_cab_or_inf.md | 6 +- ...-13-jscript_execution_using_cscript_app.md | 6 +- ...s_scripting_process_loading_ldap_module.md | 6 +- ...ms_scripting_process_loading_wmi_module.md | 6 +- ...9-13-office_application_drop_executable.md | 6 +- ...-cmdline_tool_not_executed_in_cmd_shell.md | 6 +- ...021-09-14-get_wmiobject_group_discovery.md | 6 +- ...oup_discovery_with_script_block_logging.md | 6 +- .../2021-09-14-net_localgroup_discovery.md | 6 +- ...-14-powershell_get_localgroup_discovery.md | 6 +- ...oup_discovery_with_script_block_logging.md | 6 +- .../_posts/2021-09-14-wmic_group_discovery.md | 6 +- ...me_process_accessing_chrome_default_dir.md | 6 +- ...efox_process_access_firefox_profile_dir.md | 6 +- ...21-09-16-account_discovery_with_net_app.md | 8 +- ...t_to_add_certificate_to_untrusted_store.md | 8 +- ...edential_dump_from_registry_via_reg_exe.md | 8 +- ...2021-09-16-batch_file_write_to_system32.md | 6 +- ...of_shadow_copy_with_wmic_and_powershell.md | 8 +- ...mping_via_copy_command_from_shadow_copy.md | 8 +- ...tial_dumping_via_symlink_to_shadow_copy.md | 8 +- .../2021-09-16-detect_html_help_renamed.md | 6 +- ...16-detect_html_help_url_in_command_line.md | 6 +- ...ml_help_using_infotech_storage_handlers.md | 6 +- ...09-16-detect_mshta_inline_hta_execution.md | 6 +- .../_posts/2021-09-16-detect_mshta_renamed.md | 6 +- ...-09-16-detect_mshta_url_in_command_line.md | 6 +- ...9-16-detect_psexec_with_accepteula_flag.md | 6 +- .../_posts/2021-09-16-detect_renamed_7-zip.md | 8 +- .../2021-09-16-detect_renamed_psexec.md | 6 +- .../2021-09-16-detect_renamed_winrar.md | 8 +- .../2021-09-16-dump_lsass_via_procdump.md | 8 +- ...-09-16-local_account_discovery_with_net.md | 6 +- ...09-16-local_account_discovery_with_wmic.md | 6 +- ...2021-09-16-office_product_spawning_wmic.md | 6 +- .../2021-09-16-processes_launching_netsh.md | 8 +- ...t_regasm_with_no_command_line_arguments.md | 6 +- ..._regsvcs_with_no_command_line_arguments.md | 6 +- ...ument_spawned_child_process_to_download.md | 6 +- ...ious_microsoft_workflow_compiler_rename.md | 6 +- ...ious_rundll32_no_command_line_arguments.md | 6 +- ...1-09-27-change_default_file_association.md | 109 + ...27-logon_script_event_trigger_execution.md | 109 + ...-27-screensaver_event_trigger_execution.md | 110 + ...1-09-28-active_setup_registry_autostart.md | 110 + ...9-28-print_processor_registry_autostart.md | 112 + ...21-09-29-disable_uac_remote_restriction.md | 110 + ...9-29-time_provider_persistence_registry.md | 110 + .../2021-09-29-verclsid_clsid_execution.md | 113 + ...01-vbscript_execution_using_wscript_app.md | 113 + ...ld_suspicious_spawned_by_script_process.md | 107 + ...10-04-regsvr32_silent_param_dll_loading.md | 113 + .../2021-10-05-detect_exchange_web_shell.md | 6 +- ...ble_security_logs_using_minint_registry.md | 103 + ...ble_wdigest_uselogoncredential_registry.md | 107 + ...5-malicious_inprocserver32_modification.md | 115 + ..._connect_to_internet_with_hidden_window.md | 8 +- ...1-10-05-process_writing_dynamicwrapperx.md | 116 + .../2021-10-05-rundll32_shimcache_flush.md | 109 + .../2021-10-05-suspicious_copy_on_system32.md | 112 + .../2021-10-05-winhlp32_spawning_a_process.md | 112 + ...ery_length_with_high_standard_deviation.md | 8 +- ...021-10-06-sdelete_application_execution.md | 116 + ...ipt_or_cscript_suspicious_child_process.md | 126 + .../2021-10-07-etw_registry_disabled.md | 111 + .../2021-10-11-suspicious_wevtutil_usage.md | 108 + ..._no_command_line_arguments_with_network.md | 112 + ..._no_command_line_arguments_with_network.md | 123 + ...lhost_with_no_command_line_with_network.md | 110 + docs/_stories/active_directory_discovery.md | 70 +- .../active_directory_password_spraying.md | 16 +- docs/_stories/aws_iam_privilege_escalation.md | 12 +- docs/_stories/aws_network_acl_activity.md | 4 +- docs/_stories/blackmatter_ransomware.md | 4 +- docs/_stories/clop_ransomware.md | 10 +- docs/_stories/cloud_cryptomining.md | 4 +- .../cloud_federated_credential_abuse.md | 10 +- docs/_stories/cobalt_strike.md | 18 +- docs/_stories/collection_and_staging.md | 10 +- docs/_stories/command_and_control.md | 14 +- docs/_stories/credential_dumping.md | 43 +- docs/_stories/darkside_ransomware.md | 16 +- docs/_stories/data_exfiltration.md | 10 +- docs/_stories/detect_zerologon_attack.md | 4 +- docs/_stories/dev_sec_ops.md | 26 +- docs/_stories/dhs_report_ta18-074a.md | 26 +- docs/_stories/disabling_security_tools.md | 10 +- docs/_stories/dns_amplification_attacks.md | 2 +- .../emotet_malware__dhs_report_ta18-201a_.md | 10 +- docs/_stories/fin7.md | 18 +- docs/_stories/hafnium_group.md | 28 +- docs/_stories/hidden_cobra_malware.md | 16 +- docs/_stories/icedid.md | 34 +- docs/_stories/ingress_tool_transfer.md | 4 +- docs/_stories/lateral_movement.md | 20 +- docs/_stories/malicious_powershell.md | 30 +- .../masquerading_-_rename_system_utilities.md | 13 +- ...ml_remote_code_execution_cve-2021-40444.md | 12 +- docs/_stories/netsh_abuse.md | 2 +- docs/_stories/nobelium_group.md | 18 +- docs/_stories/office_365_detections.md | 16 +- docs/_stories/orangeworm_attack_group.md | 4 +- ...ciated_with_mudcarp_espionage_campaigns.md | 4 +- .../_stories/printnightmare_cve-2021-34527.md | 16 +- ...ed_traffic_allowed_or_protocol_mismatch.md | 8 +- docs/_stories/proxyshell.md | 6 +- docs/_stories/ransomware.md | 74 +- docs/_stories/remcos.md | 9 +- docs/_stories/revil_ransomware.md | 10 +- .../router_and_infrastructure_security.md | 10 +- docs/_stories/ryuk_ransomware.md | 14 +- docs/_stories/samsam_ransomware.md | 12 +- docs/_stories/silver_sparrow.md | 4 +- docs/_stories/spearphishing_attachments.md | 36 +- .../suspicious_cloud_instance_activities.md | 6 +- .../suspicious_cloud_user_activities.md | 4 +- .../suspicious_command-line_executions.md | 6 +- .../suspicious_compiled_html_activity.md | 8 +- docs/_stories/suspicious_dns_traffic.md | 6 +- docs/_stories/suspicious_emails.md | 2 +- docs/_stories/suspicious_mshta_activity.md | 16 +- docs/_stories/suspicious_okta_activity.md | 8 +- .../suspicious_regsvcs_regasm_activity.md | 12 +- docs/_stories/suspicious_regsvr32_activity.md | 6 +- docs/_stories/suspicious_rundll32_activity.md | 22 +- .../suspicious_windows_registry_activities.md | 11 +- docs/_stories/suspicious_wmi_use.md | 4 +- .../suspicious_zoom_child_processes.md | 2 +- docs/_stories/trickbot.md | 18 +- ...ted_developer_utilities_proxy_execution.md | 2 +- ...loper_utilities_proxy_execution_msbuild.md | 7 +- docs/_stories/unusual_processes.md | 10 +- .../windows_defense_evasion_tactics.md | 50 +- docs/_stories/windows_discovery_techniques.md | 12 +- ...ws_file_extension_and_association_abuse.md | 2 +- docs/_stories/windows_log_manipulation.md | 10 +- .../windows_persistence_techniques.md | 33 +- docs/_stories/windows_privilege_escalation.md | 11 +- docs/_stories/windows_service_abuse.md | 6 +- docs/_stories/xmrig.md | 14 +- docs/detections.wiki | 4328 +++++++++++++++-- docs/index.markdown | 4 +- docs/stories.wiki | 3351 ++++++++++--- 458 files changed, 12588 insertions(+), 2663 deletions(-) create mode 100644 docs/_posts/2021-09-27-change_default_file_association.md create mode 100644 docs/_posts/2021-09-27-logon_script_event_trigger_execution.md create mode 100644 docs/_posts/2021-09-27-screensaver_event_trigger_execution.md create mode 100644 docs/_posts/2021-09-28-active_setup_registry_autostart.md create mode 100644 docs/_posts/2021-09-28-print_processor_registry_autostart.md create mode 100644 docs/_posts/2021-09-29-disable_uac_remote_restriction.md create mode 100644 docs/_posts/2021-09-29-time_provider_persistence_registry.md create mode 100644 docs/_posts/2021-09-29-verclsid_clsid_execution.md create mode 100644 docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md create mode 100644 docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md create mode 100644 docs/_posts/2021-10-04-regsvr32_silent_param_dll_loading.md create mode 100644 docs/_posts/2021-10-05-disable_security_logs_using_minint_registry.md create mode 100644 docs/_posts/2021-10-05-enable_wdigest_uselogoncredential_registry.md create mode 100644 docs/_posts/2021-10-05-malicious_inprocserver32_modification.md create mode 100644 docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md create mode 100644 docs/_posts/2021-10-05-rundll32_shimcache_flush.md create mode 100644 docs/_posts/2021-10-05-suspicious_copy_on_system32.md create mode 100644 docs/_posts/2021-10-05-winhlp32_spawning_a_process.md create mode 100644 docs/_posts/2021-10-06-sdelete_application_execution.md create mode 100644 docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md create mode 100644 docs/_posts/2021-10-07-etw_registry_disabled.md create mode 100644 docs/_posts/2021-10-11-suspicious_wevtutil_usage.md create mode 100644 docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md create mode 100644 docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md create mode 100644 docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md diff --git a/bin/jinja2_templates/doc_playbooks_page_markdown.j2 b/bin/jinja2_templates/doc_playbooks_page_markdown.j2 index e50af7ff47..0ae001d7bd 100644 --- a/bin/jinja2_templates/doc_playbooks_page_markdown.j2 +++ b/bin/jinja2_templates/doc_playbooks_page_markdown.j2 @@ -11,5 +11,9 @@ sidebar: | Name | Detections | Type | | --------| ---------- | ----------- | {% for playbook in playbooks -%} +{% if playbook.tags.detections -%} | [{{ playbook.name }}](/playbooks/{{ playbook.name|lower|replace(' ', '_') }}/)|{% for detection in playbook.tags.detections -%}{% for d in detections -%}{% if d.name == detection -%}[{{ detection }}](/detections/{{ d.type }}/{{detection|lower|replace(" ", "_")}}){% endif -%}{%- endfor -%}{%- endfor -%} | {{ playbook.type }} | +{% else -%} +| [{{ playbook.name }}](/playbooks/{{ playbook.name|lower|replace(' ', '_') }}/)| None | {{ playbook.type }} | +{% endif -%} {%- endfor -%} diff --git a/docs/_pages/abuse.md b/docs/_pages/abuse.md index bd9312f75b..d079742c85 100644 --- a/docs/_pages/abuse.md +++ b/docs/_pages/abuse.md @@ -11,6 +11,6 @@ sidebar: | Name | Technique | Tactic | | ----------- | ----------- |--------------| | [Brand Monitoring]() | None | None | -| [DNS Amplification Attacks](/stories/dns_amplification_attacks/) | [Reflection Amplification](/tags/#reflection-amplification) | [Impact](/tags/#impact) | +| [DNS Amplification Attacks](/stories/dns_amplification_attacks/) | [Network Denial of Service](/tags/#network-denial-of-service), [Reflection Amplification](/tags/#reflection-amplification) | [Impact](/tags/#impact) | | [Data Protection](/stories/data_protection/) | [Drive-by Compromise](/tags/#drive-by-compromise) | [Initial Access](/tags/#initial-access) | -| [Netsh Abuse](/stories/netsh_abuse/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall) | [Defense Evasion](/tags/#defense-evasion) | \ No newline at end of file +| [Netsh Abuse](/stories/netsh_abuse/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | \ No newline at end of file diff --git a/docs/_pages/adversary_tactics.md b/docs/_pages/adversary_tactics.md index ab9dfdc2ce..f25364a284 100644 --- a/docs/_pages/adversary_tactics.md +++ b/docs/_pages/adversary_tactics.md @@ -10,52 +10,52 @@ sidebar: | Name | Technique | Tactic | | ----------- | ----------- |--------------| -| [Active Directory Discovery](/stories/active_directory_discovery/) | [Local Groups](/tags/#local-groups) | [Discovery](/tags/#discovery) | -| [Active Directory Password Spraying](/stories/active_directory_password_spraying/) | [Password Spraying](/tags/#password-spraying) | [Credential Access](/tags/#credential-access) | +| [Active Directory Discovery](/stories/active_directory_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Discovery](/tags/#discovery) | +| [Active Directory Password Spraying](/stories/active_directory_password_spraying/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Credential Access](/tags/#credential-access) | | [BITS Jobs](/stories/bits_jobs/) | [BITS Jobs](/tags/#bits-jobs) | [Defense Evasion](/tags/#defense-evasion) | | [Baron Samedit CVE-2021-3156](/stories/baron_samedit_cve-2021-3156/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Privilege Escalation](/tags/#privilege-escalation) | -| [Cobalt Strike](/stories/cobalt_strike/) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | +| [Cobalt Strike](/stories/cobalt_strike/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | [Defense Evasion](/tags/#defense-evasion) | | [Collection and Staging](/stories/collection_and_staging/) | [Masquerading](/tags/#masquerading) | [Defense Evasion](/tags/#defense-evasion) | -| [Command and Control](/stories/command_and_control/) | [Web Protocols](/tags/#web-protocols) | [Command And Control](/tags/#command-and-control) | -| [Credential Dumping](/stories/credential_dumping/) | [PowerShell](/tags/#powershell) | [Execution](/tags/#execution) | +| [Command and Control](/stories/command_and_control/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols) | [Command And Control](/tags/#command-and-control) | +| [Credential Dumping](/stories/credential_dumping/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [Execution](/tags/#execution) | | [DNS Hijacking](/stories/dns_hijacking/) | [Drive-by Compromise](/tags/#drive-by-compromise) | [Initial Access](/tags/#initial-access) | -| [Data Exfiltration](/stories/data_exfiltration/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | [Exfiltration](/tags/#exfiltration) | +| [Data Exfiltration](/stories/data_exfiltration/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Exfiltration](/tags/#exfiltration) | | [Deobfuscate-Decode Files or Information](/stories/deobfuscate-decode_files_or_information/) | [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information) | [Defense Evasion](/tags/#defense-evasion) | | [Detect Zerologon Attack](/stories/detect_zerologon_attack/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | -| [Disabling Security Tools](/stories/disabling_security_tools/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | [Defense Evasion](/tags/#defense-evasion) | +| [Disabling Security Tools](/stories/disabling_security_tools/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | | [Domain Trust Discovery](/stories/domain_trust_discovery/) | [Remote System Discovery](/tags/#remote-system-discovery) | [Discovery](/tags/#discovery) | | [F5 TMUI RCE CVE-2020-5902](/stories/f5_tmui_rce_cve-2020-5902/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | -| [HAFNIUM Group](/stories/hafnium_group/) | [Web Shell](/tags/#web-shell) | [Persistence](/tags/#persistence) | +| [HAFNIUM Group](/stories/hafnium_group/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | [Persistence](/tags/#persistence) | | [Ingress Tool Transfer](/stories/ingress_tool_transfer/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [Command And Control](/tags/#command-and-control) | -| [Lateral Movement](/stories/lateral_movement/) | [Scheduled Task](/tags/#scheduled-task) | [Execution](/tags/#execution) | +| [Lateral Movement](/stories/lateral_movement/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Execution](/tags/#execution) | | [Malicious PowerShell](/stories/malicious_powershell/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | [Reconnaissance](/tags/#reconnaissance) | -| [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities/) | [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | +| [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | | [Meterpreter](/stories/meterpreter/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [Discovery](/tags/#discovery) | -| [Microsoft MSHTML Remote Code Execution CVE-2021-40444](/stories/microsoft_mshtml_remote_code_execution_cve-2021-40444/) | [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | +| [Microsoft MSHTML Remote Code Execution CVE-2021-40444](/stories/microsoft_mshtml_remote_code_execution_cve-2021-40444/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | | [NOBELIUM Group](/stories/nobelium_group/) | [Remote System Discovery](/tags/#remote-system-discovery) | [Discovery](/tags/#discovery) | | [PetitPotam NTLM Relay on Active Directory Certificate Services](/stories/petitpotam_ntlm_relay_on_active_directory_certificate_services/) | [OS Credential Dumping](/tags/#os-credential-dumping) | [Credential Access](/tags/#credential-access) | -| [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](/stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | [Persistence](/tags/#persistence) | -| [ProxyShell](/stories/proxyshell/) | [Web Shell](/tags/#web-shell) | [Persistence](/tags/#persistence) | +| [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](/stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Persistence](/tags/#persistence) | +| [ProxyShell](/stories/proxyshell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | [Persistence](/tags/#persistence) | | [SQL Injection](/stories/sql_injection/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | | [Silver Sparrow](/stories/silver_sparrow/) | [Data Staged](/tags/#data-staged) | [Collection](/tags/#collection) | -| [Spearphishing Attachments](/stories/spearphishing_attachments/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | [Initial Access](/tags/#initial-access) | -| [Suspicious Command-Line Executions](/stories/suspicious_command-line_executions/) | [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Compiled HTML Activity](/stories/suspicious_compiled_html_activity/) | [Compiled HTML File](/tags/#compiled-html-file) | [Defense Evasion](/tags/#defense-evasion) | +| [Spearphishing Attachments](/stories/spearphishing_attachments/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [Initial Access](/tags/#initial-access) | +| [Suspicious Command-Line Executions](/stories/suspicious_command-line_executions/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Compiled HTML Activity](/stories/suspicious_compiled_html_activity/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | [Defense Evasion](/tags/#defense-evasion) | | [Suspicious DNS Traffic](/stories/suspicious_dns_traffic/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Exfiltration](/tags/#exfiltration) | -| [Suspicious Emails](/stories/suspicious_emails/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | [Initial Access](/tags/#initial-access) | -| [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity/) | [Mshta](/tags/#mshta) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Okta Activity](/stories/suspicious_okta_activity/) | [Default Accounts](/tags/#default-accounts) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Regsvcs Regasm Activity](/stories/suspicious_regsvcs_regasm_activity/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Regsvr32 Activity](/stories/suspicious_regsvr32_activity/) | [Regsvr32](/tags/#regsvr32) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity/) | [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Emails](/stories/suspicious_emails/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | [Initial Access](/tags/#initial-access) | +| [Suspicious MSHTA Activity](/stories/suspicious_mshta_activity/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Okta Activity](/stories/suspicious_okta_activity/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Regsvcs Regasm Activity](/stories/suspicious_regsvcs_regasm_activity/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Regsvr32 Activity](/stories/suspicious_regsvr32_activity/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | | [Suspicious WMI Use](/stories/suspicious_wmi_use/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [Execution](/tags/#execution) | -| [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities/) | [Application Shimming](/tags/#application-shimming) | [Privilege Escalation](/tags/#privilege-escalation) | +| [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | [Privilege Escalation](/tags/#privilege-escalation) | | [Suspicious Zoom Child Processes](/stories/suspicious_zoom_child_processes/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Privilege Escalation](/tags/#privilege-escalation) | | [Trusted Developer Utilities Proxy Execution](/stories/trusted_developer_utilities_proxy_execution/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution) | [Defense Evasion](/tags/#defense-evasion) | -| [Trusted Developer Utilities Proxy Execution MSBuild](/stories/trusted_developer_utilities_proxy_execution_msbuild/) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | +| [Trusted Developer Utilities Proxy Execution MSBuild](/stories/trusted_developer_utilities_proxy_execution_msbuild/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | [Defense Evasion](/tags/#defense-evasion) | | [Windows DNS SIGRed CVE-2020-1350](/stories/windows_dns_sigred_cve-2020-1350/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | [Execution](/tags/#execution) | -| [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | [Defense Evasion](/tags/#defense-evasion) | +| [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | | [Windows Discovery Techniques](/stories/windows_discovery_techniques/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Process Injection](/tags/#process-injection), [Hijack Execution Flow](/tags/#hijack-execution-flow) | [Persistence](/tags/#persistence) | -| [Windows Log Manipulation](/stories/windows_log_manipulation/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | -| [Windows Persistence Techniques](/stories/windows_persistence_techniques/) | [Scheduled Task](/tags/#scheduled-task) | [Execution](/tags/#execution) | -| [Windows Privilege Escalation](/stories/windows_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection) | [Privilege Escalation](/tags/#privilege-escalation) | \ No newline at end of file +| [Windows Log Manipulation](/stories/windows_log_manipulation/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | +| [Windows Persistence Techniques](/stories/windows_persistence_techniques/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Execution](/tags/#execution) | +| [Windows Privilege Escalation](/stories/windows_privilege_escalation/) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Persistence](/tags/#persistence) | \ No newline at end of file diff --git a/docs/_pages/best_practices.md b/docs/_pages/best_practices.md index 6114be8754..dc03339daa 100644 --- a/docs/_pages/best_practices.md +++ b/docs/_pages/best_practices.md @@ -12,6 +12,6 @@ sidebar: | ----------- | ----------- |--------------| | [Asset Tracking]() | None | None | | [Monitor for Updates]() | None | None | -| [Prohibited Traffic Allowed or Protocol Mismatch](/stories/prohibited_traffic_allowed_or_protocol_mismatch/) | [Web Protocols](/tags/#web-protocols) | [Command And Control](/tags/#command-and-control) | -| [Router and Infrastructure Security](/stories/router_and_infrastructure_security/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Traffic Duplication](/tags/#traffic-duplication) | [Initial Access](/tags/#initial-access) | +| [Prohibited Traffic Allowed or Protocol Mismatch](/stories/prohibited_traffic_allowed_or_protocol_mismatch/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols) | [Command And Control](/tags/#command-and-control) | +| [Router and Infrastructure Security](/stories/router_and_infrastructure_security/) | [Hardware Additions](/tags/#hardware-additions), [Automated Exfiltration](/tags/#automated-exfiltration), [Network Denial of Service](/tags/#network-denial-of-service), [Traffic Duplication](/tags/#traffic-duplication) | [Initial Access](/tags/#initial-access) | | [Use of Cleartext Protocols]() | None | None | \ No newline at end of file diff --git a/docs/_pages/cloud_security.md b/docs/_pages/cloud_security.md index 4ecc062563..1e113284d0 100644 --- a/docs/_pages/cloud_security.md +++ b/docs/_pages/cloud_security.md @@ -11,18 +11,18 @@ sidebar: | Name | Technique | Tactic | | ----------- | ----------- |--------------| | [AWS Cross Account Activity](/stories/aws_cross_account_activity/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material) | [Defense Evasion](/tags/#defense-evasion) | -| [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation/) | [Cloud Account](/tags/#cloud-account) | [Persistence](/tags/#persistence) | -| [AWS Network ACL Activity](/stories/aws_network_acl_activity/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | [Defense Evasion](/tags/#defense-evasion) | +| [AWS IAM Privilege Escalation](/stories/aws_iam_privilege_escalation/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | [Persistence](/tags/#persistence) | +| [AWS Network ACL Activity](/stories/aws_network_acl_activity/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | | [AWS Security Hub Alerts]() | None | None | | [AWS User Monitoring](/stories/aws_user_monitoring/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Discovery](/tags/#discovery) | | [Cloud Cryptomining](/stories/cloud_cryptomining/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Defense Evasion](/tags/#defense-evasion) | -| [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection) | [Privilege Escalation](/tags/#privilege-escalation) | +| [Cloud Federated Credential Abuse](/stories/cloud_federated_credential_abuse/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution) | [Privilege Escalation](/tags/#privilege-escalation) | | [Container Implantation Monitoring and Investigation](/stories/container_implantation_monitoring_and_investigation/) | [Implant Internal Image](/tags/#implant-internal-image) | [Persistence](/tags/#persistence) | | [Dev Sec Ops](/stories/dev_sec_ops/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Discovery](/tags/#discovery) | | [GCP Cross Account Activity](/stories/gcp_cross_account_activity/) | [Valid Accounts](/tags/#valid-accounts) | [Defense Evasion](/tags/#defense-evasion) | | [Kubernetes Scanning Activity](/stories/kubernetes_scanning_activity/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Discovery](/tags/#discovery) | | [Kubernetes Sensitive Object Access Activity]() | None | None | -| [Office 365 Detections](/stories/office_365_detections/) | [Email Forwarding Rule](/tags/#email-forwarding-rule) | [Collection](/tags/#collection) | +| [Office 365 Detections](/stories/office_365_detections/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection) | [Collection](/tags/#collection) | | [Suspicious AWS Login Activities](/stories/suspicious_aws_login_activities/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Defense Evasion](/tags/#defense-evasion) | | [Suspicious AWS S3 Activities](/stories/suspicious_aws_s3_activities/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | [Collection](/tags/#collection) | | [Suspicious AWS Traffic]() | None | None | diff --git a/docs/_pages/detections.md b/docs/_pages/detections.md index 25fa3d4300..53ede289f2 100644 --- a/docs/_pages/detections.md +++ b/docs/_pages/detections.md @@ -10,107 +10,109 @@ sidebar: | Name | Technique | Type | | --------| --------- |------------| -| [7zip CommandLine To SMB Share Path](/endpoint/7zip_commandline_to_smb_share_path/) | [Archive via Utility](/tags/#archive-via-utility) | Hunting | -| [AWS Create Policy Version to allow all resources](/cloud/aws_create_policy_version_to_allow_all_resources/) | [Cloud Accounts](/tags/#cloud-accounts) | TTP | -| [AWS CreateAccessKey](/cloud/aws_createaccesskey/) | [Cloud Account](/tags/#cloud-account) | Hunting | -| [AWS CreateLoginProfile](/cloud/aws_createloginprofile/) | [Cloud Account](/tags/#cloud-account) | TTP | +| [7zip CommandLine To SMB Share Path](/endpoint/7zip_commandline_to_smb_share_path/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Hunting | +| [AWS Create Policy Version to allow all resources](/cloud/aws_create_policy_version_to_allow_all_resources/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | TTP | +| [AWS CreateAccessKey](/cloud/aws_createaccesskey/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | Hunting | +| [AWS CreateLoginProfile](/cloud/aws_createloginprofile/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | | [AWS Cross Account Activity From Previously Unseen Account]() | None | Anomaly | | [AWS Detect Users creating keys with encrypt policy without MFA](/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | TTP | | [AWS Detect Users with KMS keys performing encryption S3](/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | Anomaly | -| [AWS ECR Container Scanning Findings High](/cloud/aws_ecr_container_scanning_findings_high/) | [Malicious Image](/tags/#malicious-image) | TTP | -| [AWS ECR Container Scanning Findings Low Informational Unknown](/cloud/aws_ecr_container_scanning_findings_low_informational_unknown/) | [Malicious Image](/tags/#malicious-image) | Hunting | -| [AWS ECR Container Scanning Findings Medium](/cloud/aws_ecr_container_scanning_findings_medium/) | [Malicious Image](/tags/#malicious-image) | Anomaly | -| [AWS ECR Container Upload Outside Business Hours](/cloud/aws_ecr_container_upload_outside_business_hours/) | [Malicious Image](/tags/#malicious-image) | Anomaly | -| [AWS ECR Container Upload Unknown User](/cloud/aws_ecr_container_upload_unknown_user/) | [Malicious Image](/tags/#malicious-image) | Anomaly | +| [AWS ECR Container Scanning Findings High](/cloud/aws_ecr_container_scanning_findings_high/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | TTP | +| [AWS ECR Container Scanning Findings Low Informational Unknown](/cloud/aws_ecr_container_scanning_findings_low_informational_unknown/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Hunting | +| [AWS ECR Container Scanning Findings Medium](/cloud/aws_ecr_container_scanning_findings_medium/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Anomaly | +| [AWS ECR Container Upload Outside Business Hours](/cloud/aws_ecr_container_upload_outside_business_hours/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Anomaly | +| [AWS ECR Container Upload Unknown User](/cloud/aws_ecr_container_upload_unknown_user/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Anomaly | | [AWS Excessive Security Scanning](/cloud/aws_excessive_security_scanning/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | TTP | | [AWS IAM AccessDenied Discovery Events](/cloud/aws_iam_accessdenied_discovery_events/) | [Cloud Infrastructure Discovery](/tags/#cloud-infrastructure-discovery) | Anomaly | | [AWS IAM Assume Role Policy Brute Force](/cloud/aws_iam_assume_role_policy_brute_force/) | [Cloud Infrastructure Discovery](/tags/#cloud-infrastructure-discovery), [Brute Force](/tags/#brute-force) | TTP | | [AWS IAM Delete Policy](/cloud/aws_iam_delete_policy/) | [Account Manipulation](/tags/#account-manipulation) | Hunting | | [AWS IAM Failure Group Deletion](/cloud/aws_iam_failure_group_deletion/) | [Account Manipulation](/tags/#account-manipulation) | Anomaly | -| [AWS IAM Successful Group Deletion](/cloud/aws_iam_successful_group_deletion/) | [Cloud Groups](/tags/#cloud-groups), [Account Manipulation](/tags/#account-manipulation) | Hunting | -| [AWS Network Access Control List Created with All Open Ports](/cloud/aws_network_access_control_list_created_with_all_open_ports/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | TTP | -| [AWS Network Access Control List Deleted](/cloud/aws_network_access_control_list_deleted/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | Anomaly | +| [AWS IAM Successful Group Deletion](/cloud/aws_iam_successful_group_deletion/) | [Cloud Groups](/tags/#cloud-groups), [Account Manipulation](/tags/#account-manipulation), [Permission Groups Discovery](/tags/#permission-groups-discovery) | Hunting | +| [AWS Network Access Control List Created with All Open Ports](/cloud/aws_network_access_control_list_created_with_all_open_ports/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [AWS Network Access Control List Deleted](/cloud/aws_network_access_control_list_deleted/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | Anomaly | | [AWS SAML Access by Provider User and Principal](/cloud/aws_saml_access_by_provider_user_and_principal/) | [Valid Accounts](/tags/#valid-accounts) | Anomaly | | [AWS SAML Update identity provider](/cloud/aws_saml_update_identity_provider/) | [Valid Accounts](/tags/#valid-accounts) | TTP | -| [AWS SetDefaultPolicyVersion](/cloud/aws_setdefaultpolicyversion/) | [Cloud Accounts](/tags/#cloud-accounts) | TTP | -| [AWS UpdateLoginProfile](/cloud/aws_updateloginprofile/) | [Cloud Account](/tags/#cloud-account) | TTP | -| [Abnormally High Number Of Cloud Infrastructure API Calls](/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | -| [Abnormally High Number Of Cloud Instances Destroyed](/cloud/abnormally_high_number_of_cloud_instances_destroyed/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | -| [Abnormally High Number Of Cloud Instances Launched](/cloud/abnormally_high_number_of_cloud_instances_launched/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | -| [Abnormally High Number Of Cloud Security Group API Calls](/cloud/abnormally_high_number_of_cloud_security_group_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | -| [Access LSASS Memory for Dump Creation](/endpoint/access_lsass_memory_for_dump_creation/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Account Discovery With Net App](/endpoint/account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account) | TTP | -| [Add DefaultUser And Password In Registry](/endpoint/add_defaultuser_and_password_in_registry/) | [Credentials in Registry](/tags/#credentials-in-registry) | Anomaly | -| [AdsiSearcher Account Discovery](/endpoint/adsisearcher_account_discovery/) | [Domain Account](/tags/#domain-account) | TTP | -| [Allow File And Printing Sharing In Firewall](/endpoint/allow_file_and_printing_sharing_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | TTP | -| [Allow Inbound Traffic By Firewall Rule Registry](/endpoint/allow_inbound_traffic_by_firewall_rule_registry/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | TTP | -| [Allow Inbound Traffic In Firewall Rule](/endpoint/allow_inbound_traffic_in_firewall_rule/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | TTP | -| [Allow Network Discovery In Firewall](/endpoint/allow_network_discovery_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | TTP | +| [AWS SetDefaultPolicyVersion](/cloud/aws_setdefaultpolicyversion/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | TTP | +| [AWS UpdateLoginProfile](/cloud/aws_updateloginprofile/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | +| [Abnormally High Number Of Cloud Infrastructure API Calls](/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | +| [Abnormally High Number Of Cloud Instances Destroyed](/cloud/abnormally_high_number_of_cloud_instances_destroyed/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | +| [Abnormally High Number Of Cloud Instances Launched](/cloud/abnormally_high_number_of_cloud_instances_launched/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | +| [Abnormally High Number Of Cloud Security Group API Calls](/cloud/abnormally_high_number_of_cloud_security_group_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | +| [Access LSASS Memory for Dump Creation](/endpoint/access_lsass_memory_for_dump_creation/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Account Discovery With Net App](/endpoint/account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | +| [Active Setup Registry Autostart](/endpoint/active_setup_registry_autostart/) | [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Add DefaultUser And Password In Registry](/endpoint/add_defaultuser_and_password_in_registry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials) | Anomaly | +| [AdsiSearcher Account Discovery](/endpoint/adsisearcher_account_discovery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | +| [Allow File And Printing Sharing In Firewall](/endpoint/allow_file_and_printing_sharing_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Allow Inbound Traffic By Firewall Rule Registry](/endpoint/allow_inbound_traffic_by_firewall_rule_registry/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | TTP | +| [Allow Inbound Traffic In Firewall Rule](/endpoint/allow_inbound_traffic_in_firewall_rule/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | TTP | +| [Allow Network Discovery In Firewall](/endpoint/allow_network_discovery_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Allow Operation with Consent Admin](/endpoint/allow_operation_with_consent_admin/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Amazon EKS Kubernetes Pod scan detection](/cloud/amazon_eks_kubernetes_pod_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | Hunting | | [Amazon EKS Kubernetes cluster scan detection](/cloud/amazon_eks_kubernetes_cluster_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | Hunting | -| [Anomalous usage of 7zip](/endpoint/anomalous_usage_of_7zip/) | [Archive via Utility](/tags/#archive-via-utility) | Anomaly | -| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [PowerShell](/tags/#powershell) | TTP | -| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [PowerShell](/tags/#powershell) | TTP | +| [Anomalous usage of 7zip](/endpoint/anomalous_usage_of_7zip/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Anomaly | +| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Applying Stolen Credentials via Mimikatz modules](/endpoint/applying_stolen_credentials_via_mimikatz_modules/) | [Process Injection](/tags/#process-injection), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Access Token Manipulation](/tags/#access-token-manipulation), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Compromise Client Software Binary](/tags/#compromise-client-software-binary), [Modify Authentication Process](/tags/#modify-authentication-process), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | | [Applying Stolen Credentials via PowerSploit modules](/endpoint/applying_stolen_credentials_via_powersploit_modules/) | [Process Injection](/tags/#process-injection), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Access Token Manipulation](/tags/#access-token-manipulation), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Compromise Client Software Binary](/tags/#compromise-client-software-binary), [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | | [Assessment of Credential Strength via DSInternals modules](/endpoint/assessment_of_credential_strength_via_dsinternals_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Account Discovery](/tags/#account-discovery), [Password Policy Discovery](/tags/#password-policy-discovery), [Unsecured Credentials](/tags/#unsecured-credentials), [Credentials from Password Stores](/tags/#credentials-from-password-stores) | TTP | -| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Active Scanning](/tags/#active-scanning), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Attempt To Add Certificate To Untrusted Store](/endpoint/attempt_to_add_certificate_to_untrusted_store/) | [Install Root Certificate](/tags/#install-root-certificate) | TTP | +| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning) | TTP | +| [Attempt To Add Certificate To Untrusted Store](/endpoint/attempt_to_add_certificate_to_untrusted_store/) | [Install Root Certificate](/tags/#install-root-certificate), [Subvert Trust Controls](/tags/#subvert-trust-controls) | TTP | | [Attempt To Disable Services](/endpoint/attempt_to_disable_services/) | [Service Stop](/tags/#service-stop) | TTP | -| [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Attempt To delete Services](/endpoint/attempt_to_delete_services/) | [Service Stop](/tags/#service-stop) | TTP | | [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager) | TTP | -| [Auto Admin Logon Registry Entry](/endpoint/auto_admin_logon_registry_entry/) | [Credentials in Registry](/tags/#credentials-in-registry) | TTP | +| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Auto Admin Logon Registry Entry](/endpoint/auto_admin_logon_registry_entry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials) | TTP | | [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [BITS Job Persistence](/endpoint/bits_job_persistence/) | [BITS Jobs](/tags/#bits-jobs) | TTP | | [BITSAdmin Download File](/endpoint/bitsadmin_download_file/) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | -| [Batch File Write to System32](/endpoint/batch_file_write_to_system32/) | [Malicious File](/tags/#malicious-file) | TTP | +| [Batch File Write to System32](/endpoint/batch_file_write_to_system32/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file) | TTP | | [Bcdedit Command Back To Normal Mode Boot](/endpoint/bcdedit_command_back_to_normal_mode_boot/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [CHCP Command Execution](/endpoint/chcp_command_execution/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | TTP | -| [CMD Echo Pipe - Escalation](/endpoint/cmd_echo_pipe_-_escalation/) | [Windows Command Shell](/tags/#windows-command-shell), [Windows Service](/tags/#windows-service) | TTP | -| [CMLUA Or CMSTPLUA UAC Bypass](/endpoint/cmlua_or_cmstplua_uac_bypass/) | [CMSTP](/tags/#cmstp) | TTP | +| [CMD Echo Pipe - Escalation](/endpoint/cmd_echo_pipe_-_escalation/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | +| [CMLUA Or CMSTPLUA UAC Bypass](/endpoint/cmlua_or_cmstplua_uac_bypass/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | TTP | | [CertUtil Download With URLCache and Split Arguments](/endpoint/certutil_download_with_urlcache_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [CertUtil Download With VerifyCtl and Split Arguments](/endpoint/certutil_download_with_verifyctl_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [CertUtil With Decode Argument](/endpoint/certutil_with_decode_argument/) | [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information) | TTP | | [Certutil exe certificate extraction]() | None | TTP | +| [Change Default File Association](/endpoint/change_default_file_association/) | [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [Change To Safe Mode With Network Config](/endpoint/change_to_safe_mode_with_network_config/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Check Elevated CMD using whoami](/endpoint/check_elevated_cmd_using_whoami/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | TTP | | [Child Processes of Spoolsv exe](/endpoint/child_processes_of_spoolsv_exe/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | TTP | | [Circle CI Disable Security Job](/cloud/circle_ci_disable_security_job/) | [Compromise Client Software Binary](/tags/#compromise-client-software-binary) | Anomaly | | [Circle CI Disable Security Step](/cloud/circle_ci_disable_security_step/) | [Compromise Client Software Binary](/tags/#compromise-client-software-binary) | Anomaly | -| [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion) | TTP | +| [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [Clop Common Exec Parameter](/endpoint/clop_common_exec_parameter/) | [User Execution](/tags/#user-execution) | TTP | | [Clop Ransomware Known Service Name](/endpoint/clop_ransomware_known_service_name/) | [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [Cloud API Calls From Previously Unseen User Roles](/cloud/cloud_api_calls_from_previously_unseen_user_roles/) | [Valid Accounts](/tags/#valid-accounts) | Anomaly | -| [Cloud Compute Instance Created By Previously Unseen User](/cloud/cloud_compute_instance_created_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | +| [Cloud Compute Instance Created By Previously Unseen User](/cloud/cloud_compute_instance_created_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | | [Cloud Compute Instance Created In Previously Unused Region](/cloud/cloud_compute_instance_created_in_previously_unused_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | Anomaly | | [Cloud Compute Instance Created With Previously Unseen Image]() | None | Anomaly | | [Cloud Compute Instance Created With Previously Unseen Instance Type]() | None | Anomaly | -| [Cloud Instance Modified By Previously Unseen User](/cloud/cloud_instance_modified_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | +| [Cloud Instance Modified By Previously Unseen User](/cloud/cloud_instance_modified_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | | [Cloud Provisioning Activity From Previously Unseen City](/cloud/cloud_provisioning_activity_from_previously_unseen_city/) | [Valid Accounts](/tags/#valid-accounts) | Anomaly | | [Cloud Provisioning Activity From Previously Unseen Country](/cloud/cloud_provisioning_activity_from_previously_unseen_country/) | [Valid Accounts](/tags/#valid-accounts) | Anomaly | | [Cloud Provisioning Activity From Previously Unseen IP Address](/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address/) | [Valid Accounts](/tags/#valid-accounts) | Anomaly | | [Cloud Provisioning Activity From Previously Unseen Region](/cloud/cloud_provisioning_activity_from_previously_unseen_region/) | [Valid Accounts](/tags/#valid-accounts) | Anomaly | -| [Cmdline Tool Not Executed In CMD Shell](/endpoint/cmdline_tool_not_executed_in_cmd_shell/) | [JavaScript](/tags/#javascript) | TTP | +| [Cmdline Tool Not Executed In CMD Shell](/endpoint/cmdline_tool_not_executed_in_cmd_shell/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | TTP | | [Cobalt Strike Named Pipes](/endpoint/cobalt_strike_named_pipes/) | [Process Injection](/tags/#process-injection) | TTP | | [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [Conti Common Exec parameter](/endpoint/conti_common_exec_parameter/) | [User Execution](/tags/#user-execution) | TTP | -| [Control Loading from World Writable Directory](/endpoint/control_loading_from_world_writable_directory/) | [Control Panel](/tags/#control-panel) | TTP | -| [Correlation by Repository and Risk](/cloud/correlation_by_repository_and_risk/) | [Malicious Image](/tags/#malicious-image) | Correlation | -| [Correlation by User and Risk](/cloud/correlation_by_user_and_risk/) | [Malicious Image](/tags/#malicious-image) | Correlation | +| [Control Loading from World Writable Directory](/endpoint/control_loading_from_world_writable_directory/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Control Panel](/tags/#control-panel) | TTP | +| [Correlation by Repository and Risk](/cloud/correlation_by_repository_and_risk/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Correlation | +| [Correlation by User and Risk](/cloud/correlation_by_user_and_risk/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Correlation | | [Create Remote Thread In Shell Application](/endpoint/create_remote_thread_in_shell_application/) | [Process Injection](/tags/#process-injection) | TTP | -| [Create Remote Thread into LSASS](/endpoint/create_remote_thread_into_lsass/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Create Service In Suspicious File Path](/endpoint/create_service_in_suspicious_file_path/) | [Service Execution](/tags/#service-execution) | TTP | -| [Create local admin accounts using net exe](/endpoint/create_local_admin_accounts_using_net_exe/) | [Local Account](/tags/#local-account) | TTP | -| [Create or delete windows shares using net exe](/endpoint/create_or_delete_windows_shares_using_net_exe/) | [Network Share Connection Removal](/tags/#network-share-connection-removal) | TTP | -| [Creation of Shadow Copy](/endpoint/creation_of_shadow_copy/) | [NTDS](/tags/#ntds) | TTP | -| [Creation of Shadow Copy with wmic and powershell](/endpoint/creation_of_shadow_copy_with_wmic_and_powershell/) | [NTDS](/tags/#ntds) | TTP | -| [Creation of lsass Dump with Taskmgr](/endpoint/creation_of_lsass_dump_with_taskmgr/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Credential Dumping via Copy Command from Shadow Copy](/endpoint/credential_dumping_via_copy_command_from_shadow_copy/) | [NTDS](/tags/#ntds) | TTP | -| [Credential Dumping via Symlink to Shadow Copy](/endpoint/credential_dumping_via_symlink_to_shadow_copy/) | [NTDS](/tags/#ntds) | TTP | +| [Create Remote Thread into LSASS](/endpoint/create_remote_thread_into_lsass/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Create Service In Suspicious File Path](/endpoint/create_service_in_suspicious_file_path/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | TTP | +| [Create local admin accounts using net exe](/endpoint/create_local_admin_accounts_using_net_exe/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account) | TTP | +| [Create or delete windows shares using net exe](/endpoint/create_or_delete_windows_shares_using_net_exe/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Network Share Connection Removal](/tags/#network-share-connection-removal) | TTP | +| [Creation of Shadow Copy](/endpoint/creation_of_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Creation of Shadow Copy with wmic and powershell](/endpoint/creation_of_shadow_copy_with_wmic_and_powershell/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Creation of lsass Dump with Taskmgr](/endpoint/creation_of_lsass_dump_with_taskmgr/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Credential Dumping via Copy Command from Shadow Copy](/endpoint/credential_dumping_via_copy_command_from_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Credential Dumping via Symlink to Shadow Copy](/endpoint/credential_dumping_via_symlink_to_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction indicative of FGDump and CacheDump with s option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction indicative of FGDump and CacheDump with v option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction indicative of Lazagne command line options](/endpoint/credential_extraction_indicative_of_lazagne_command_line_options/) | [OS Credential Dumping](/tags/#os-credential-dumping), [Credentials from Password Stores](/tags/#credentials-from-password-stores) | TTP | @@ -123,230 +125,234 @@ sidebar: | [Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals](/endpoint/credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [DLLHost with no Command Line Arguments with Network](/endpoint/dllhost_with_no_command_line_arguments_with_network/) | [Process Injection](/tags/#process-injection) | TTP | | [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | -| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns) | Anomaly | -| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | Anomaly | +| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | Anomaly | +| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | | [DSQuery Domain Discovery](/endpoint/dsquery_domain_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | | [Delete A Net User](/endpoint/delete_a_net_user/) | [Service Stop](/tags/#service-stop) | Anomaly | | [Delete ShadowCopy With PowerShell](/endpoint/delete_shadowcopy_with_powershell/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Deleting Of Net Users](/endpoint/deleting_of_net_users/) | [Account Access Removal](/tags/#account-access-removal) | TTP | | [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Deny Permission using Cacls Utility](/endpoint/deny_permission_using_cacls_utility/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | -| [Detect ARP Poisoning](/network/detect_arp_poisoning/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | +| [Detect ARP Poisoning](/network/detect_arp_poisoning/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Man-in-the-Middle](/tags/#man-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | | [Detect AWS Console Login by New User]() | None | Hunting | | [Detect AWS Console Login by User from New City](/cloud/detect_aws_console_login_by_user_from_new_city/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | Hunting | | [Detect AWS Console Login by User from New Country](/cloud/detect_aws_console_login_by_user_from_new_country/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | Hunting | | [Detect AWS Console Login by User from New Region](/cloud/detect_aws_console_login_by_user_from_new_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | Hunting | -| [Detect Activity Related to Pass the Hash Attacks](/endpoint/detect_activity_related_to_pass_the_hash_attacks/) | [Pass the Hash](/tags/#pass-the-hash) | TTP | -| [Detect AzureHound Command-Line Arguments](/endpoint/detect_azurehound_command-line_arguments/) | [Domain Account](/tags/#domain-account), [Local Account](/tags/#local-account), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Domain Groups](/tags/#domain-groups), [Local Groups](/tags/#local-groups) | TTP | -| [Detect AzureHound File Modifications](/endpoint/detect_azurehound_file_modifications/) | [Domain Account](/tags/#domain-account), [Local Account](/tags/#local-account), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Domain Groups](/tags/#domain-groups), [Local Groups](/tags/#local-groups) | TTP | +| [Detect Activity Related to Pass the Hash Attacks](/endpoint/detect_activity_related_to_pass_the_hash_attacks/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [Detect AzureHound Command-Line Arguments](/endpoint/detect_azurehound_command-line_arguments/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | TTP | +| [Detect AzureHound File Modifications](/endpoint/detect_azurehound_file_modifications/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | TTP | | [Detect Baron Samedit CVE-2021-3156](/endpoint/detect_baron_samedit_cve-2021-3156/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | TTP | | [Detect Baron Samedit CVE-2021-3156 Segfault](/endpoint/detect_baron_samedit_cve-2021-3156_segfault/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | TTP | | [Detect Baron Samedit CVE-2021-3156 via OSQuery](/endpoint/detect_baron_samedit_cve-2021-3156_via_osquery/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | TTP | | [Detect Computer Changed with Anonymous Account](/endpoint/detect_computer_changed_with_anonymous_account/) | [Exploitation of Remote Services](/tags/#exploitation-of-remote-services) | Hunting | -| [Detect Copy of ShadowCopy with Script Block Logging](/endpoint/detect_copy_of_shadowcopy_with_script_block_logging/) | [Security Account Manager](/tags/#security-account-manager) | TTP | -| [Detect Credential Dumping through LSASS access](/endpoint/detect_credential_dumping_through_lsass_access/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Detect Dump LSASS Memory using comsvcs](/endpoint/detect_dump_lsass_memory_using_comsvcs/) | [NTDS](/tags/#ntds) | TTP | -| [Detect Empire with PowerShell Script Block Logging](/endpoint/detect_empire_with_powershell_script_block_logging/) | [PowerShell](/tags/#powershell) | TTP | -| [Detect Excessive Account Lockouts From Endpoint](/endpoint/detect_excessive_account_lockouts_from_endpoint/) | [Domain Accounts](/tags/#domain-accounts) | Anomaly | -| [Detect Excessive User Account Lockouts](/endpoint/detect_excessive_user_account_lockouts/) | [Local Accounts](/tags/#local-accounts) | Anomaly | -| [Detect Exchange Web Shell](/endpoint/detect_exchange_web_shell/) | [Web Shell](/tags/#web-shell) | TTP | +| [Detect Copy of ShadowCopy with Script Block Logging](/endpoint/detect_copy_of_shadowcopy_with_script_block_logging/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Detect Credential Dumping through LSASS access](/endpoint/detect_credential_dumping_through_lsass_access/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Detect Dump LSASS Memory using comsvcs](/endpoint/detect_dump_lsass_memory_using_comsvcs/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Detect Empire with PowerShell Script Block Logging](/endpoint/detect_empire_with_powershell_script_block_logging/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Detect Excessive Account Lockouts From Endpoint](/endpoint/detect_excessive_account_lockouts_from_endpoint/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | Anomaly | +| [Detect Excessive User Account Lockouts](/endpoint/detect_excessive_user_account_lockouts/) | [Valid Accounts](/tags/#valid-accounts), [Local Accounts](/tags/#local-accounts) | Anomaly | +| [Detect Exchange Web Shell](/endpoint/detect_exchange_web_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | TTP | | [Detect F5 TMUI RCE CVE-2020-5902](/web/detect_f5_tmui_rce_cve-2020-5902/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | TTP | | [Detect GCP Storage access from a new IP](/cloud/detect_gcp_storage_access_from_a_new_ip/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | Anomaly | -| [Detect HTML Help Renamed](/endpoint/detect_html_help_renamed/) | [Compiled HTML File](/tags/#compiled-html-file) | Hunting | -| [Detect HTML Help Spawn Child Process](/endpoint/detect_html_help_spawn_child_process/) | [Compiled HTML File](/tags/#compiled-html-file) | TTP | -| [Detect HTML Help URL in Command Line](/endpoint/detect_html_help_url_in_command_line/) | [Compiled HTML File](/tags/#compiled-html-file) | TTP | -| [Detect HTML Help Using InfoTech Storage Handlers](/endpoint/detect_html_help_using_infotech_storage_handlers/) | [Compiled HTML File](/tags/#compiled-html-file) | TTP | -| [Detect IPv6 Network Infrastructure Threats](/network/detect_ipv6_network_infrastructure_threats/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | -| [Detect Kerberoasting](/endpoint/detect_kerberoasting/) | [Kerberoasting](/tags/#kerberoasting) | TTP | +| [Detect HTML Help Renamed](/endpoint/detect_html_help_renamed/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | Hunting | +| [Detect HTML Help Spawn Child Process](/endpoint/detect_html_help_spawn_child_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | TTP | +| [Detect HTML Help URL in Command Line](/endpoint/detect_html_help_url_in_command_line/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | TTP | +| [Detect HTML Help Using InfoTech Storage Handlers](/endpoint/detect_html_help_using_infotech_storage_handlers/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | TTP | +| [Detect IPv6 Network Infrastructure Threats](/network/detect_ipv6_network_infrastructure_threats/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Man-in-the-Middle](/tags/#man-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | +| [Detect Kerberoasting](/endpoint/detect_kerberoasting/) | [Kerberoasting](/tags/#kerberoasting), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | | [Detect Large Outbound ICMP Packets](/network/detect_large_outbound_icmp_packets/) | [Non-Application Layer Protocol](/tags/#non-application-layer-protocol) | TTP | -| [Detect MSHTA Url in Command Line](/endpoint/detect_mshta_url_in_command_line/) | [Mshta](/tags/#mshta) | TTP | -| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory) | TTP | +| [Detect MSHTA Url in Command Line](/endpoint/detect_mshta_url_in_command_line/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Detect Mimikatz With PowerShell Script Block Logging](/endpoint/detect_mimikatz_with_powershell_script_block_logging/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Detect New Local Admin account](/endpoint/detect_new_local_admin_account/) | [Local Account](/tags/#local-account) | TTP | +| [Detect New Local Admin account](/endpoint/detect_new_local_admin_account/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account) | TTP | | [Detect New Login Attempts to Routers]() | None | TTP | | [Detect New Open GCP Storage Buckets](/cloud/detect_new_open_gcp_storage_buckets/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | TTP | | [Detect New Open S3 Buckets over AWS CLI](/cloud/detect_new_open_s3_buckets_over_aws_cli/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | TTP | | [Detect New Open S3 buckets](/cloud/detect_new_open_s3_buckets/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | TTP | -| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols) | TTP | -| [Detect Outlook exe writing a zip file](/endpoint/detect_outlook_exe_writing_a_zip_file/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Detect Pass the Hash](/endpoint/detect_pass_the_hash/) | [Pass the Hash](/tags/#pass-the-hash) | TTP | -| [Detect Path Interception By Creation Of program exe](/endpoint/detect_path_interception_by_creation_of_program_exe/) | [Path Interception by Unquoted Path](/tags/#path-interception-by-unquoted-path) | TTP | -| [Detect Port Security Violation](/network/detect_port_security_violation/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | -| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Windows Command Shell](/tags/#windows-command-shell) | Hunting | +| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol) | TTP | +| [Detect Outlook exe writing a zip file](/endpoint/detect_outlook_exe_writing_a_zip_file/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Detect Pass the Hash](/endpoint/detect_pass_the_hash/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [Detect Path Interception By Creation Of program exe](/endpoint/detect_path_interception_by_creation_of_program_exe/) | [Path Interception by Unquoted Path](/tags/#path-interception-by-unquoted-path), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | +| [Detect Port Security Violation](/network/detect_port_security_violation/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Man-in-the-Middle](/tags/#man-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | +| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | Hunting | | [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | | [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration) | TTP | | [Detect Rare Executables]() | None | Anomaly | -| [Detect Regasm Spawning a Process](/endpoint/detect_regasm_spawning_a_process/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | -| [Detect Regasm with Network Connection](/endpoint/detect_regasm_with_network_connection/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | -| [Detect Regasm with no Command Line Arguments](/endpoint/detect_regasm_with_no_command_line_arguments/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | -| [Detect Regsvcs Spawning a Process](/endpoint/detect_regsvcs_spawning_a_process/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | -| [Detect Regsvcs with Network Connection](/endpoint/detect_regsvcs_with_network_connection/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | -| [Detect Regsvcs with No Command Line Arguments](/endpoint/detect_regsvcs_with_no_command_line_arguments/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | -| [Detect Regsvr32 Application Control Bypass](/endpoint/detect_regsvr32_application_control_bypass/) | [Regsvr32](/tags/#regsvr32) | TTP | -| [Detect Renamed 7-Zip](/endpoint/detect_renamed_7-zip/) | [Archive via Utility](/tags/#archive-via-utility) | Hunting | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [Service Execution](/tags/#service-execution) | Hunting | +| [Detect Regasm Spawning a Process](/endpoint/detect_regasm_spawning_a_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regasm with Network Connection](/endpoint/detect_regasm_with_network_connection/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regasm with no Command Line Arguments](/endpoint/detect_regasm_with_no_command_line_arguments/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regsvcs Spawning a Process](/endpoint/detect_regsvcs_spawning_a_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regsvcs with Network Connection](/endpoint/detect_regsvcs_with_network_connection/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regsvcs with No Command Line Arguments](/endpoint/detect_regsvcs_with_no_command_line_arguments/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regsvr32 Application Control Bypass](/endpoint/detect_regsvr32_application_control_bypass/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | TTP | +| [Detect Renamed 7-Zip](/endpoint/detect_renamed_7-zip/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Hunting | +| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Hunting | | [Detect Renamed RClone](/endpoint/detect_renamed_rclone/) | [Automated Exfiltration](/tags/#automated-exfiltration) | Hunting | -| [Detect Renamed WinRAR](/endpoint/detect_renamed_winrar/) | [Archive via Utility](/tags/#archive-via-utility) | Hunting | +| [Detect Renamed WinRAR](/endpoint/detect_renamed_winrar/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Hunting | | [Detect Rogue DHCP Server](/network/detect_rogue_dhcp_server/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Man-in-the-Middle](/tags/#man-in-the-middle) | TTP | -| [Detect Rundll32 Application Control Bypass - advpack](/endpoint/detect_rundll32_application_control_bypass_-_advpack/) | [Rundll32](/tags/#rundll32) | TTP | -| [Detect Rundll32 Application Control Bypass - setupapi](/endpoint/detect_rundll32_application_control_bypass_-_setupapi/) | [Rundll32](/tags/#rundll32) | TTP | -| [Detect Rundll32 Application Control Bypass - syssetup](/endpoint/detect_rundll32_application_control_bypass_-_syssetup/) | [Rundll32](/tags/#rundll32) | TTP | -| [Detect Rundll32 Inline HTA Execution](/endpoint/detect_rundll32_inline_hta_execution/) | [Mshta](/tags/#mshta) | TTP | +| [Detect Rundll32 Application Control Bypass - advpack](/endpoint/detect_rundll32_application_control_bypass_-_advpack/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Detect Rundll32 Application Control Bypass - setupapi](/endpoint/detect_rundll32_application_control_bypass_-_setupapi/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Detect Rundll32 Application Control Bypass - syssetup](/endpoint/detect_rundll32_application_control_bypass_-_syssetup/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Detect Rundll32 Inline HTA Execution](/endpoint/detect_rundll32_inline_hta_execution/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | | [Detect S3 access from a new IP](/cloud/detect_s3_access_from_a_new_ip/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | Anomaly | | [Detect SNICat SNI Exfiltration](/network/detect_snicat_sni_exfiltration/) | [Exfiltration Over C2 Channel](/tags/#exfiltration-over-c2-channel) | TTP | -| [Detect SharpHound Command-Line Arguments](/endpoint/detect_sharphound_command-line_arguments/) | [Domain Account](/tags/#domain-account), [Local Account](/tags/#local-account), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Domain Groups](/tags/#domain-groups), [Local Groups](/tags/#local-groups) | TTP | -| [Detect SharpHound File Modifications](/endpoint/detect_sharphound_file_modifications/) | [Domain Account](/tags/#domain-account), [Local Account](/tags/#local-account), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Domain Groups](/tags/#domain-groups), [Local Groups](/tags/#local-groups) | TTP | -| [Detect SharpHound Usage](/endpoint/detect_sharphound_usage/) | [Domain Account](/tags/#domain-account), [Local Account](/tags/#local-account), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Domain Groups](/tags/#domain-groups), [Local Groups](/tags/#local-groups) | TTP | -| [Detect Software Download To Network Device](/network/detect_software_download_to_network_device/) | [TFTP Boot](/tags/#tftp-boot) | TTP | +| [Detect SharpHound Command-Line Arguments](/endpoint/detect_sharphound_command-line_arguments/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | TTP | +| [Detect SharpHound File Modifications](/endpoint/detect_sharphound_file_modifications/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | TTP | +| [Detect SharpHound Usage](/endpoint/detect_sharphound_usage/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | TTP | +| [Detect Software Download To Network Device](/network/detect_software_download_to_network_device/) | [TFTP Boot](/tags/#tftp-boot), [Pre-OS Boot](/tags/#pre-os-boot) | TTP | | [Detect Spike in AWS Security Hub Alerts for EC2 Instance]() | None | Anomaly | | [Detect Spike in AWS Security Hub Alerts for User]() | None | Anomaly | | [Detect Spike in S3 Bucket deletion](/cloud/detect_spike_in_s3_bucket_deletion/) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | Anomaly | | [Detect Spike in blocked Outbound Traffic from your AWS]() | None | Anomaly | -| [Detect Traffic Mirroring](/network/detect_traffic_mirroring/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Traffic Duplication](/tags/#traffic-duplication) | TTP | +| [Detect Traffic Mirroring](/network/detect_traffic_mirroring/) | [Hardware Additions](/tags/#hardware-additions), [Automated Exfiltration](/tags/#automated-exfiltration), [Network Denial of Service](/tags/#network-denial-of-service), [Traffic Duplication](/tags/#traffic-duplication) | TTP | | [Detect Unauthorized Assets by MAC address]() | None | TTP | -| [Detect Use of cmd exe to Launch Script Interpreters](/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters/) | [Windows Command Shell](/tags/#windows-command-shell) | TTP | -| [Detect WMI Event Subscription Persistence](/endpoint/detect_wmi_event_subscription_persistence/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription) | TTP | +| [Detect Use of cmd exe to Launch Script Interpreters](/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | TTP | +| [Detect WMI Event Subscription Persistence](/endpoint/detect_wmi_event_subscription_persistence/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [Detect Windows DNS SIGRed via Splunk Stream](/network/detect_windows_dns_sigred_via_splunk_stream/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | TTP | | [Detect Windows DNS SIGRed via Zeek](/network/detect_windows_dns_sigred_via_zeek/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | TTP | | [Detect Zerologon via Zeek](/network/detect_zerologon_via_zeek/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | TTP | | [Detect attackers scanning for vulnerable JBoss servers](/web/detect_attackers_scanning_for_vulnerable_jboss_servers/) | [System Information Discovery](/tags/#system-information-discovery) | TTP | | [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise) | TTP | | [Detect malicious requests to exploit JBoss servers]() | None | TTP | -| [Detect mshta inline hta execution](/endpoint/detect_mshta_inline_hta_execution/) | [Mshta](/tags/#mshta) | TTP | -| [Detect mshta renamed](/endpoint/detect_mshta_renamed/) | [Mshta](/tags/#mshta) | Hunting | +| [Detect mshta inline hta execution](/endpoint/detect_mshta_inline_hta_execution/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [Detect mshta renamed](/endpoint/detect_mshta_renamed/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | Hunting | | [Detect processes used for System Network Configuration Discovery](/endpoint/detect_processes_used_for_system_network_configuration_discovery/) | [System Network Configuration Discovery](/tags/#system-network-configuration-discovery) | TTP | | [Detect shared ec2 snapshot](/cloud/detect_shared_ec2_snapshot/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | TTP | | [Detection of tools built by NirSoft](/endpoint/detection_of_tools_built_by_nirsoft/) | [Software Deployment Tools](/tags/#software-deployment-tools) | TTP | -| [Disable AMSI Through Registry](/endpoint/disable_amsi_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disable ETW Through Registry](/endpoint/disable_etw_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disable Logs Using WevtUtil](/endpoint/disable_logs_using_wevtutil/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Disable AMSI Through Registry](/endpoint/disable_amsi_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable ETW Through Registry](/endpoint/disable_etw_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable Logs Using WevtUtil](/endpoint/disable_logs_using_wevtutil/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | | [Disable Net User Account](/endpoint/disable_net_user_account/) | [Service Stop](/tags/#service-stop) | TTP | -| [Disable Registry Tool](/endpoint/disable_registry_tool/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disable Show Hidden Files](/endpoint/disable_show_hidden_files/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disable Windows App Hotkeys](/endpoint/disable_windows_app_hotkeys/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disable Windows SmartScreen Protection](/endpoint/disable_windows_smartscreen_protection/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling CMD Application](/endpoint/disabling_cmd_application/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling ControlPanel](/endpoint/disabling_controlpanel/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling Firewall with Netsh](/endpoint/disabling_firewall_with_netsh/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling FolderOptions Windows Feature](/endpoint/disabling_folderoptions_windows_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Disable Registry Tool](/endpoint/disable_registry_tool/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable Security Logs Using MiniNt Registry](/endpoint/disable_security_logs_using_minint_registry/) | [Modify Registry](/tags/#modify-registry) | TTP | +| [Disable Show Hidden Files](/endpoint/disable_show_hidden_files/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Hide Artifacts](/tags/#hide-artifacts), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable UAC Remote Restriction](/endpoint/disable_uac_remote_restriction/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Disable Windows App Hotkeys](/endpoint/disable_windows_app_hotkeys/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable Windows SmartScreen Protection](/endpoint/disable_windows_smartscreen_protection/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling CMD Application](/endpoint/disabling_cmd_application/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling ControlPanel](/endpoint/disabling_controlpanel/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling Firewall with Netsh](/endpoint/disabling_firewall_with_netsh/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling FolderOptions Windows Feature](/endpoint/disabling_folderoptions_windows_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disabling Net User Account](/endpoint/disabling_net_user_account/) | [Account Access Removal](/tags/#account-access-removal) | TTP | -| [Disabling NoRun Windows App](/endpoint/disabling_norun_windows_app/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [Disabling SystemRestore In Registry](/endpoint/disabling_systemrestore_in_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling Task Manager](/endpoint/disabling_task_manager/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Domain Account Discovery With Net App](/endpoint/domain_account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account) | TTP | -| [Domain Account Discovery with Dsquery](/endpoint/domain_account_discovery_with_dsquery/) | [Domain Account](/tags/#domain-account) | Hunting | -| [Domain Account Discovery with Wmic](/endpoint/domain_account_discovery_with_wmic/) | [Domain Account](/tags/#domain-account) | TTP | +| [Disabling NoRun Windows App](/endpoint/disabling_norun_windows_app/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Disabling SystemRestore In Registry](/endpoint/disabling_systemrestore_in_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling Task Manager](/endpoint/disabling_task_manager/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Domain Account Discovery With Net App](/endpoint/domain_account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | +| [Domain Account Discovery with Dsquery](/endpoint/domain_account_discovery_with_dsquery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | Hunting | +| [Domain Account Discovery with Wmic](/endpoint/domain_account_discovery_with_wmic/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | | [Domain Controller Discovery with Nltest](/endpoint/domain_controller_discovery_with_nltest/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | | [Domain Controller Discovery with Wmic](/endpoint/domain_controller_discovery_with_wmic/) | [Remote System Discovery](/tags/#remote-system-discovery) | Hunting | -| [Domain Group Discovery With Dsquery](/endpoint/domain_group_discovery_with_dsquery/) | [Domain Groups](/tags/#domain-groups) | Hunting | -| [Domain Group Discovery With Net](/endpoint/domain_group_discovery_with_net/) | [Domain Groups](/tags/#domain-groups) | Hunting | -| [Domain Group Discovery With Wmic](/endpoint/domain_group_discovery_with_wmic/) | [Domain Groups](/tags/#domain-groups) | Hunting | -| [Domain Group Discovery with Adsisearcher](/endpoint/domain_group_discovery_with_adsisearcher/) | [Domain Groups](/tags/#domain-groups) | TTP | +| [Domain Group Discovery With Dsquery](/endpoint/domain_group_discovery_with_dsquery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | +| [Domain Group Discovery With Net](/endpoint/domain_group_discovery_with_net/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | +| [Domain Group Discovery With Wmic](/endpoint/domain_group_discovery_with_wmic/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | +| [Domain Group Discovery with Adsisearcher](/endpoint/domain_group_discovery_with_adsisearcher/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | | [Download Files Using Telegram](/endpoint/download_files_using_telegram/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | -| [Drop IcedID License dat](/endpoint/drop_icedid_license_dat/) | [Malicious File](/tags/#malicious-file) | Hunting | -| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Dump LSASS via procdump](/endpoint/dump_lsass_via_procdump/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Elevated Group Discovery With Net](/endpoint/elevated_group_discovery_with_net/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [Elevated Group Discovery With Wmic](/endpoint/elevated_group_discovery_with_wmic/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [Elevated Group Discovery with PowerView](/endpoint/elevated_group_discovery_with_powerview/) | [Domain Groups](/tags/#domain-groups) | Hunting | +| [Drop IcedID License dat](/endpoint/drop_icedid_license_dat/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file) | Hunting | +| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Dump LSASS via procdump](/endpoint/dump_lsass_via_procdump/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Elevated Group Discovery With Net](/endpoint/elevated_group_discovery_with_net/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [Elevated Group Discovery With Wmic](/endpoint/elevated_group_discovery_with_wmic/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [Elevated Group Discovery with PowerView](/endpoint/elevated_group_discovery_with_powerview/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | | [Email Attachments With Lots Of Spaces]() | None | Anomaly | -| [Email files written outside of the Outlook directory](/application/email_files_written_outside_of_the_outlook_directory/) | [Local Email Collection](/tags/#local-email-collection) | TTP | -| [Email servers sending high volume traffic to hosts](/application/email_servers_sending_high_volume_traffic_to_hosts/) | [Remote Email Collection](/tags/#remote-email-collection) | Anomaly | +| [Email files written outside of the Outlook directory](/application/email_files_written_outside_of_the_outlook_directory/) | [Email Collection](/tags/#email-collection), [Local Email Collection](/tags/#local-email-collection) | TTP | +| [Email servers sending high volume traffic to hosts](/application/email_servers_sending_high_volume_traffic_to_hosts/) | [Email Collection](/tags/#email-collection), [Remote Email Collection](/tags/#remote-email-collection) | Anomaly | | [Enable RDP In Other Port Number](/endpoint/enable_rdp_in_other_port_number/) | [Remote Services](/tags/#remote-services) | TTP | +| [Enable WDigest UseLogonCredential Registry](/endpoint/enable_wdigest_uselogoncredential_registry/) | [Modify Registry](/tags/#modify-registry), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Enumerate Users Local Group Using Telegram](/endpoint/enumerate_users_local_group_using_telegram/) | [Account Discovery](/tags/#account-discovery) | TTP | -| [Esentutl SAM Copy](/endpoint/esentutl_sam_copy/) | [Security Account Manager](/tags/#security-account-manager) | Hunting | -| [Eventvwr UAC Bypass](/endpoint/eventvwr_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [Excel Spawning PowerShell](/endpoint/excel_spawning_powershell/) | [Security Account Manager](/tags/#security-account-manager) | TTP | -| [Excel Spawning Windows Script Host](/endpoint/excel_spawning_windows_script_host/) | [Security Account Manager](/tags/#security-account-manager) | TTP | +| [Esentutl SAM Copy](/endpoint/esentutl_sam_copy/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | Hunting | +| [Eventvwr UAC Bypass](/endpoint/eventvwr_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Excel Spawning PowerShell](/endpoint/excel_spawning_powershell/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Excel Spawning Windows Script Host](/endpoint/excel_spawning_windows_script_host/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Excessive Attempt To Disable Services](/endpoint/excessive_attempt_to_disable_services/) | [Service Stop](/tags/#service-stop) | Anomaly | -| [Excessive DNS Failures](/network/excessive_dns_failures/) | [DNS](/tags/#dns) | Anomaly | +| [Excessive DNS Failures](/network/excessive_dns_failures/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | Anomaly | | [Excessive Service Stop Attempt](/endpoint/excessive_service_stop_attempt/) | [Service Stop](/tags/#service-stop) | Anomaly | | [Excessive Usage Of Cacls App](/endpoint/excessive_usage_of_cacls_app/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | Anomaly | | [Excessive Usage Of Net App](/endpoint/excessive_usage_of_net_app/) | [Account Access Removal](/tags/#account-access-removal) | Anomaly | -| [Excessive Usage Of SC Service Utility](/endpoint/excessive_usage_of_sc_service_utility/) | [Service Execution](/tags/#service-execution) | Anomaly | -| [Excessive Usage Of Taskkill](/endpoint/excessive_usage_of_taskkill/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | Anomaly | +| [Excessive Usage Of SC Service Utility](/endpoint/excessive_usage_of_sc_service_utility/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Anomaly | +| [Excessive Usage Of Taskkill](/endpoint/excessive_usage_of_taskkill/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | Anomaly | | [Excessive Usage of NSLOOKUP App](/endpoint/excessive_usage_of_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | | [Excessive number of distinct processes created in Windows Temp folder](/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | Anomaly | -| [Excessive number of service control start as disabled](/endpoint/excessive_number_of_service_control_start_as_disabled/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | Anomaly | +| [Excessive number of service control start as disabled](/endpoint/excessive_number_of_service_control_start_as_disabled/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | Anomaly | | [Excessive number of taskhost processes](/endpoint/excessive_number_of_taskhost_processes/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Anomaly | | [Exchange PowerShell Abuse via SSRF](/endpoint/exchange_powershell_abuse_via_ssrf/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | TTP | -| [Exchange PowerShell Module Usage](/endpoint/exchange_powershell_module_usage/) | [PowerShell](/tags/#powershell) | TTP | +| [Exchange PowerShell Module Usage](/endpoint/exchange_powershell_module_usage/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading) | TTP | -| [Execute Javascript With Jscript COM CLSID](/endpoint/execute_javascript_with_jscript_com_clsid/) | [Visual Basic](/tags/#visual-basic) | TTP | -| [Execution of File with Multiple Extensions](/endpoint/execution_of_file_with_multiple_extensions/) | [Rename System Utilities](/tags/#rename-system-utilities) | TTP | -| [Extraction of Registry Hives](/endpoint/extraction_of_registry_hives/) | [Security Account Manager](/tags/#security-account-manager) | TTP | +| [Execute Javascript With Jscript COM CLSID](/endpoint/execute_javascript_with_jscript_com_clsid/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Visual Basic](/tags/#visual-basic) | TTP | +| [Execution of File with Multiple Extensions](/endpoint/execution_of_file_with_multiple_extensions/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | +| [Extraction of Registry Hives](/endpoint/extraction_of_registry_hives/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [File with Samsam Extension]() | None | TTP | | [First Time Seen Child Process of Zoom](/endpoint/first_time_seen_child_process_of_zoom/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | Anomaly | -| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [Service Execution](/tags/#service-execution) | Anomaly | +| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Anomaly | | [First time seen command line argument](/endpoint/first_time_seen_command_line_argument/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Regsvr32](/tags/#regsvr32), [Indirect Command Execution](/tags/#indirect-command-execution) | Anomaly | -| [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | +| [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Fsutil Zeroing File](/endpoint/fsutil_zeroing_file/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [GCP Detect gcploit framework](/cloud/gcp_detect_gcploit_framework/) | [Valid Accounts](/tags/#valid-accounts) | TTP | | [GCP Kubernetes cluster pod scan detection](/cloud/gcp_kubernetes_cluster_pod_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | Hunting | | [GPUpdate with no Command Line Arguments with Network](/endpoint/gpupdate_with_no_command_line_arguments_with_network/) | [Process Injection](/tags/#process-injection) | TTP | -| [GSuite Email Suspicious Attachment](/cloud/gsuite_email_suspicious_attachment/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | Anomaly | +| [GSuite Email Suspicious Attachment](/cloud/gsuite_email_suspicious_attachment/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | | [Get ADDefaultDomainPasswordPolicy with Powershell](/endpoint/get_addefaultdomainpasswordpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery) | Hunting | | [Get ADDefaultDomainPasswordPolicy with Powershell Script Block](/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery) | Hunting | -| [Get ADUser with PowerShell](/endpoint/get_aduser_with_powershell/) | [Domain Account](/tags/#domain-account) | Hunting | -| [Get ADUser with PowerShell Script Block](/endpoint/get_aduser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account) | Hunting | +| [Get ADUser with PowerShell](/endpoint/get_aduser_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | Hunting | +| [Get ADUser with PowerShell Script Block](/endpoint/get_aduser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | Hunting | | [Get ADUserResultantPasswordPolicy with Powershell](/endpoint/get_aduserresultantpasswordpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery) | TTP | | [Get ADUserResultantPasswordPolicy with Powershell Script Block](/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery) | TTP | | [Get DomainPolicy with Powershell](/endpoint/get_domainpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery) | TTP | | [Get DomainPolicy with Powershell Script Block](/endpoint/get_domainpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery) | TTP | -| [Get DomainUser with PowerShell](/endpoint/get_domainuser_with_powershell/) | [Domain Account](/tags/#domain-account) | TTP | -| [Get DomainUser with PowerShell Script Block](/endpoint/get_domainuser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account) | TTP | -| [Get WMIObject Group Discovery](/endpoint/get_wmiobject_group_discovery/) | [Local Groups](/tags/#local-groups) | Hunting | -| [Get WMIObject Group Discovery with Script Block Logging](/endpoint/get_wmiobject_group_discovery_with_script_block_logging/) | [Local Groups](/tags/#local-groups) | Hunting | +| [Get DomainUser with PowerShell](/endpoint/get_domainuser_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | +| [Get DomainUser with PowerShell Script Block](/endpoint/get_domainuser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | +| [Get WMIObject Group Discovery](/endpoint/get_wmiobject_group_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | +| [Get WMIObject Group Discovery with Script Block Logging](/endpoint/get_wmiobject_group_discovery_with_script_block_logging/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | | [Get-DomainTrust with PowerShell](/endpoint/get-domaintrust_with_powershell/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | | [Get-DomainTrust with PowerShell Script Block](/endpoint/get-domaintrust_with_powershell_script_block/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | | [Get-ForestTrust with PowerShell](/endpoint/get-foresttrust_with_powershell/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | | [Get-ForestTrust with PowerShell Script Block](/endpoint/get-foresttrust_with_powershell_script_block/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | | [GetAdComputer with PowerShell](/endpoint/getadcomputer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | Hunting | | [GetAdComputer with PowerShell Script Block](/endpoint/getadcomputer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | Hunting | -| [GetAdGroup with PowerShell](/endpoint/getadgroup_with_powershell/) | [Domain Groups](/tags/#domain-groups) | Hunting | -| [GetAdGroup with PowerShell Script Block](/endpoint/getadgroup_with_powershell_script_block/) | [Domain Groups](/tags/#domain-groups) | Hunting | +| [GetAdGroup with PowerShell](/endpoint/getadgroup_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | +| [GetAdGroup with PowerShell Script Block](/endpoint/getadgroup_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | | [GetCurrent User with PowerShell](/endpoint/getcurrent_user_with_powershell/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Hunting | | [GetCurrent User with PowerShell Script Block](/endpoint/getcurrent_user_with_powershell_script_block/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Hunting | | [GetDomainComputer with PowerShell](/endpoint/getdomaincomputer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | | [GetDomainComputer with PowerShell Script Block](/endpoint/getdomaincomputer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | | [GetDomainController with PowerShell](/endpoint/getdomaincontroller_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | Hunting | | [GetDomainController with PowerShell Script Block](/endpoint/getdomaincontroller_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | -| [GetDomainGroup with PowerShell](/endpoint/getdomaingroup_with_powershell/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [GetDomainGroup with PowerShell Script Block](/endpoint/getdomaingroup_with_powershell_script_block/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [GetLocalUser with PowerShell](/endpoint/getlocaluser_with_powershell/) | [Local Account](/tags/#local-account) | Hunting | -| [GetLocalUser with PowerShell Script Block](/endpoint/getlocaluser_with_powershell_script_block/) | [Local Account](/tags/#local-account) | Hunting | +| [GetDomainGroup with PowerShell](/endpoint/getdomaingroup_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [GetDomainGroup with PowerShell Script Block](/endpoint/getdomaingroup_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [GetLocalUser with PowerShell](/endpoint/getlocaluser_with_powershell/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | +| [GetLocalUser with PowerShell Script Block](/endpoint/getlocaluser_with_powershell_script_block/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | | [GetNetTcpconnection with PowerShell](/endpoint/getnettcpconnection_with_powershell/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | Hunting | | [GetNetTcpconnection with PowerShell Script Block](/endpoint/getnettcpconnection_with_powershell_script_block/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | Hunting | -| [GetWmiObject DS User with PowerShell](/endpoint/getwmiobject_ds_user_with_powershell/) | [Domain Account](/tags/#domain-account) | TTP | -| [GetWmiObject DS User with PowerShell Script Block](/endpoint/getwmiobject_ds_user_with_powershell_script_block/) | [Domain Account](/tags/#domain-account) | TTP | +| [GetWmiObject DS User with PowerShell](/endpoint/getwmiobject_ds_user_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | +| [GetWmiObject DS User with PowerShell Script Block](/endpoint/getwmiobject_ds_user_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | | [GetWmiObject Ds Computer with PowerShell](/endpoint/getwmiobject_ds_computer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | | [GetWmiObject Ds Computer with PowerShell Script Block](/endpoint/getwmiobject_ds_computer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | -| [GetWmiObject Ds Group with PowerShell](/endpoint/getwmiobject_ds_group_with_powershell/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [GetWmiObject Ds Group with PowerShell Script Block](/endpoint/getwmiobject_ds_group_with_powershell_script_block/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [GetWmiObject User Account with PowerShell](/endpoint/getwmiobject_user_account_with_powershell/) | [Local Account](/tags/#local-account) | Hunting | -| [GetWmiObject User Account with PowerShell Script Block](/endpoint/getwmiobject_user_account_with_powershell_script_block/) | [Local Account](/tags/#local-account) | Hunting | -| [GitHub Dependabot Alert](/cloud/github_dependabot_alert/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools) | Anomaly | -| [GitHub Pull Request from Unknown User](/cloud/github_pull_request_from_unknown_user/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools) | Anomaly | +| [GetWmiObject Ds Group with PowerShell](/endpoint/getwmiobject_ds_group_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [GetWmiObject Ds Group with PowerShell Script Block](/endpoint/getwmiobject_ds_group_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [GetWmiObject User Account with PowerShell](/endpoint/getwmiobject_user_account_with_powershell/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | +| [GetWmiObject User Account with PowerShell Script Block](/endpoint/getwmiobject_user_account_with_powershell_script_block/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | +| [GitHub Dependabot Alert](/cloud/github_dependabot_alert/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools), [Supply Chain Compromise](/tags/#supply-chain-compromise) | Anomaly | +| [GitHub Pull Request from Unknown User](/cloud/github_pull_request_from_unknown_user/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools), [Supply Chain Compromise](/tags/#supply-chain-compromise) | Anomaly | | [Github Commit Changes In Master](/cloud/github_commit_changes_in_master/) | [Trusted Relationship](/tags/#trusted-relationship) | Anomaly | | [Github Commit In Develop](/cloud/github_commit_in_develop/) | [Trusted Relationship](/tags/#trusted-relationship) | Anomaly | | [Grant Permission Using Cacls Utility](/endpoint/grant_permission_using_cacls_utility/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | -| [Gsuite Drive Share In External Email](/cloud/gsuite_drive_share_in_external_email/) | [Exfiltration to Cloud Storage](/tags/#exfiltration-to-cloud-storage) | Anomaly | -| [Gsuite Email Suspicious Subject With Attachment](/cloud/gsuite_email_suspicious_subject_with_attachment/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | Anomaly | -| [Gsuite Email With Known Abuse Web Service Link](/cloud/gsuite_email_with_known_abuse_web_service_link/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | Anomaly | -| [Gsuite Outbound Email With Attachment To External Domain](/cloud/gsuite_outbound_email_with_attachment_to_external_domain/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | Anomaly | -| [Gsuite Suspicious Shared File Name](/cloud/gsuite_suspicious_shared_file_name/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | Anomaly | -| [Hide User Account From Sign-In Screen](/endpoint/hide_user_account_from_sign-in_screen/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | +| [Gsuite Drive Share In External Email](/cloud/gsuite_drive_share_in_external_email/) | [Exfiltration to Cloud Storage](/tags/#exfiltration-to-cloud-storage), [Exfiltration Over Web Service](/tags/#exfiltration-over-web-service) | Anomaly | +| [Gsuite Email Suspicious Subject With Attachment](/cloud/gsuite_email_suspicious_subject_with_attachment/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | +| [Gsuite Email With Known Abuse Web Service Link](/cloud/gsuite_email_with_known_abuse_web_service_link/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | +| [Gsuite Outbound Email With Attachment To External Domain](/cloud/gsuite_outbound_email_with_attachment_to_external_domain/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | +| [Gsuite Suspicious Shared File Name](/cloud/gsuite_suspicious_shared_file_name/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | +| [Hide User Account From Sign-In Screen](/endpoint/hide_user_account_from_sign-in_screen/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | | [High File Deletion Frequency](/endpoint/high_file_deletion_frequency/) | [Data Destruction](/tags/#data-destruction) | Anomaly | -| [High Number of Login Failures from a single source](/cloud/high_number_of_login_failures_from_a_single_source/) | [Password Guessing](/tags/#password-guessing) | Anomaly | +| [High Number of Login Failures from a single source](/cloud/high_number_of_login_failures_from_a_single_source/) | [Password Guessing](/tags/#password-guessing), [Brute Force](/tags/#brute-force) | Anomaly | | [High Process Termination Frequency](/endpoint/high_process_termination_frequency/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | Anomaly | -| [Hosts receiving high volume of network traffic from email server](/network/hosts_receiving_high_volume_of_network_traffic_from_email_server/) | [Remote Email Collection](/tags/#remote-email-collection) | Anomaly | +| [Hosts receiving high volume of network traffic from email server](/network/hosts_receiving_high_volume_of_network_traffic_from_email_server/) | [Remote Email Collection](/tags/#remote-email-collection), [Email Collection](/tags/#email-collection) | Anomaly | | [ICACLS Grant Command](/endpoint/icacls_grant_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [Icacls Deny Command](/endpoint/icacls_deny_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | -| [IcedID Exfiltrated Archived File Creation](/endpoint/icedid_exfiltrated_archived_file_creation/) | [Archive via Utility](/tags/#archive-via-utility) | Hunting | +| [IcedID Exfiltrated Archived File Creation](/endpoint/icedid_exfiltrated_archived_file_creation/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Hunting | | [Illegal Access To User Content via PowerSploit modules](/endpoint/illegal_access_to_user_content_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Screen Capture](/tags/#screen-capture), [Audio Capture](/tags/#audio-capture), [Remote Service Session Hijacking](/tags/#remote-service-session-hijacking) | TTP | | [Illegal Account Creation via PowerSploit modules](/endpoint/illegal_account_creation_via_powersploit_modules/) | [Establish Accounts](/tags/#establish-accounts) | TTP | | [Illegal Deletion of Logs via Mimikatz modules](/endpoint/illegal_deletion_of_logs_via_mimikatz_modules/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | @@ -357,121 +363,126 @@ sidebar: | [Illegal Privilege Elevation via Mimikatz modules](/endpoint/illegal_privilege_elevation_via_mimikatz_modules/) | [Access Token Manipulation](/tags/#access-token-manipulation), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Illegal Service and Process Control via Mimikatz modules](/endpoint/illegal_service_and_process_control_via_mimikatz_modules/) | [Process Injection](/tags/#process-injection), [Native API](/tags/#native-api), [System Services](/tags/#system-services) | TTP | | [Illegal Service and Process Control via PowerSploit modules](/endpoint/illegal_service_and_process_control_via_powersploit_modules/) | [Process Injection](/tags/#process-injection), [Native API](/tags/#native-api), [System Services](/tags/#system-services) | TTP | -| [Jscript Execution Using Cscript App](/endpoint/jscript_execution_using_cscript_app/) | [JavaScript](/tags/#javascript) | TTP | -| [Kerberoasting spn request with RC4 encryption](/endpoint/kerberoasting_spn_request_with_rc4_encryption/) | [Kerberoasting](/tags/#kerberoasting) | TTP | +| [Jscript Execution Using Cscript App](/endpoint/jscript_execution_using_cscript_app/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | TTP | +| [Kerberoasting spn request with RC4 encryption](/endpoint/kerberoasting_spn_request_with_rc4_encryption/) | [Kerberoasting](/tags/#kerberoasting), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | | [Known Services Killed by Ransomware](/endpoint/known_services_killed_by_ransomware/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Kubernetes AWS detect suspicious kubectl calls]() | None | Hunting | | [Kubernetes Nginx Ingress LFI](/cloud/kubernetes_nginx_ingress_lfi/) | [Exploitation for Credential Access](/tags/#exploitation-for-credential-access) | TTP | | [Kubernetes Nginx Ingress RFI](/cloud/kubernetes_nginx_ingress_rfi/) | [Exploitation for Credential Access](/tags/#exploitation-for-credential-access) | TTP | | [Kubernetes Scanner Image Pulling](/cloud/kubernetes_scanner_image_pulling/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | TTP | -| [Large Volume of DNS ANY Queries](/network/large_volume_of_dns_any_queries/) | [Reflection Amplification](/tags/#reflection-amplification) | Anomaly | -| [Local Account Discovery With Wmic](/endpoint/local_account_discovery_with_wmic/) | [Local Account](/tags/#local-account) | Hunting | -| [Local Account Discovery with Net](/endpoint/local_account_discovery_with_net/) | [Local Account](/tags/#local-account) | Hunting | -| [MS Scripting Process Loading Ldap Module](/endpoint/ms_scripting_process_loading_ldap_module/) | [JavaScript](/tags/#javascript) | Anomaly | -| [MS Scripting Process Loading WMI Module](/endpoint/ms_scripting_process_loading_wmi_module/) | [JavaScript](/tags/#javascript) | Anomaly | -| [MSHTML Module Load in Office Product](/endpoint/mshtml_module_load_in_office_product/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Large Volume of DNS ANY Queries](/network/large_volume_of_dns_any_queries/) | [Network Denial of Service](/tags/#network-denial-of-service), [Reflection Amplification](/tags/#reflection-amplification) | Anomaly | +| [Local Account Discovery With Wmic](/endpoint/local_account_discovery_with_wmic/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | +| [Local Account Discovery with Net](/endpoint/local_account_discovery_with_net/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | +| [Logon Script Event Trigger Execution](/endpoint/logon_script_event_trigger_execution/) | [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)) | TTP | +| [MS Scripting Process Loading Ldap Module](/endpoint/ms_scripting_process_loading_ldap_module/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | Anomaly | +| [MS Scripting Process Loading WMI Module](/endpoint/ms_scripting_process_loading_wmi_module/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | Anomaly | +| [MSBuild Suspicious Spawned By Script Process](/endpoint/msbuild_suspicious_spawned_by_script_process/) | [MSBuild](/tags/#msbuild), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution) | TTP | +| [MSHTML Module Load in Office Product](/endpoint/mshtml_module_load_in_office_product/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | | [MacOS - Re-opened Applications]() | None | TTP | -| [Mailsniper Invoke functions](/endpoint/mailsniper_invoke_functions/) | [Local Email Collection](/tags/#local-email-collection) | TTP | -| [Malicious PowerShell Process - Connect To Internet With Hidden Window](/endpoint/malicious_powershell_process_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell) | Hunting | +| [Mailsniper Invoke functions](/endpoint/mailsniper_invoke_functions/) | [Email Collection](/tags/#email-collection), [Local Email Collection](/tags/#local-email-collection) | TTP | +| [Malicious InProcServer32 Modification](/endpoint/malicious_inprocserver32_modification/) | [Regsvr32](/tags/#regsvr32), [Modify Registry](/tags/#modify-registry) | TTP | +| [Malicious PowerShell Process - Connect To Internet With Hidden Window](/endpoint/malicious_powershell_process_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | Hunting | | [Malicious PowerShell Process - Encoded Command](/endpoint/malicious_powershell_process_-_encoded_command/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information) | Hunting | -| [Malicious PowerShell Process - Execution Policy Bypass](/endpoint/malicious_powershell_process_-_execution_policy_bypass/) | [PowerShell](/tags/#powershell) | TTP | -| [Malicious PowerShell Process With Obfuscation Techniques](/endpoint/malicious_powershell_process_with_obfuscation_techniques/) | [PowerShell](/tags/#powershell) | TTP | -| [Malicious Powershell Executed As A Service](/endpoint/malicious_powershell_executed_as_a_service/) | [Service Execution](/tags/#service-execution) | TTP | +| [Malicious PowerShell Process - Execution Policy Bypass](/endpoint/malicious_powershell_process_-_execution_policy_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Malicious PowerShell Process With Obfuscation Techniques](/endpoint/malicious_powershell_process_with_obfuscation_techniques/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Malicious Powershell Executed As A Service](/endpoint/malicious_powershell_executed_as_a_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | TTP | | [Modification Of Wallpaper](/endpoint/modification_of_wallpaper/) | [Defacement](/tags/#defacement) | TTP | | [Modify ACL permission To Files Or Folder](/endpoint/modify_acl_permission_to_files_or_folder/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [Modify ACLs Permission Of Files Or Folders](/endpoint/modify_acls_permission_of_files_or_folders/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | Anomaly | | [Monitor Email For Brand Abuse]() | None | TTP | -| [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors) | TTP | +| [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Monitor Web Traffic For Brand Abuse]() | None | TTP | | [More than usual number of LOLBAS applications in short time period](/endpoint/more_than_usual_number_of_lolbas_applications_in_short_time_period/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Scheduled Task/Job](/tags/#scheduled-task/job) | Anomaly | -| [Mshta spawning Rundll32 OR Regsvr32 Process](/endpoint/mshta_spawning_rundll32_or_regsvr32_process/) | [Mshta](/tags/#mshta) | TTP | -| [Msmpeng Application DLL Side Loading](/endpoint/msmpeng_application_dll_side_loading/) | [DLL Side-Loading](/tags/#dll-side-loading) | TTP | -| [Multiple Archive Files Http Post Traffic](/network/multiple_archive_files_http_post_traffic/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | TTP | -| [Multiple Disabled Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Invalid Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Invalid Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Okta Users With Invalid Credentials From The Same IP](/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip/) | [Default Accounts](/tags/#default-accounts) | TTP | -| [Multiple Users Attempting To Authenticate Using Explicit Credentials](/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Users Failing To Authenticate From Process](/endpoint/multiple_users_failing_to_authenticate_from_process/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Users Remotely Failing To Authenticate From Host](/endpoint/multiple_users_remotely_failing_to_authenticate_from_host/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [NET Profiler UAC bypass](/endpoint/net_profiler_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | +| [Mshta spawning Rundll32 OR Regsvr32 Process](/endpoint/mshta_spawning_rundll32_or_regsvr32_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [Msmpeng Application DLL Side Loading](/endpoint/msmpeng_application_dll_side_loading/) | [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | +| [Multiple Archive Files Http Post Traffic](/network/multiple_archive_files_http_post_traffic/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | +| [Multiple Disabled Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Invalid Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Invalid Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Okta Users With Invalid Credentials From The Same IP](/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | TTP | +| [Multiple Users Attempting To Authenticate Using Explicit Credentials](/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Users Failing To Authenticate From Process](/endpoint/multiple_users_failing_to_authenticate_from_process/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Users Remotely Failing To Authenticate From Host](/endpoint/multiple_users_remotely_failing_to_authenticate_from_host/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [NET Profiler UAC bypass](/endpoint/net_profiler_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [NLTest Domain Trust Discovery](/endpoint/nltest_domain_trust_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | -| [Net Localgroup Discovery](/endpoint/net_localgroup_discovery/) | [Local Groups](/tags/#local-groups) | Hunting | +| [Net Localgroup Discovery](/endpoint/net_localgroup_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | | [Network Connection Discovery With Arp](/endpoint/network_connection_discovery_with_arp/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | Hunting | | [Network Connection Discovery With Net](/endpoint/network_connection_discovery_with_net/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | Hunting | | [Network Connection Discovery With Netstat](/endpoint/network_connection_discovery_with_netstat/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | Hunting | | [New container uploaded to AWS ECR](/cloud/new_container_uploaded_to_aws_ecr/) | [Implant Internal Image](/tags/#implant-internal-image) | Hunting | -| [Nishang PowershellTCPOneLine](/endpoint/nishang_powershelltcponeline/) | [PowerShell](/tags/#powershell) | TTP | +| [Nishang PowershellTCPOneLine](/endpoint/nishang_powershelltcponeline/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [No Windows Updates in a time frame]() | None | Hunting | -| [Non Chrome Process Accessing Chrome Default Dir](/endpoint/non_chrome_process_accessing_chrome_default_dir/) | [Credentials from Web Browsers](/tags/#credentials-from-web-browsers) | Anomaly | -| [Non Firefox Process Access Firefox Profile Dir](/endpoint/non_firefox_process_access_firefox_profile_dir/) | [Credentials from Web Browsers](/tags/#credentials-from-web-browsers) | Anomaly | -| [Ntdsutil Export NTDS](/endpoint/ntdsutil_export_ntds/) | [NTDS](/tags/#ntds) | TTP | -| [O365 Add App Role Assignment Grant User](/cloud/o365_add_app_role_assignment_grant_user/) | [Cloud Account](/tags/#cloud-account) | TTP | -| [O365 Added Service Principal](/cloud/o365_added_service_principal/) | [Cloud Account](/tags/#cloud-account) | TTP | -| [O365 Bypass MFA via Trusted IP](/cloud/o365_bypass_mfa_via_trusted_ip/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | TTP | +| [Non Chrome Process Accessing Chrome Default Dir](/endpoint/non_chrome_process_accessing_chrome_default_dir/) | [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers) | Anomaly | +| [Non Firefox Process Access Firefox Profile Dir](/endpoint/non_firefox_process_access_firefox_profile_dir/) | [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers) | Anomaly | +| [Ntdsutil Export NTDS](/endpoint/ntdsutil_export_ntds/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [O365 Add App Role Assignment Grant User](/cloud/o365_add_app_role_assignment_grant_user/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | +| [O365 Added Service Principal](/cloud/o365_added_service_principal/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | +| [O365 Bypass MFA via Trusted IP](/cloud/o365_bypass_mfa_via_trusted_ip/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | | [O365 Disable MFA](/cloud/o365_disable_mfa/) | [Modify Authentication Process](/tags/#modify-authentication-process) | TTP | | [O365 Excessive Authentication Failures Alert](/cloud/o365_excessive_authentication_failures_alert/) | [Brute Force](/tags/#brute-force) | Anomaly | | [O365 Excessive SSO logon errors](/cloud/o365_excessive_sso_logon_errors/) | [Modify Authentication Process](/tags/#modify-authentication-process) | Anomaly | -| [O365 New Federated Domain Added](/cloud/o365_new_federated_domain_added/) | [Cloud Account](/tags/#cloud-account) | TTP | +| [O365 New Federated Domain Added](/cloud/o365_new_federated_domain_added/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | | [O365 PST export alert](/cloud/o365_pst_export_alert/) | [Email Collection](/tags/#email-collection) | TTP | -| [O365 Suspicious Admin Email Forwarding](/cloud/o365_suspicious_admin_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule) | Anomaly | -| [O365 Suspicious Rights Delegation](/cloud/o365_suspicious_rights_delegation/) | [Remote Email Collection](/tags/#remote-email-collection) | TTP | -| [O365 Suspicious User Email Forwarding](/cloud/o365_suspicious_user_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule) | Anomaly | -| [Office Application Drop Executable](/endpoint/office_application_drop_executable/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Application Spawn Regsvr32 process](/endpoint/office_application_spawn_regsvr32_process/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Document Creating Schedule Task](/endpoint/office_document_creating_schedule_task/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Document Spawned Child Process To Download](/endpoint/office_document_spawned_child_process_to_download/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawn CMD Process](/endpoint/office_product_spawn_cmd_process/) | [Mshta](/tags/#mshta) | TTP | -| [Office Product Spawning BITSAdmin](/endpoint/office_product_spawning_bitsadmin/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawning CertUtil](/endpoint/office_product_spawning_certutil/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawning MSHTA](/endpoint/office_product_spawning_mshta/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawning Rundll32 with no DLL](/endpoint/office_product_spawning_rundll32_with_no_dll/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawning Wmic](/endpoint/office_product_spawning_wmic/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Writing cab or inf](/endpoint/office_product_writing_cab_or_inf/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Spawning Control](/endpoint/office_spawning_control/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Okta Account Lockout Events](/application/okta_account_lockout_events/) | [Default Accounts](/tags/#default-accounts) | Anomaly | -| [Okta Failed SSO Attempts](/application/okta_failed_sso_attempts/) | [Default Accounts](/tags/#default-accounts) | Anomaly | -| [Okta User Logins From Multiple Cities](/application/okta_user_logins_from_multiple_cities/) | [Default Accounts](/tags/#default-accounts) | Anomaly | -| [Overwriting Accessibility Binaries](/endpoint/overwriting_accessibility_binaries/) | [Accessibility Features](/tags/#accessibility-features) | TTP | +| [O365 Suspicious Admin Email Forwarding](/cloud/o365_suspicious_admin_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection) | Anomaly | +| [O365 Suspicious Rights Delegation](/cloud/o365_suspicious_rights_delegation/) | [Remote Email Collection](/tags/#remote-email-collection), [Email Collection](/tags/#email-collection) | TTP | +| [O365 Suspicious User Email Forwarding](/cloud/o365_suspicious_user_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection) | Anomaly | +| [Office Application Drop Executable](/endpoint/office_application_drop_executable/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Application Spawn Regsvr32 process](/endpoint/office_application_spawn_regsvr32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Document Creating Schedule Task](/endpoint/office_document_creating_schedule_task/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Document Spawned Child Process To Download](/endpoint/office_document_spawned_child_process_to_download/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawn CMD Process](/endpoint/office_product_spawn_cmd_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [Office Product Spawning BITSAdmin](/endpoint/office_product_spawning_bitsadmin/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawning CertUtil](/endpoint/office_product_spawning_certutil/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawning MSHTA](/endpoint/office_product_spawning_mshta/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawning Rundll32 with no DLL](/endpoint/office_product_spawning_rundll32_with_no_dll/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawning Wmic](/endpoint/office_product_spawning_wmic/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Writing cab or inf](/endpoint/office_product_writing_cab_or_inf/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Spawning Control](/endpoint/office_spawning_control/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Okta Account Lockout Events](/application/okta_account_lockout_events/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | Anomaly | +| [Okta Failed SSO Attempts](/application/okta_failed_sso_attempts/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | Anomaly | +| [Okta User Logins From Multiple Cities](/application/okta_user_logins_from_multiple_cities/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | Anomaly | +| [Overwriting Accessibility Binaries](/endpoint/overwriting_accessibility_binaries/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Accessibility Features](/tags/#accessibility-features) | TTP | | [Password Policy Discovery with Net](/endpoint/password_policy_discovery_with_net/) | [Password Policy Discovery](/tags/#password-policy-discovery) | Hunting | | [Permission Modification using Takeown App](/endpoint/permission_modification_using_takeown_app/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [PetitPotam Network Share Access Request](/endpoint/petitpotam_network_share_access_request/) | [Forced Authentication](/tags/#forced-authentication) | TTP | | [PetitPotam Suspicious Kerberos TGT Request](/endpoint/petitpotam_suspicious_kerberos_tgt_request/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Phishing Email Detection by Machine Learning Method - SSA](/application/phishing_email_detection_by_machine_learning_method_-_ssa/) | [Phishing](/tags/#phishing) | Anomaly | -| [Plain HTTP POST Exfiltrated Data](/network/plain_http_post_exfiltrated_data/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | TTP | -| [Potential Pass the Token or Hash Observed at the Destination Device](/endpoint/potential_pass_the_token_or_hash_observed_at_the_destination_device/) | [Pass the Hash](/tags/#pass-the-hash) | TTP | -| [Potential Pass the Token or Hash Observed by an Event Collecting Device](/endpoint/potential_pass_the_token_or_hash_observed_by_an_event_collecting_device/) | [Pass the Hash](/tags/#pass-the-hash) | TTP | -| [PowerShell 4104 Hunting](/endpoint/powershell_4104_hunting/) | [PowerShell](/tags/#powershell) | Hunting | -| [PowerShell Domain Enumeration](/endpoint/powershell_domain_enumeration/) | [PowerShell](/tags/#powershell) | TTP | -| [PowerShell Get LocalGroup Discovery](/endpoint/powershell_get_localgroup_discovery/) | [Local Groups](/tags/#local-groups) | Hunting | -| [PowerShell Loading DotNET into Memory via System Reflection Assembly](/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly/) | [PowerShell](/tags/#powershell) | TTP | +| [Plain HTTP POST Exfiltrated Data](/network/plain_http_post_exfiltrated_data/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | +| [Potential Pass the Token or Hash Observed at the Destination Device](/endpoint/potential_pass_the_token_or_hash_observed_at_the_destination_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [Potential Pass the Token or Hash Observed by an Event Collecting Device](/endpoint/potential_pass_the_token_or_hash_observed_by_an_event_collecting_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [PowerShell 4104 Hunting](/endpoint/powershell_4104_hunting/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | Hunting | +| [PowerShell Domain Enumeration](/endpoint/powershell_domain_enumeration/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [PowerShell Get LocalGroup Discovery](/endpoint/powershell_get_localgroup_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | +| [PowerShell Loading DotNET into Memory via System Reflection Assembly](/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [PowerShell Start-BitsTransfer](/endpoint/powershell_start-bitstransfer/) | [BITS Jobs](/tags/#bits-jobs) | TTP | -| [Powershell Creating Thread Mutex](/endpoint/powershell_creating_thread_mutex/) | [Indicator Removal from Tools](/tags/#indicator-removal-from-tools) | TTP | -| [Powershell Disable Security Monitoring](/endpoint/powershell_disable_security_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Powershell Enable SMB1Protocol Feature](/endpoint/powershell_enable_smb1protocol_feature/) | [Indicator Removal from Tools](/tags/#indicator-removal-from-tools) | TTP | -| [Powershell Execute COM Object](/endpoint/powershell_execute_com_object/) | [Component Object Model Hijacking](/tags/#component-object-model-hijacking) | TTP | -| [Powershell Fileless Process Injection via GetProcAddress](/endpoint/powershell_fileless_process_injection_via_getprocaddress/) | [Process Injection](/tags/#process-injection), [PowerShell](/tags/#powershell) | TTP | -| [Powershell Fileless Script Contains Base64 Encoded Content](/endpoint/powershell_fileless_script_contains_base64_encoded_content/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [PowerShell](/tags/#powershell) | TTP | -| [Powershell Get LocalGroup Discovery with Script Block Logging](/endpoint/powershell_get_localgroup_discovery_with_script_block_logging/) | [Local Groups](/tags/#local-groups) | Hunting | -| [Powershell Processing Stream Of Data](/endpoint/powershell_processing_stream_of_data/) | [PowerShell](/tags/#powershell) | TTP | +| [Powershell Creating Thread Mutex](/endpoint/powershell_creating_thread_mutex/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools) | TTP | +| [Powershell Disable Security Monitoring](/endpoint/powershell_disable_security_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Powershell Enable SMB1Protocol Feature](/endpoint/powershell_enable_smb1protocol_feature/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools) | TTP | +| [Powershell Execute COM Object](/endpoint/powershell_execute_com_object/) | [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Powershell Fileless Process Injection via GetProcAddress](/endpoint/powershell_fileless_process_injection_via_getprocaddress/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Process Injection](/tags/#process-injection), [PowerShell](/tags/#powershell) | TTP | +| [Powershell Fileless Script Contains Base64 Encoded Content](/endpoint/powershell_fileless_script_contains_base64_encoded_content/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [PowerShell](/tags/#powershell) | TTP | +| [Powershell Get LocalGroup Discovery with Script Block Logging](/endpoint/powershell_get_localgroup_discovery_with_script_block_logging/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | +| [Powershell Processing Stream Of Data](/endpoint/powershell_processing_stream_of_data/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Powershell Remote Thread To Known Windows Process](/endpoint/powershell_remote_thread_to_known_windows_process/) | [Process Injection](/tags/#process-injection) | TTP | | [Powershell Using memory As Backing Store](/endpoint/powershell_using_memory_as_backing_store/) | [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information) | TTP | | [Prevent Automatic Repair Mode using Bcdedit](/endpoint/prevent_automatic_repair_mode_using_bcdedit/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | -| [Print Spooler Adding A Printer Driver](/endpoint/print_spooler_adding_a_printer_driver/) | [Print Processors](/tags/#print-processors) | TTP | -| [Print Spooler Failed to Load a Plug-in](/endpoint/print_spooler_failed_to_load_a_plug-in/) | [Print Processors](/tags/#print-processors) | TTP | +| [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Print Spooler Adding A Printer Driver](/endpoint/print_spooler_adding_a_printer_driver/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Print Spooler Failed to Load a Plug-in](/endpoint/print_spooler_failed_to_load_a_plug-in/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Probing Access with Stolen Credentials via PowerSploit modules](/endpoint/probing_access_with_stolen_credentials_via_powersploit_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Process Creating LNK file in Suspicious Location](/endpoint/process_creating_lnk_file_in_suspicious_location/) | [Spearphishing Link](/tags/#spearphishing-link) | TTP | +| [Process Creating LNK file in Suspicious Location](/endpoint/process_creating_lnk_file_in_suspicious_location/) | [Phishing](/tags/#phishing), [Spearphishing Link](/tags/#spearphishing-link) | TTP | | [Process Deleting Its Process File Path](/endpoint/process_deleting_its_process_file_path/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [Process Execution via WMI](/endpoint/process_execution_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | -| [Process Kill Base On File Path](/endpoint/process_kill_base_on_file_path/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Process Kill Base On File Path](/endpoint/process_kill_base_on_file_path/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Process Writing DynamicWrapperX](/endpoint/process_writing_dynamicwrapperx/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Component Object Model](/tags/#component-object-model) | Hunting | | [Processes Tapping Keyboard Events]() | None | TTP | -| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall) | TTP | +| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Prohibited Network Traffic Allowed](/network/prohibited_network_traffic_allowed/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | -| [Protocol or Port Mismatch](/network/protocol_or_port_mismatch/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | Anomaly | +| [Protocol or Port Mismatch](/network/protocol_or_port_mismatch/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | | [Protocols passing authentication in cleartext]() | None | TTP | | [Ransomware Notes bulk creation](/endpoint/ransomware_notes_bulk_creation/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | Anomaly | | [Rare Parent-Child Process Relationship](/endpoint/rare_parent-child_process_relationship/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Scheduled Task/Job](/tags/#scheduled-task/job), [Software Deployment Tools](/tags/#software-deployment-tools) | Anomaly | @@ -482,26 +493,27 @@ sidebar: | [Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit modules](/endpoint/reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules/) | [Trusted Relationship](/tags/#trusted-relationship), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Gather Victim Org Information](/tags/#gather-victim-org-information), [Active Scanning](/tags/#active-scanning) | TTP | | [Reconnaissance and Access to Computers and Domains via PowerSploit modules](/endpoint/reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules/) | [Gather Victim Host Information](/tags/#gather-victim-host-information), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Account Discovery](/tags/#account-discovery) | TTP | | [Reconnaissance and Access to Computers via Mimikatz modules](/endpoint/reconnaissance_and_access_to_computers_via_mimikatz_modules/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | -| [Reconnaissance and Access to Operating System Elements via PowerSploit modules](/endpoint/reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules/) | [System Service Discovery](/tags/#system-service-discovery), [Query Registry](/tags/#query-registry), [Network Service Scanning](/tags/#network-service-scanning), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Process Discovery](/tags/#process-discovery), [File and Directory Discovery](/tags/#file-and-directory-discovery), [Software Discovery](/tags/#software-discovery), [Software](/tags/#software) | TTP | +| [Reconnaissance and Access to Operating System Elements via PowerSploit modules](/endpoint/reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules/) | [Process Discovery](/tags/#process-discovery), [File and Directory Discovery](/tags/#file-and-directory-discovery), [Software](/tags/#software), [Network Service Scanning](/tags/#network-service-scanning), [Query Registry](/tags/#query-registry), [System Service Discovery](/tags/#system-service-discovery), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Software Discovery](/tags/#software-discovery) | TTP | | [Reconnaissance and Access to Processes and Services via Mimikatz modules](/endpoint/reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules/) | [System Service Discovery](/tags/#system-service-discovery), [Network Service Scanning](/tags/#network-service-scanning), [Process Discovery](/tags/#process-discovery) | TTP | -| [Reconnaissance and Access to Shared Resources via Mimikatz modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_mimikatz_modules/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Network Share Discovery](/tags/#network-share-discovery), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive) | TTP | -| [Reconnaissance and Access to Shared Resources via PowerSploit modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_powersploit_modules/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Network Share Discovery](/tags/#network-share-discovery), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive) | TTP | +| [Reconnaissance and Access to Shared Resources via Mimikatz modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_mimikatz_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Reconnaissance and Access to Shared Resources via PowerSploit modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | | [Reconnaissance of Access and Persistence Opportunities via PowerSploit modules](/endpoint/reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | -| [Reconnaissance of Connectivity via PowerSploit modules](/endpoint/reconnaissance_of_connectivity_via_powersploit_modules/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Network Share Discovery](/tags/#network-share-discovery), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive) | TTP | -| [Reconnaissance of Credential Stores and Services via Mimikatz modules](/endpoint/reconnaissance_of_credential_stores_and_services_via_mimikatz_modules/) | [Credentials](/tags/#credentials), [Domain Properties](/tags/#domain-properties), [Network Trust Dependencies](/tags/#network-trust-dependencies), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Reconnaissance of Defensive Tools via PowerSploit modules](/endpoint/reconnaissance_of_defensive_tools_via_powersploit_modules/) | [Vulnerability Scanning](/tags/#vulnerability-scanning), [Software](/tags/#software) | TTP | +| [Reconnaissance of Connectivity via PowerSploit modules](/endpoint/reconnaissance_of_connectivity_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Reconnaissance of Credential Stores and Services via Mimikatz modules](/endpoint/reconnaissance_of_credential_stores_and_services_via_mimikatz_modules/) | [Account Manipulation](/tags/#account-manipulation), [Domain Properties](/tags/#domain-properties), [Valid Accounts](/tags/#valid-accounts), [Credentials](/tags/#credentials), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Gather Victim Identity Information](/tags/#gather-victim-identity-information), [Network Trust Dependencies](/tags/#network-trust-dependencies) | TTP | +| [Reconnaissance of Defensive Tools via PowerSploit modules](/endpoint/reconnaissance_of_defensive_tools_via_powersploit_modules/) | [Software](/tags/#software), [Vulnerability Scanning](/tags/#vulnerability-scanning), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Active Scanning](/tags/#active-scanning) | TTP | | [Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules](/endpoint/reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | | [Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules](/endpoint/reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Process Injection](/tags/#process-injection), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | -| [Recursive Delete of Directory In Batch CMD](/endpoint/recursive_delete_of_directory_in_batch_cmd/) | [File Deletion](/tags/#file-deletion) | TTP | -| [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness) | TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | -| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection) | TTP | -| [Registry Keys for Creating SHIM Databases](/endpoint/registry_keys_for_creating_shim_databases/) | [Application Shimming](/tags/#application-shimming) | TTP | +| [Recursive Delete of Directory In Batch CMD](/endpoint/recursive_delete_of_directory_in_batch_cmd/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | +| [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | +| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Registry Keys for Creating SHIM Databases](/endpoint/registry_keys_for_creating_shim_databases/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Regsvr32 Silent Param Dll Loading](/endpoint/regsvr32_silent_param_dll_loading/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | TTP | | [Remcos RAT File Creation in Remcos Folder](/endpoint/remcos_rat_file_creation_in_remcos_folder/) | [Screen Capture](/tags/#screen-capture) | TTP | | [Remcos client registry install entry](/endpoint/remcos_client_registry_install_entry/) | [Modify Registry](/tags/#modify-registry) | TTP | -| [Remote Desktop Network Bruteforce](/network/remote_desktop_network_bruteforce/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | TTP | -| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | Anomaly | -| [Remote Desktop Process Running On System](/endpoint/remote_desktop_process_running_on_system/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | Hunting | +| [Remote Desktop Network Bruteforce](/network/remote_desktop_network_bruteforce/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | TTP | +| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Anomaly | +| [Remote Desktop Process Running On System](/endpoint/remote_desktop_process_running_on_system/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Hunting | | [Remote Process Instantiation via WMI](/endpoint/remote_process_instantiation_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | | [Remote System Discovery with Adsisearcher](/endpoint/remote_system_discovery_with_adsisearcher/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | | [Remote System Discovery with Dsquery](/endpoint/remote_system_discovery_with_dsquery/) | [Remote System Discovery](/tags/#remote-system-discovery) | Hunting | @@ -512,101 +524,106 @@ sidebar: | [Resize Shadowstorage Volume](/endpoint/resize_shadowstorage_volume/) | [Service Stop](/tags/#service-stop) | TTP | | [Revil Common Exec Parameter](/endpoint/revil_common_exec_parameter/) | [User Execution](/tags/#user-execution) | TTP | | [Revil Registry Entry](/endpoint/revil_registry_entry/) | [Modify Registry](/tags/#modify-registry) | TTP | -| [RunDLL Loading DLL By Ordinal](/endpoint/rundll_loading_dll_by_ordinal/) | [Rundll32](/tags/#rundll32) | TTP | -| [Rundll32 Control RunDLL Hunt](/endpoint/rundll32_control_rundll_hunt/) | [Rundll32](/tags/#rundll32) | Hunting | -| [Rundll32 Control RunDLL World Writable Directory](/endpoint/rundll32_control_rundll_world_writable_directory/) | [Rundll32](/tags/#rundll32) | TTP | +| [RunDLL Loading DLL By Ordinal](/endpoint/rundll_loading_dll_by_ordinal/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Rundll32 Control RunDLL Hunt](/endpoint/rundll32_control_rundll_hunt/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | Hunting | +| [Rundll32 Control RunDLL World Writable Directory](/endpoint/rundll32_control_rundll_world_writable_directory/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | | [Rundll32 Create Remote Thread To A Process](/endpoint/rundll32_create_remote_thread_to_a_process/) | [Process Injection](/tags/#process-injection) | TTP | | [Rundll32 CreateRemoteThread In Browser](/endpoint/rundll32_createremotethread_in_browser/) | [Process Injection](/tags/#process-injection) | TTP | -| [Rundll32 DNSQuery](/endpoint/rundll32_dnsquery/) | [Rundll32](/tags/#rundll32) | TTP | -| [Rundll32 Process Creating Exe Dll Files](/endpoint/rundll32_process_creating_exe_dll_files/) | [Rundll32](/tags/#rundll32) | TTP | -| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [Rundll32](/tags/#rundll32) | TTP | +| [Rundll32 DNSQuery](/endpoint/rundll32_dnsquery/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Rundll32 Process Creating Exe Dll Files](/endpoint/rundll32_process_creating_exe_dll_files/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Rundll32 Shimcache Flush](/endpoint/rundll32_shimcache_flush/) | [Modify Registry](/tags/#modify-registry) | TTP | +| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | | [Ryuk Test Files Detected](/endpoint/ryuk_test_files_detected/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | TTP | -| [Ryuk Wake on LAN Command](/endpoint/ryuk_wake_on_lan_command/) | [Windows Command Shell](/tags/#windows-command-shell) | TTP | -| [SAM Database File Access Attempt](/endpoint/sam_database_file_access_attempt/) | [Security Account Manager](/tags/#security-account-manager) | Hunting | -| [SLUI RunAs Elevated](/endpoint/slui_runas_elevated/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [SLUI Spawning a Process](/endpoint/slui_spawning_a_process/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | Anomaly | -| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | Anomaly | +| [Ryuk Wake on LAN Command](/endpoint/ryuk_wake_on_lan_command/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | TTP | +| [SAM Database File Access Attempt](/endpoint/sam_database_file_access_attempt/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | Hunting | +| [SLUI RunAs Elevated](/endpoint/slui_runas_elevated/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [SLUI Spawning a Process](/endpoint/slui_spawning_a_process/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | Anomaly | +| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | Anomaly | | [SQL Injection with Long URLs](/web/sql_injection_with_long_urls/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | TTP | | [Samsam Test File Write](/endpoint/samsam_test_file_write/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | TTP | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service) | TTP | -| [SchCache Change By App Connect And Create ADSI Object](/endpoint/schcache_change_by_app_connect_and_create_adsi_object/) | [Domain Account](/tags/#domain-account) | Anomaly | +| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | +| [SchCache Change By App Connect And Create ADSI Object](/endpoint/schcache_change_by_app_connect_and_create_adsi_object/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | Anomaly | | [Schedule Task with HTTP Command Arguments](/endpoint/schedule_task_with_http_command_arguments/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | | [Schedule Task with Rundll32 Command Trigger](/endpoint/schedule_task_with_rundll32_command_trigger/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | -| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task) | TTP | +| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | | [Schtasks Run Task On Demand](/endpoint/schtasks_run_task_on_demand/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | -| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task) | TTP | -| [Schtasks used for forcing a reboot](/endpoint/schtasks_used_for_forcing_a_reboot/) | [Scheduled Task](/tags/#scheduled-task) | TTP | +| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [Schtasks used for forcing a reboot](/endpoint/schtasks_used_for_forcing_a_reboot/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [Screensaver Event Trigger Execution](/endpoint/screensaver_event_trigger_execution/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Screensaver](/tags/#screensaver) | TTP | | [Script Execution via WMI](/endpoint/script_execution_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | -| [Sdclt UAC Bypass](/endpoint/sdclt_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | +| [Sdclt UAC Bypass](/endpoint/sdclt_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Sdelete Application Execution](/endpoint/sdelete_application_execution/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [SearchProtocolHost with no Command Line with Network](/endpoint/searchprotocolhost_with_no_command_line_with_network/) | [Process Injection](/tags/#process-injection) | TTP | -| [SecretDumps Offline NTDS Dumping Tool](/endpoint/secretdumps_offline_ntds_dumping_tool/) | [NTDS](/tags/#ntds) | TTP | +| [SecretDumps Offline NTDS Dumping Tool](/endpoint/secretdumps_offline_ntds_dumping_tool/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Services Escalate Exe](/endpoint/services_escalate_exe/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | -| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [PowerShell](/tags/#powershell) | TTP | +| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Setting Credentials via DSInternals modules](/endpoint/setting_credentials_via_dsinternals_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | | [Setting Credentials via Mimikatz modules](/endpoint/setting_credentials_via_mimikatz_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | | [Setting Credentials via PowerSploit modules](/endpoint/setting_credentials_via_powersploit_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Shim Database File Creation](/endpoint/shim_database_file_creation/) | [Application Shimming](/tags/#application-shimming) | TTP | -| [Shim Database Installation With Suspicious Parameters](/endpoint/shim_database_installation_with_suspicious_parameters/) | [Application Shimming](/tags/#application-shimming) | TTP | -| [Short Lived Windows Accounts](/endpoint/short_lived_windows_accounts/) | [Local Account](/tags/#local-account) | TTP | -| [SilentCleanup UAC Bypass](/endpoint/silentcleanup_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [Single Letter Process On Endpoint](/endpoint/single_letter_process_on_endpoint/) | [Malicious File](/tags/#malicious-file) | TTP | +| [Shim Database File Creation](/endpoint/shim_database_file_creation/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Shim Database Installation With Suspicious Parameters](/endpoint/shim_database_installation_with_suspicious_parameters/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Short Lived Windows Accounts](/endpoint/short_lived_windows_accounts/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account) | TTP | +| [SilentCleanup UAC Bypass](/endpoint/silentcleanup_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Single Letter Process On Endpoint](/endpoint/single_letter_process_on_endpoint/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file) | TTP | | [Spike in File Writes]() | None | Anomaly | -| [Spoolsv Spawning Rundll32](/endpoint/spoolsv_spawning_rundll32/) | [Print Processors](/tags/#print-processors) | TTP | -| [Spoolsv Suspicious Loaded Modules](/endpoint/spoolsv_suspicious_loaded_modules/) | [Print Processors](/tags/#print-processors) | TTP | +| [Spoolsv Spawning Rundll32](/endpoint/spoolsv_spawning_rundll32/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Spoolsv Suspicious Loaded Modules](/endpoint/spoolsv_suspicious_loaded_modules/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Spoolsv Suspicious Process Access](/endpoint/spoolsv_suspicious_process_access/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | TTP | -| [Spoolsv Writing a DLL](/endpoint/spoolsv_writing_a_dll/) | [Print Processors](/tags/#print-processors) | TTP | -| [Spoolsv Writing a DLL - Sysmon](/endpoint/spoolsv_writing_a_dll_-_sysmon/) | [Print Processors](/tags/#print-processors) | TTP | +| [Spoolsv Writing a DLL](/endpoint/spoolsv_writing_a_dll/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Spoolsv Writing a DLL - Sysmon](/endpoint/spoolsv_writing_a_dll_-_sysmon/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Sqlite Module In Temp Folder](/endpoint/sqlite_module_in_temp_folder/) | [Data from Local System](/tags/#data-from-local-system) | TTP | -| [Start Up During Safe Mode Boot](/endpoint/start_up_during_safe_mode_boot/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | +| [Start Up During Safe Mode Boot](/endpoint/start_up_during_safe_mode_boot/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Sunburst Correlation DLL and Network Event](/endpoint/sunburst_correlation_dll_and_network_event/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | TTP | | [Supernova Webshell](/web/supernova_webshell/) | [Web Shell](/tags/#web-shell) | TTP | +| [Suspicious Copy on System32](/endpoint/suspicious_copy_on_system32/) | [Rename System Utilities](/tags/#rename-system-utilities), [Masquerading](/tags/#masquerading) | TTP | | [Suspicious Curl Network Connection](/endpoint/suspicious_curl_network_connection/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [Suspicious DLLHost no Command Line Arguments](/endpoint/suspicious_dllhost_no_command_line_arguments/) | [Process Injection](/tags/#process-injection) | TTP | -| [Suspicious Driver Loaded Path](/endpoint/suspicious_driver_loaded_path/) | [Windows Service](/tags/#windows-service) | TTP | -| [Suspicious Email Attachment Extensions](/application/suspicious_email_attachment_extensions/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | Anomaly | -| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Suspicious Driver Loaded Path](/endpoint/suspicious_driver_loaded_path/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | +| [Suspicious Email Attachment Extensions](/application/suspicious_email_attachment_extensions/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | +| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | | [Suspicious GPUpdate no Command Line Arguments](/endpoint/suspicious_gpupdate_no_command_line_arguments/) | [Process Injection](/tags/#process-injection) | TTP | -| [Suspicious IcedID Regsvr32 Cmdline](/endpoint/suspicious_icedid_regsvr32_cmdline/) | [Regsvr32](/tags/#regsvr32) | TTP | -| [Suspicious IcedID Rundll32 Cmdline](/endpoint/suspicious_icedid_rundll32_cmdline/) | [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious IcedID Regsvr32 Cmdline](/endpoint/suspicious_icedid_regsvr32_cmdline/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | TTP | +| [Suspicious IcedID Rundll32 Cmdline](/endpoint/suspicious_icedid_rundll32_cmdline/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | | [Suspicious Image Creation In Appdata Folder](/endpoint/suspicious_image_creation_in_appdata_folder/) | [Screen Capture](/tags/#screen-capture) | TTP | | [Suspicious Java Classes]() | None | Anomaly | -| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | -| [Suspicious MSBuild Spawn](/endpoint/suspicious_msbuild_spawn/) | [MSBuild](/tags/#msbuild) | TTP | -| [Suspicious PlistBuddy Usage](/endpoint/suspicious_plistbuddy_usage/) | [Launch Agent](/tags/#launch-agent) | TTP | -| [Suspicious PlistBuddy Usage via OSquery](/endpoint/suspicious_plistbuddy_usage_via_osquery/) | [Launch Agent](/tags/#launch-agent) | TTP | +| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | TTP | +| [Suspicious MSBuild Spawn](/endpoint/suspicious_msbuild_spawn/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [MSBuild](/tags/#msbuild) | TTP | +| [Suspicious PlistBuddy Usage](/endpoint/suspicious_plistbuddy_usage/) | [Launch Agent](/tags/#launch-agent), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | +| [Suspicious PlistBuddy Usage via OSquery](/endpoint/suspicious_plistbuddy_usage_via_osquery/) | [Launch Agent](/tags/#launch-agent), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [Suspicious Reg exe Process](/endpoint/suspicious_reg_exe_process/) | [Modify Registry](/tags/#modify-registry) | TTP | -| [Suspicious Regsvr32 Register Suspicious Path](/endpoint/suspicious_regsvr32_register_suspicious_path/) | [Regsvr32](/tags/#regsvr32) | TTP | -| [Suspicious Rundll32 PluginInit](/endpoint/suspicious_rundll32_plugininit/) | [Rundll32](/tags/#rundll32) | TTP | -| [Suspicious Rundll32 Rename](/endpoint/suspicious_rundll32_rename/) | [Rundll32](/tags/#rundll32), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | -| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [Rundll32](/tags/#rundll32) | TTP | -| [Suspicious Rundll32 dllregisterserver](/endpoint/suspicious_rundll32_dllregisterserver/) | [Rundll32](/tags/#rundll32) | TTP | -| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious Regsvr32 Register Suspicious Path](/endpoint/suspicious_regsvr32_register_suspicious_path/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | TTP | +| [Suspicious Rundll32 PluginInit](/endpoint/suspicious_rundll32_plugininit/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious Rundll32 Rename](/endpoint/suspicious_rundll32_rename/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Masquerading](/tags/#masquerading), [Rundll32](/tags/#rundll32), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | +| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious Rundll32 dllregisterserver](/endpoint/suspicious_rundll32_dllregisterserver/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | | [Suspicious SQLite3 LSQuarantine Behavior](/endpoint/suspicious_sqlite3_lsquarantine_behavior/) | [Data Staged](/tags/#data-staged) | TTP | -| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task) | Anomaly | +| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | Anomaly | | [Suspicious SearchProtocolHost no Command Line Arguments](/endpoint/suspicious_searchprotocolhost_no_command_line_arguments/) | [Process Injection](/tags/#process-injection) | TTP | | [Suspicious WAV file in Appdata Folder](/endpoint/suspicious_wav_file_in_appdata_folder/) | [Screen Capture](/tags/#screen-capture) | TTP | -| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | +| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | | [Suspicious microsoft workflow compiler usage](/endpoint/suspicious_microsoft_workflow_compiler_usage/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution) | TTP | -| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | -| [Suspicious mshta child process](/endpoint/suspicious_mshta_child_process/) | [Mshta](/tags/#mshta) | TTP | -| [Suspicious mshta spawn](/endpoint/suspicious_mshta_spawn/) | [Mshta](/tags/#mshta) | TTP | -| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | TTP | +| [Suspicious mshta child process](/endpoint/suspicious_mshta_child_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [Suspicious mshta spawn](/endpoint/suspicious_mshta_spawn/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [Suspicious writes to windows Recycle Bin](/endpoint/suspicious_writes_to_windows_recycle_bin/) | [Masquerading](/tags/#masquerading) | TTP | | [System Information Discovery Detection](/endpoint/system_information_discovery_detection/) | [System Information Discovery](/tags/#system-information-discovery) | TTP | | [System Process Running from Unexpected Location](/endpoint/system_process_running_from_unexpected_location/) | [Masquerading](/tags/#masquerading) | Anomaly | -| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Rename System Utilities](/tags/#rename-system-utilities) | TTP | +| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | | [System User Discovery With Query](/endpoint/system_user_discovery_with_query/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Hunting | | [System User Discovery With Whoami](/endpoint/system_user_discovery_with_whoami/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Hunting | -| [TOR Traffic](/network/tor_traffic/) | [Web Protocols](/tags/#web-protocols) | TTP | +| [TOR Traffic](/network/tor_traffic/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols) | TTP | +| [Time Provider Persistence Registry](/endpoint/time_provider_persistence_registry/) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Trickbot Named Pipe](/endpoint/trickbot_named_pipe/) | [Process Injection](/tags/#process-injection) | TTP | -| [UAC Bypass MMC Load Unsigned Dll](/endpoint/uac_bypass_mmc_load_unsigned_dll/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [UAC Bypass With Colorui COM Object](/endpoint/uac_bypass_with_colorui_com_object/) | [CMSTP](/tags/#cmstp) | TTP | +| [UAC Bypass MMC Load Unsigned Dll](/endpoint/uac_bypass_mmc_load_unsigned_dll/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [UAC Bypass With Colorui COM Object](/endpoint/uac_bypass_with_colorui_com_object/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | TTP | | [USN Journal Deletion](/endpoint/usn_journal_deletion/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [Unified Messaging Service Spawning a Process](/endpoint/unified_messaging_service_spawning_a_process/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | TTP | -| [Uninstall App Using MsiExec](/endpoint/uninstall_app_using_msiexec/) | [Msiexec](/tags/#msiexec) | TTP | -| [Unload Sysmon Filter Driver](/endpoint/unload_sysmon_filter_driver/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Uninstall App Using MsiExec](/endpoint/uninstall_app_using_msiexec/) | [Msiexec](/tags/#msiexec), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution) | TTP | +| [Unload Sysmon Filter Driver](/endpoint/unload_sysmon_filter_driver/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Unloading AMSI via Reflection](/endpoint/unloading_amsi_via_reflection/) | [Impair Defenses](/tags/#impair-defenses) | TTP | | [Unusually Long Command Line]() | None | Anomaly | | [Unusually Long Command Line]() | None | Anomaly | @@ -614,33 +631,37 @@ sidebar: | [Unusually Long Content-Type Length]() | None | Anomaly | | [User Discovery With Env Vars PowerShell](/endpoint/user_discovery_with_env_vars_powershell/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Hunting | | [User Discovery With Env Vars PowerShell Script Block](/endpoint/user_discovery_with_env_vars_powershell_script_block/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Hunting | -| [W3WP Spawning Shell](/endpoint/w3wp_spawning_shell/) | [Web Shell](/tags/#web-shell) | TTP | +| [Vbscript Execution Using Wscript App](/endpoint/vbscript_execution_using_wscript_app/) | [Visual Basic](/tags/#visual-basic), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | TTP | +| [Verclsid CLSID Execution](/endpoint/verclsid_clsid_execution/) | [Verclsid](/tags/#verclsid), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution) | Hunting | +| [W3WP Spawning Shell](/endpoint/w3wp_spawning_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | TTP | | [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [WMI Permanent Event Subscription](/endpoint/wmi_permanent_event_subscription/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | -| [WMI Permanent Event Subscription - Sysmon](/endpoint/wmi_permanent_event_subscription_-_sysmon/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription) | TTP | +| [WMI Permanent Event Subscription - Sysmon](/endpoint/wmi_permanent_event_subscription_-_sysmon/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [WMI Recon Running Process Or Services](/endpoint/wmi_recon_running_process_or_services/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | | [WMI Temporary Event Subscription](/endpoint/wmi_temporary_event_subscription/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | -| [WSReset UAC Bypass](/endpoint/wsreset_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [Wbemprox COM Object Execution](/endpoint/wbemprox_com_object_execution/) | [CMSTP](/tags/#cmstp) | TTP | +| [WSReset UAC Bypass](/endpoint/wsreset_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Wbemprox COM Object Execution](/endpoint/wbemprox_com_object_execution/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | TTP | | [Web Servers Executing Suspicious Processes](/application/web_servers_executing_suspicious_processes/) | [System Information Discovery](/tags/#system-information-discovery) | TTP | -| [Wermgr Process Connecting To IP Check Web Services](/endpoint/wermgr_process_connecting_to_ip_check_web_services/) | [IP Addresses](/tags/#ip-addresses) | TTP | +| [Wermgr Process Connecting To IP Check Web Services](/endpoint/wermgr_process_connecting_to_ip_check_web_services/) | [Gather Victim Network Information](/tags/#gather-victim-network-information), [IP Addresses](/tags/#ip-addresses) | TTP | | [Wermgr Process Create Executable File](/endpoint/wermgr_process_create_executable_file/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information) | TTP | | [Wermgr Process Spawned CMD Or Powershell Process](/endpoint/wermgr_process_spawned_cmd_or_powershell_process/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | TTP | -| [WevtUtil Usage To Clear Logs](/endpoint/wevtutil_usage_to_clear_logs/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [Wevtutil Usage To Disable Logs](/endpoint/wevtutil_usage_to_disable_logs/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task) | TTP | -| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task) | TTP | +| [WevtUtil Usage To Clear Logs](/endpoint/wevtutil_usage_to_clear_logs/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Wevtutil Usage To Disable Logs](/endpoint/wevtutil_usage_to_disable_logs/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | | [WinRM Spawning a Process](/endpoint/winrm_spawning_a_process/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | TTP | | [Windows AdFind Exe](/endpoint/windows_adfind_exe/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | -| [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | | [Windows Security Account Manager Stopped](/endpoint/windows_security_account_manager_stopped/) | [Service Stop](/tags/#service-stop) | TTP | -| [Winword Spawning Cmd](/endpoint/winword_spawning_cmd/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Winword Spawning PowerShell](/endpoint/winword_spawning_powershell/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Winword Spawning Windows Script Host](/endpoint/winword_spawning_windows_script_host/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Wmic Group Discovery](/endpoint/wmic_group_discovery/) | [Local Groups](/tags/#local-groups) | Hunting | -| [Write Executable in SMB Share](/endpoint/write_executable_in_smb_share/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [XMRIG Driver Loaded](/endpoint/xmrig_driver_loaded/) | [Windows Service](/tags/#windows-service) | TTP | +| [Winhlp32 Spawning a Process](/endpoint/winhlp32_spawning_a_process/) | [Process Injection](/tags/#process-injection) | TTP | +| [Winword Spawning Cmd](/endpoint/winword_spawning_cmd/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Winword Spawning PowerShell](/endpoint/winword_spawning_powershell/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Winword Spawning Windows Script Host](/endpoint/winword_spawning_windows_script_host/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Wmic Group Discovery](/endpoint/wmic_group_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | +| [Write Executable in SMB Share](/endpoint/write_executable_in_smb_share/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Wscript Or Cscript Suspicious Child Process](/endpoint/wscript_or_cscript_suspicious_child_process/) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation) | TTP | +| [XMRIG Driver Loaded](/endpoint/xmrig_driver_loaded/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [XSL Script Execution With WMIC](/endpoint/xsl_script_execution_with_wmic/) | [XSL Script Processing](/tags/#xsl-script-processing) | TTP | | [aws detect attach to role policy](/cloud/aws_detect_attach_to_role_policy/) | [Valid Accounts](/tags/#valid-accounts) | Hunting | | [aws detect permanent key creation](/cloud/aws_detect_permanent_key_creation/) | [Valid Accounts](/tags/#valid-accounts) | Hunting | diff --git a/docs/_pages/lateral_movement.md b/docs/_pages/lateral_movement.md index 42acf4eb27..e9de2d6344 100644 --- a/docs/_pages/lateral_movement.md +++ b/docs/_pages/lateral_movement.md @@ -10,4 +10,4 @@ sidebar: | Name | Technique | Tactic | | ----------- | ----------- |--------------| -| [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527/) | [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | \ No newline at end of file +| [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | \ No newline at end of file diff --git a/docs/_pages/malware.md b/docs/_pages/malware.md index db8e2eae05..2737b240fa 100644 --- a/docs/_pages/malware.md +++ b/docs/_pages/malware.md @@ -11,24 +11,24 @@ sidebar: | Name | Technique | Tactic | | ----------- | ----------- |--------------| | [BlackMatter Ransomware](/stories/blackmatter_ransomware/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Impact](/tags/#impact) | -| [Clop Ransomware](/stories/clop_ransomware/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | +| [Clop Ransomware](/stories/clop_ransomware/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | | [ColdRoot MacOS RAT]() | None | None | | [DHS Report TA18-074A](/stories/dhs_report_ta18-074a/) | [Modify Registry](/tags/#modify-registry) | [Defense Evasion](/tags/#defense-evasion) | -| [DarkSide Ransomware](/stories/darkside_ransomware/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | [Privilege Escalation](/tags/#privilege-escalation) | +| [DarkSide Ransomware](/stories/darkside_ransomware/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Privilege Escalation](/tags/#privilege-escalation) | | [Dynamic DNS](/stories/dynamic_dns/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Exfiltration](/tags/#exfiltration) | -| [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | [Initial Access](/tags/#initial-access) | +| [Emotet Malware DHS Report TA18-201A ](/stories/emotet_malware__dhs_report_ta18-201a_/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | [Initial Access](/tags/#initial-access) | | [FIN7](/stories/fin7/) | [XSL Script Processing](/tags/#xsl-script-processing) | [Defense Evasion](/tags/#defense-evasion) | -| [Hidden Cobra Malware](/stories/hidden_cobra_malware/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | [Lateral Movement](/tags/#lateral-movement) | -| [IcedID](/stories/icedid/) | [Scheduled Task](/tags/#scheduled-task) | [Execution](/tags/#execution) | -| [Orangeworm Attack Group](/stories/orangeworm_attack_group/) | [Windows Service](/tags/#windows-service) | [Persistence](/tags/#persistence) | -| [Ransomware](/stories/ransomware/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | +| [Hidden Cobra Malware](/stories/hidden_cobra_malware/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | [Lateral Movement](/tags/#lateral-movement) | +| [IcedID](/stories/icedid/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Execution](/tags/#execution) | +| [Orangeworm Attack Group](/stories/orangeworm_attack_group/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [Persistence](/tags/#persistence) | +| [Ransomware](/stories/ransomware/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | | [Ransomware Cloud](/stories/ransomware_cloud/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Impact](/tags/#impact) | -| [Remcos](/stories/remcos/) | [Screen Capture](/tags/#screen-capture) | [Collection](/tags/#collection) | -| [Revil Ransomware](/stories/revil_ransomware/) | [CMSTP](/tags/#cmstp) | [Defense Evasion](/tags/#defense-evasion) | +| [Remcos](/stories/remcos/) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation) | [Defense Evasion](/tags/#defense-evasion) | +| [Revil Ransomware](/stories/revil_ransomware/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | [Defense Evasion](/tags/#defense-evasion) | | [Ryuk Ransomware](/stories/ryuk_ransomware/) | [Service Stop](/tags/#service-stop) | [Impact](/tags/#impact) | | [SamSam Ransomware](/stories/samsam_ransomware/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Impact](/tags/#impact) | -| [Trickbot](/stories/trickbot/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | [Lateral Movement](/tags/#lateral-movement) | -| [Unusual Processes](/stories/unusual_processes/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | -| [Windows File Extension and Association Abuse](/stories/windows_file_extension_and_association_abuse/) | [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | -| [Windows Service Abuse](/stories/windows_service_abuse/) | [Windows Service](/tags/#windows-service) | [Persistence](/tags/#persistence) | -| [XMRig](/stories/xmrig/) | [Windows Service](/tags/#windows-service) | [Persistence](/tags/#persistence) | \ No newline at end of file +| [Trickbot](/stories/trickbot/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | [Lateral Movement](/tags/#lateral-movement) | +| [Unusual Processes](/stories/unusual_processes/) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation) | [Defense Evasion](/tags/#defense-evasion) | +| [Windows File Extension and Association Abuse](/stories/windows_file_extension_and_association_abuse/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | +| [Windows Service Abuse](/stories/windows_service_abuse/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [Persistence](/tags/#persistence) | +| [XMRig](/stories/xmrig/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [Persistence](/tags/#persistence) | \ No newline at end of file diff --git a/docs/_pages/playbooks.md b/docs/_pages/playbooks.md index 138b2993a5..37e7e87ba5 100644 --- a/docs/_pages/playbooks.md +++ b/docs/_pages/playbooks.md @@ -10,4 +10,4 @@ sidebar: | Name | Detections | Type | | --------| ---------- | ----------- | -| [Ransomware Investigate and Contain](/playbooks/ransomware_investigate_and_contain/)|[Conti Common Exec parameter](/detections/TTP/conti_common_exec_parameter)| Response | \ No newline at end of file +| [Ransomware Investigate and Contain](/playbooks/ransomware_investigate_and_contain/)|[Conti Common Exec parameter](/detections/TTP/conti_common_exec_parameter)| Response | diff --git a/docs/_pages/stories.md b/docs/_pages/stories.md index bedf6ebda7..f6d323f477 100644 --- a/docs/_pages/stories.md +++ b/docs/_pages/stories.md @@ -11,75 +11,75 @@ sidebar: | Name | Technique | Tactic | | ----------- | ----------- |--------------| | [AWS Cross Account Activity](aws_cross_account_activity) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material) | [Defense Evasion](/tags/#defense-evasion) | -| [AWS IAM Privilege Escalation](aws_iam_privilege_escalation) | [Cloud Account](/tags/#cloud-account) | [Persistence](/tags/#persistence) | -| [AWS Network ACL Activity](aws_network_acl_activity) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | [Defense Evasion](/tags/#defense-evasion) | +| [AWS IAM Privilege Escalation](aws_iam_privilege_escalation) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | [Persistence](/tags/#persistence) | +| [AWS Network ACL Activity](aws_network_acl_activity) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | | [AWS Security Hub Alerts]() | None | None | | [AWS User Monitoring](aws_user_monitoring) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Discovery](/tags/#discovery) | -| [Active Directory Discovery](active_directory_discovery) | [Local Groups](/tags/#local-groups) | [Discovery](/tags/#discovery) | -| [Active Directory Password Spraying](active_directory_password_spraying) | [Password Spraying](/tags/#password-spraying) | [Credential Access](/tags/#credential-access) | +| [Active Directory Discovery](active_directory_discovery) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Discovery](/tags/#discovery) | +| [Active Directory Password Spraying](active_directory_password_spraying) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Credential Access](/tags/#credential-access) | | [Apache Struts Vulnerability](apache_struts_vulnerability) | [System Information Discovery](/tags/#system-information-discovery) | [Discovery](/tags/#discovery) | | [Asset Tracking]() | None | None | | [BITS Jobs](bits_jobs) | [BITS Jobs](/tags/#bits-jobs) | [Defense Evasion](/tags/#defense-evasion) | | [Baron Samedit CVE-2021-3156](baron_samedit_cve-2021-3156) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Privilege Escalation](/tags/#privilege-escalation) | | [BlackMatter Ransomware](blackmatter_ransomware) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Impact](/tags/#impact) | | [Brand Monitoring]() | None | None | -| [Clop Ransomware](clop_ransomware) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | +| [Clop Ransomware](clop_ransomware) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | | [Cloud Cryptomining](cloud_cryptomining) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Defense Evasion](/tags/#defense-evasion) | -| [Cloud Federated Credential Abuse](cloud_federated_credential_abuse) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection) | [Privilege Escalation](/tags/#privilege-escalation) | -| [Cobalt Strike](cobalt_strike) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | +| [Cloud Federated Credential Abuse](cloud_federated_credential_abuse) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution) | [Privilege Escalation](/tags/#privilege-escalation) | +| [Cobalt Strike](cobalt_strike) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | [Defense Evasion](/tags/#defense-evasion) | | [ColdRoot MacOS RAT]() | None | None | | [Collection and Staging](collection_and_staging) | [Masquerading](/tags/#masquerading) | [Defense Evasion](/tags/#defense-evasion) | -| [Command and Control](command_and_control) | [Web Protocols](/tags/#web-protocols) | [Command And Control](/tags/#command-and-control) | +| [Command and Control](command_and_control) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols) | [Command And Control](/tags/#command-and-control) | | [Container Implantation Monitoring and Investigation](container_implantation_monitoring_and_investigation) | [Implant Internal Image](/tags/#implant-internal-image) | [Persistence](/tags/#persistence) | -| [Credential Dumping](credential_dumping) | [PowerShell](/tags/#powershell) | [Execution](/tags/#execution) | +| [Credential Dumping](credential_dumping) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [Execution](/tags/#execution) | | [DHS Report TA18-074A](dhs_report_ta18-074a) | [Modify Registry](/tags/#modify-registry) | [Defense Evasion](/tags/#defense-evasion) | -| [DNS Amplification Attacks](dns_amplification_attacks) | [Reflection Amplification](/tags/#reflection-amplification) | [Impact](/tags/#impact) | +| [DNS Amplification Attacks](dns_amplification_attacks) | [Network Denial of Service](/tags/#network-denial-of-service), [Reflection Amplification](/tags/#reflection-amplification) | [Impact](/tags/#impact) | | [DNS Hijacking](dns_hijacking) | [Drive-by Compromise](/tags/#drive-by-compromise) | [Initial Access](/tags/#initial-access) | -| [DarkSide Ransomware](darkside_ransomware) | [Bypass User Account Control](/tags/#bypass-user-account-control) | [Privilege Escalation](/tags/#privilege-escalation) | -| [Data Exfiltration](data_exfiltration) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | [Exfiltration](/tags/#exfiltration) | +| [DarkSide Ransomware](darkside_ransomware) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Privilege Escalation](/tags/#privilege-escalation) | +| [Data Exfiltration](data_exfiltration) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Exfiltration](/tags/#exfiltration) | | [Data Protection](data_protection) | [Drive-by Compromise](/tags/#drive-by-compromise) | [Initial Access](/tags/#initial-access) | | [Deobfuscate-Decode Files or Information](deobfuscate-decode_files_or_information) | [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information) | [Defense Evasion](/tags/#defense-evasion) | | [Detect Zerologon Attack](detect_zerologon_attack) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | | [Dev Sec Ops](dev_sec_ops) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Discovery](/tags/#discovery) | -| [Disabling Security Tools](disabling_security_tools) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | [Defense Evasion](/tags/#defense-evasion) | +| [Disabling Security Tools](disabling_security_tools) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | | [Domain Trust Discovery](domain_trust_discovery) | [Remote System Discovery](/tags/#remote-system-discovery) | [Discovery](/tags/#discovery) | | [Dynamic DNS](dynamic_dns) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Exfiltration](/tags/#exfiltration) | -| [Emotet Malware DHS Report TA18-201A ](emotet_malware__dhs_report_ta18-201a_) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | [Initial Access](/tags/#initial-access) | +| [Emotet Malware DHS Report TA18-201A ](emotet_malware__dhs_report_ta18-201a_) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | [Initial Access](/tags/#initial-access) | | [F5 TMUI RCE CVE-2020-5902](f5_tmui_rce_cve-2020-5902) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | | [FIN7](fin7) | [XSL Script Processing](/tags/#xsl-script-processing) | [Defense Evasion](/tags/#defense-evasion) | | [GCP Cross Account Activity](gcp_cross_account_activity) | [Valid Accounts](/tags/#valid-accounts) | [Defense Evasion](/tags/#defense-evasion) | -| [HAFNIUM Group](hafnium_group) | [Web Shell](/tags/#web-shell) | [Persistence](/tags/#persistence) | -| [Hidden Cobra Malware](hidden_cobra_malware) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | [Lateral Movement](/tags/#lateral-movement) | -| [IcedID](icedid) | [Scheduled Task](/tags/#scheduled-task) | [Execution](/tags/#execution) | +| [HAFNIUM Group](hafnium_group) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | [Persistence](/tags/#persistence) | +| [Hidden Cobra Malware](hidden_cobra_malware) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | [Lateral Movement](/tags/#lateral-movement) | +| [IcedID](icedid) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Execution](/tags/#execution) | | [Ingress Tool Transfer](ingress_tool_transfer) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [Command And Control](/tags/#command-and-control) | | [JBoss Vulnerability](jboss_vulnerability) | [System Information Discovery](/tags/#system-information-discovery) | [Discovery](/tags/#discovery) | | [Kubernetes Scanning Activity](kubernetes_scanning_activity) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Discovery](/tags/#discovery) | | [Kubernetes Sensitive Object Access Activity]() | None | None | -| [Lateral Movement](lateral_movement) | [Scheduled Task](/tags/#scheduled-task) | [Execution](/tags/#execution) | +| [Lateral Movement](lateral_movement) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Execution](/tags/#execution) | | [Malicious PowerShell](malicious_powershell) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | [Reconnaissance](/tags/#reconnaissance) | -| [Masquerading - Rename System Utilities](masquerading_-_rename_system_utilities) | [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | +| [Masquerading - Rename System Utilities](masquerading_-_rename_system_utilities) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | | [Meterpreter](meterpreter) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [Discovery](/tags/#discovery) | -| [Microsoft MSHTML Remote Code Execution CVE-2021-40444](microsoft_mshtml_remote_code_execution_cve-2021-40444) | [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | +| [Microsoft MSHTML Remote Code Execution CVE-2021-40444](microsoft_mshtml_remote_code_execution_cve-2021-40444) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | | [Monitor for Updates]() | None | None | | [NOBELIUM Group](nobelium_group) | [Remote System Discovery](/tags/#remote-system-discovery) | [Discovery](/tags/#discovery) | -| [Netsh Abuse](netsh_abuse) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall) | [Defense Evasion](/tags/#defense-evasion) | -| [Office 365 Detections](office_365_detections) | [Email Forwarding Rule](/tags/#email-forwarding-rule) | [Collection](/tags/#collection) | -| [Orangeworm Attack Group](orangeworm_attack_group) | [Windows Service](/tags/#windows-service) | [Persistence](/tags/#persistence) | +| [Netsh Abuse](netsh_abuse) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | +| [Office 365 Detections](office_365_detections) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection) | [Collection](/tags/#collection) | +| [Orangeworm Attack Group](orangeworm_attack_group) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [Persistence](/tags/#persistence) | | [PetitPotam NTLM Relay on Active Directory Certificate Services](petitpotam_ntlm_relay_on_active_directory_certificate_services) | [OS Credential Dumping](/tags/#os-credential-dumping) | [Credential Access](/tags/#credential-access) | -| [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | [Persistence](/tags/#persistence) | -| [PrintNightmare CVE-2021-34527](printnightmare_cve-2021-34527) | [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | -| [Prohibited Traffic Allowed or Protocol Mismatch](prohibited_traffic_allowed_or_protocol_mismatch) | [Web Protocols](/tags/#web-protocols) | [Command And Control](/tags/#command-and-control) | -| [ProxyShell](proxyshell) | [Web Shell](/tags/#web-shell) | [Persistence](/tags/#persistence) | -| [Ransomware](ransomware) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | +| [Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns](possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Persistence](/tags/#persistence) | +| [PrintNightmare CVE-2021-34527](printnightmare_cve-2021-34527) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | +| [Prohibited Traffic Allowed or Protocol Mismatch](prohibited_traffic_allowed_or_protocol_mismatch) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols) | [Command And Control](/tags/#command-and-control) | +| [ProxyShell](proxyshell) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | [Persistence](/tags/#persistence) | +| [Ransomware](ransomware) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | | [Ransomware Cloud](ransomware_cloud) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Impact](/tags/#impact) | -| [Remcos](remcos) | [Screen Capture](/tags/#screen-capture) | [Collection](/tags/#collection) | -| [Revil Ransomware](revil_ransomware) | [CMSTP](/tags/#cmstp) | [Defense Evasion](/tags/#defense-evasion) | -| [Router and Infrastructure Security](router_and_infrastructure_security) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Traffic Duplication](/tags/#traffic-duplication) | [Initial Access](/tags/#initial-access) | +| [Remcos](remcos) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation) | [Defense Evasion](/tags/#defense-evasion) | +| [Revil Ransomware](revil_ransomware) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | [Defense Evasion](/tags/#defense-evasion) | +| [Router and Infrastructure Security](router_and_infrastructure_security) | [Hardware Additions](/tags/#hardware-additions), [Automated Exfiltration](/tags/#automated-exfiltration), [Network Denial of Service](/tags/#network-denial-of-service), [Traffic Duplication](/tags/#traffic-duplication) | [Initial Access](/tags/#initial-access) | | [Ryuk Ransomware](ryuk_ransomware) | [Service Stop](/tags/#service-stop) | [Impact](/tags/#impact) | | [SQL Injection](sql_injection) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | | [SamSam Ransomware](samsam_ransomware) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | [Impact](/tags/#impact) | | [Silver Sparrow](silver_sparrow) | [Data Staged](/tags/#data-staged) | [Collection](/tags/#collection) | -| [Spearphishing Attachments](spearphishing_attachments) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | [Initial Access](/tags/#initial-access) | +| [Spearphishing Attachments](spearphishing_attachments) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | [Initial Access](/tags/#initial-access) | | [Suspicious AWS Login Activities](suspicious_aws_login_activities) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | [Defense Evasion](/tags/#defense-evasion) | | [Suspicious AWS S3 Activities](suspicious_aws_s3_activities) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | [Collection](/tags/#collection) | | [Suspicious AWS Traffic]() | None | None | @@ -87,30 +87,30 @@ sidebar: | [Suspicious Cloud Instance Activities](suspicious_cloud_instance_activities) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | [Exfiltration](/tags/#exfiltration) | | [Suspicious Cloud Provisioning Activities](suspicious_cloud_provisioning_activities) | [Valid Accounts](/tags/#valid-accounts) | [Defense Evasion](/tags/#defense-evasion) | | [Suspicious Cloud User Activities](suspicious_cloud_user_activities) | [Valid Accounts](/tags/#valid-accounts) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Command-Line Executions](suspicious_command-line_executions) | [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Compiled HTML Activity](suspicious_compiled_html_activity) | [Compiled HTML File](/tags/#compiled-html-file) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Command-Line Executions](suspicious_command-line_executions) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Compiled HTML Activity](suspicious_compiled_html_activity) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | [Defense Evasion](/tags/#defense-evasion) | | [Suspicious DNS Traffic](suspicious_dns_traffic) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Exfiltration](/tags/#exfiltration) | -| [Suspicious Emails](suspicious_emails) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | [Initial Access](/tags/#initial-access) | +| [Suspicious Emails](suspicious_emails) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | [Initial Access](/tags/#initial-access) | | [Suspicious GCP Storage Activities](suspicious_gcp_storage_activities) | [Data from Cloud Storage Object](/tags/#data-from-cloud-storage-object) | [Collection](/tags/#collection) | -| [Suspicious MSHTA Activity](suspicious_mshta_activity) | [Mshta](/tags/#mshta) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Okta Activity](suspicious_okta_activity) | [Default Accounts](/tags/#default-accounts) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Regsvcs Regasm Activity](suspicious_regsvcs_regasm_activity) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Regsvr32 Activity](suspicious_regsvr32_activity) | [Regsvr32](/tags/#regsvr32) | [Defense Evasion](/tags/#defense-evasion) | -| [Suspicious Rundll32 Activity](suspicious_rundll32_activity) | [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious MSHTA Activity](suspicious_mshta_activity) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Okta Activity](suspicious_okta_activity) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Regsvcs Regasm Activity](suspicious_regsvcs_regasm_activity) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Regsvr32 Activity](suspicious_regsvr32_activity) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | [Defense Evasion](/tags/#defense-evasion) | +| [Suspicious Rundll32 Activity](suspicious_rundll32_activity) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion) | | [Suspicious WMI Use](suspicious_wmi_use) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | [Execution](/tags/#execution) | -| [Suspicious Windows Registry Activities](suspicious_windows_registry_activities) | [Application Shimming](/tags/#application-shimming) | [Privilege Escalation](/tags/#privilege-escalation) | +| [Suspicious Windows Registry Activities](suspicious_windows_registry_activities) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | [Privilege Escalation](/tags/#privilege-escalation) | | [Suspicious Zoom Child Processes](suspicious_zoom_child_processes) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Privilege Escalation](/tags/#privilege-escalation) | -| [Trickbot](trickbot) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | [Lateral Movement](/tags/#lateral-movement) | +| [Trickbot](trickbot) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | [Lateral Movement](/tags/#lateral-movement) | | [Trusted Developer Utilities Proxy Execution](trusted_developer_utilities_proxy_execution) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution) | [Defense Evasion](/tags/#defense-evasion) | -| [Trusted Developer Utilities Proxy Execution MSBuild](trusted_developer_utilities_proxy_execution_msbuild) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | -| [Unusual Processes](unusual_processes) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | +| [Trusted Developer Utilities Proxy Execution MSBuild](trusted_developer_utilities_proxy_execution_msbuild) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | [Defense Evasion](/tags/#defense-evasion) | +| [Unusual Processes](unusual_processes) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation) | [Defense Evasion](/tags/#defense-evasion) | | [Use of Cleartext Protocols]() | None | None | | [Windows DNS SIGRed CVE-2020-1350](windows_dns_sigred_cve-2020-1350) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | [Execution](/tags/#execution) | -| [Windows Defense Evasion Tactics](windows_defense_evasion_tactics) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | [Defense Evasion](/tags/#defense-evasion) | +| [Windows Defense Evasion Tactics](windows_defense_evasion_tactics) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | | [Windows Discovery Techniques](windows_discovery_techniques) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Process Injection](/tags/#process-injection), [Hijack Execution Flow](/tags/#hijack-execution-flow) | [Persistence](/tags/#persistence) | -| [Windows File Extension and Association Abuse](windows_file_extension_and_association_abuse) | [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | -| [Windows Log Manipulation](windows_log_manipulation) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | -| [Windows Persistence Techniques](windows_persistence_techniques) | [Scheduled Task](/tags/#scheduled-task) | [Execution](/tags/#execution) | -| [Windows Privilege Escalation](windows_privilege_escalation) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection) | [Privilege Escalation](/tags/#privilege-escalation) | -| [Windows Service Abuse](windows_service_abuse) | [Windows Service](/tags/#windows-service) | [Persistence](/tags/#persistence) | -| [XMRig](xmrig) | [Windows Service](/tags/#windows-service) | [Persistence](/tags/#persistence) | \ No newline at end of file +| [Windows File Extension and Association Abuse](windows_file_extension_and_association_abuse) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | +| [Windows Log Manipulation](windows_log_manipulation) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | +| [Windows Persistence Techniques](windows_persistence_techniques) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | [Execution](/tags/#execution) | +| [Windows Privilege Escalation](windows_privilege_escalation) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Persistence](/tags/#persistence) | +| [Windows Service Abuse](windows_service_abuse) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [Persistence](/tags/#persistence) | +| [XMRig](xmrig) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [Persistence](/tags/#persistence) | \ No newline at end of file diff --git a/docs/_playbooks/ransomware_investigate_and_contain.md b/docs/_playbooks/ransomware_investigate_and_contain.md index 995e0df85a..35e58c63ff 100644 --- a/docs/_playbooks/ransomware_investigate_and_contain.md +++ b/docs/_playbooks/ransomware_investigate_and_contain.md @@ -111,6 +111,8 @@ This playbook investigates and contains ransomware detected on endpoints. + + @@ -648,6 +650,25 @@ This playbook investigates and contains ransomware detected on endpoints. + + + + + + + + + + + + + + + + + + + diff --git a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md index 421938b9e6..c0523e50ea 100644 --- a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md +++ b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md @@ -1,6 +1,6 @@ --- title: "Large Volume of DNS ANY Queries" -excerpt: "Reflection Amplification" +excerpt: "Network Denial of Service, Reflection Amplification" categories: - Network last_modified_at: 2017-09-20 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Anomaly + - T1498 + - Network Denial of Service + - Impact - T1498.002 - Reflection Amplification - Impact @@ -40,6 +43,7 @@ The search is used to identify attempts to use your DNS Infrastructure for DDoS | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | | [T1498.002](https://attack.mitre.org/techniques/T1498/002/) | Reflection Amplification | Impact | diff --git a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md b/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md index ef5b8d2e16..f036c1c64e 100644 --- a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md +++ b/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md @@ -1,6 +1,6 @@ --- title: "Detect Credential Dumping through LSASS access" -excerpt: "LSASS Memory" +excerpt: "LSASS Memory, OS Credential Dumping" categories: - Endpoint last_modified_at: 2019-12-03 @@ -11,6 +11,9 @@ tags: - T1003.001 - LSASS Memory - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -37,7 +40,8 @@ This search looks for reading lsass memory consistent with credential dumping. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | +| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md b/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md index aac20225e9..3b1162192c 100644 --- a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md +++ b/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md @@ -1,6 +1,6 @@ --- title: "Detect Mimikatz Using Loaded Images" -excerpt: "LSASS Memory" +excerpt: "LSASS Memory, OS Credential Dumping" categories: - Endpoint last_modified_at: 2019-12-03 @@ -11,6 +11,9 @@ tags: - T1003.001 - LSASS Memory - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -37,7 +40,8 @@ This search looks for reading loaded Images unique to credential dumping with Mi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | +| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md b/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md index 0dd5c25b3b..5c02bb02fa 100644 --- a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md +++ b/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md @@ -1,6 +1,6 @@ --- title: "Access LSASS Memory for Dump Creation" -excerpt: "LSASS Memory" +excerpt: "LSASS Memory, OS Credential Dumping" categories: - Endpoint last_modified_at: 2019-12-06 @@ -11,6 +11,9 @@ tags: - T1003.001 - LSASS Memory - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -37,7 +40,8 @@ Detect memory dumping of the LSASS process. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | +| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md b/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md index dd2461a047..5532dc0e00 100644 --- a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md +++ b/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md @@ -1,6 +1,6 @@ --- title: "Create Remote Thread into LSASS" -excerpt: "LSASS Memory" +excerpt: "LSASS Memory, OS Credential Dumping" categories: - Endpoint last_modified_at: 2019-12-06 @@ -11,6 +11,9 @@ tags: - T1003.001 - LSASS Memory - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -37,7 +40,8 @@ Detect remote thread creation into LSASS consistent with credential dumping. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | +| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2019-12-10-creation_of_shadow_copy.md b/docs/_posts/2019-12-10-creation_of_shadow_copy.md index 3e3225f6c1..f1079168dc 100644 --- a/docs/_posts/2019-12-10-creation_of_shadow_copy.md +++ b/docs/_posts/2019-12-10-creation_of_shadow_copy.md @@ -1,6 +1,6 @@ --- title: "Creation of Shadow Copy" -excerpt: "NTDS" +excerpt: "NTDS, OS Credential Dumping" categories: - Endpoint last_modified_at: 2019-12-10 @@ -11,6 +11,9 @@ tags: - T1003.003 - NTDS - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ Monitor for signs that Vssadmin or Wmic has been used to create a shadow copy. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | +| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md index b472f501d5..2ca1f036ad 100644 --- a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md +++ b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md @@ -1,6 +1,6 @@ --- title: "DNS Query Length Outliers - MLTK" -excerpt: "DNS" +excerpt: "DNS, Application Layer Protocol" categories: - Network last_modified_at: 2020-01-22 @@ -11,6 +11,9 @@ tags: - T1071.004 - DNS - Command And Control + - T1071 + - Application Layer Protocol + - Command And Control - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +43,8 @@ This search allows you to identify DNS requests that are unusually large for the | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1071.004](https://attack.mitre.org/techniques/T1071/004/) | DNS | Command And Control | +| [T1071.004](https://attack.mitre.org/techniques/T1071/004/) | DNS | Command And Control || [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | + #### Search diff --git a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md b/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md index e00c42e7af..8461ca54c0 100644 --- a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md +++ b/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md @@ -1,6 +1,6 @@ --- title: "Creation of lsass Dump with Taskmgr" -excerpt: "LSASS Memory" +excerpt: "LSASS Memory, OS Credential Dumping" categories: - Endpoint last_modified_at: 2020-02-03 @@ -11,6 +11,9 @@ tags: - T1003.001 - LSASS Memory - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -37,7 +40,8 @@ Detect the hands on keyboard behavior of Windows Task Manager creating a process | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | +| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md b/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md index b9e41e7577..d694d51def 100644 --- a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md +++ b/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md @@ -1,6 +1,6 @@ --- title: "Dump LSASS via comsvcs DLL" -excerpt: "LSASS Memory" +excerpt: "LSASS Memory, OS Credential Dumping" categories: - Endpoint last_modified_at: 2020-02-21 @@ -11,6 +11,9 @@ tags: - T1003.001 - LSASS Memory - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ Detect the usage of comsvcs.dll for dumping the lsass process. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | +| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md b/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md index f7b55491b8..c311e97660 100644 --- a/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md +++ b/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md @@ -1,6 +1,6 @@ --- title: "Detect Path Interception By Creation Of program exe" -excerpt: "Path Interception by Unquoted Path" +excerpt: "Path Interception by Unquoted Path, Hijack Execution Flow" categories: - Endpoint last_modified_at: 2020-07-03 @@ -13,6 +13,11 @@ tags: - Persistence - Privilege Escalation - Defense Evasion + - T1574 + - Hijack Execution Flow + - Persistence + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +45,8 @@ The detection Detect Path Interception By Creation Of program exe is detecting t | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1574.009](https://attack.mitre.org/techniques/T1574/009/) | Path Interception by Unquoted Path | Persistence, Privilege Escalation, Defense Evasion | +| [T1574.009](https://attack.mitre.org/techniques/T1574/009/) | Path Interception by Unquoted Path | Persistence, Privilege Escalation, Defense Evasion || [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Persistence, Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2020-07-06-short_lived_windows_accounts.md b/docs/_posts/2020-07-06-short_lived_windows_accounts.md index f7764772c0..fb6bb43dfa 100644 --- a/docs/_posts/2020-07-06-short_lived_windows_accounts.md +++ b/docs/_posts/2020-07-06-short_lived_windows_accounts.md @@ -1,6 +1,6 @@ --- title: "Short Lived Windows Accounts" -excerpt: "Local Account" +excerpt: "Local Account, Create Account" categories: - Endpoint last_modified_at: 2020-07-06 @@ -11,6 +11,9 @@ tags: - T1136.001 - Local Account - Persistence + - T1136 + - Create Account + - Persistence - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -37,7 +40,8 @@ This search detects accounts that were created and deleted in a short time perio | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence | +| [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence || [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | + #### Search diff --git a/docs/_posts/2020-07-06-windows_event_log_cleared.md b/docs/_posts/2020-07-06-windows_event_log_cleared.md index 0450d3d269..6f88380f1b 100644 --- a/docs/_posts/2020-07-06-windows_event_log_cleared.md +++ b/docs/_posts/2020-07-06-windows_event_log_cleared.md @@ -1,6 +1,6 @@ --- title: "Windows Event Log Cleared" -excerpt: "Clear Windows Event Logs" +excerpt: "Indicator Removal on Host, Clear Windows Event Logs" categories: - Endpoint last_modified_at: 2020-07-06 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1070 + - Indicator Removal on Host + - Defense Evasion - T1070.001 - Clear Windows Event Logs - Defense Evasion @@ -37,6 +40,7 @@ The following analytic utilizes Windows Security Event ID 1102 or System log eve | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | | [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | diff --git a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md index 138253d43f..fc3393c75a 100644 --- a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md +++ b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md @@ -1,6 +1,6 @@ --- title: "Remote Desktop Network Traffic" -excerpt: "Remote Desktop Protocol" +excerpt: "Remote Desktop Protocol, Remote Services" categories: - Network last_modified_at: 2020-07-07 @@ -11,6 +11,9 @@ tags: - T1021.001 - Remote Desktop Protocol - Lateral Movement + - T1021 + - Remote Services + - Lateral Movement - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +43,8 @@ This search looks for network traffic on TCP/3389, the default port used by remo | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | +| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement || [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | + #### Search diff --git a/docs/_posts/2020-07-08-detect_new_local_admin_account.md b/docs/_posts/2020-07-08-detect_new_local_admin_account.md index ca61b02144..6ccf31bd9c 100644 --- a/docs/_posts/2020-07-08-detect_new_local_admin_account.md +++ b/docs/_posts/2020-07-08-detect_new_local_admin_account.md @@ -1,6 +1,6 @@ --- title: "Detect New Local Admin account" -excerpt: "Local Account" +excerpt: "Local Account, Create Account" categories: - Endpoint last_modified_at: 2020-07-08 @@ -11,6 +11,9 @@ tags: - T1136.001 - Local Account - Persistence + - T1136 + - Create Account + - Persistence - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search looks for newly created accounts that have been elevated to local ad | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence | +| [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence || [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | + #### Search diff --git a/docs/_posts/2020-07-21-attempt_to_stop_security_service.md b/docs/_posts/2020-07-21-attempt_to_stop_security_service.md index 25b22fe5c6..2b88cb8b0e 100644 --- a/docs/_posts/2020-07-21-attempt_to_stop_security_service.md +++ b/docs/_posts/2020-07-21-attempt_to_stop_security_service.md @@ -1,6 +1,6 @@ --- title: "Attempt To Stop Security Service" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2020-07-21 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +42,8 @@ This search looks for attempts to stop security-related services on the endpoint | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md b/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md index e655b78f98..daaa5a5b13 100644 --- a/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md +++ b/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md @@ -1,6 +1,6 @@ --- title: "Detect Excessive User Account Lockouts" -excerpt: "Local Accounts" +excerpt: "Valid Accounts, Local Accounts" categories: - Endpoint last_modified_at: 2020-07-21 @@ -8,6 +8,12 @@ toc: true toc_label: "" tags: - Anomaly + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - T1078.003 - Local Accounts - Defense Evasion @@ -40,6 +46,7 @@ This search detects user accounts that have been locked out a relatively high nu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | | [T1078.003](https://attack.mitre.org/techniques/T1078/003/) | Local Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | diff --git a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md index 4c00575181..5266f5dbae 100644 --- a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md +++ b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md @@ -1,6 +1,6 @@ --- title: "Detect Outbound SMB Traffic" -excerpt: "File Transfer Protocols" +excerpt: "File Transfer Protocols, Application Layer Protocol" categories: - Network last_modified_at: 2020-07-21 @@ -11,6 +11,9 @@ tags: - T1071.002 - File Transfer Protocols - Command And Control + - T1071 + - Application Layer Protocol + - Command And Control - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +44,8 @@ This search looks for outbound SMB connections made by hosts within your network | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1071.002](https://attack.mitre.org/techniques/T1071/002/) | File Transfer Protocols | Command And Control | +| [T1071.002](https://attack.mitre.org/techniques/T1071/002/) | File Transfer Protocols | Command And Control || [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | + #### Search diff --git a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md index 5ddead128c..b1441f996c 100644 --- a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md +++ b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md @@ -1,6 +1,6 @@ --- title: "Detect Outlook exe writing a zip file" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2020-07-21 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -40,6 +43,7 @@ This search looks for execution of process `outlook.exe` where the process is wr | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md b/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md index 47aa6a73ac..bf3403f1ff 100644 --- a/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md +++ b/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md @@ -1,6 +1,6 @@ --- title: "Detect Use of cmd exe to Launch Script Interpreters" -excerpt: "Windows Command Shell" +excerpt: "Command and Scripting Interpreter, Windows Command Shell" categories: - Endpoint last_modified_at: 2020-07-21 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.003 - Windows Command Shell - Execution @@ -38,6 +41,7 @@ This search looks for the execution of the cscript.exe or wscript.exe processes, | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | diff --git a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md index a068ff8738..47671479f3 100644 --- a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md +++ b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md @@ -1,6 +1,6 @@ --- title: "Email files written outside of the Outlook directory" -excerpt: "Local Email Collection" +excerpt: "Email Collection, Local Email Collection" categories: - Application last_modified_at: 2020-07-21 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1114 + - Email Collection + - Collection - T1114.001 - Local Email Collection - Collection @@ -40,6 +43,7 @@ The search looks at the change-analysis data model and detects email files creat | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | | [T1114.001](https://attack.mitre.org/techniques/T1114/001/) | Local Email Collection | Collection | diff --git a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md index ef1a8f7eb1..56fc245013 100644 --- a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md +++ b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md @@ -1,6 +1,6 @@ --- title: "Email servers sending high volume traffic to hosts" -excerpt: "Remote Email Collection" +excerpt: "Email Collection, Remote Email Collection" categories: - Application last_modified_at: 2020-07-21 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Anomaly + - T1114 + - Email Collection + - Collection - T1114.002 - Remote Email Collection - Collection @@ -40,6 +43,7 @@ This search looks for an increase of data transfers from your email server to yo | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | | [T1114.002](https://attack.mitre.org/techniques/T1114/002/) | Remote Email Collection | Collection | diff --git a/docs/_posts/2020-07-21-excessive_dns_failures.md b/docs/_posts/2020-07-21-excessive_dns_failures.md index e89e6d5791..064ce25bda 100644 --- a/docs/_posts/2020-07-21-excessive_dns_failures.md +++ b/docs/_posts/2020-07-21-excessive_dns_failures.md @@ -1,6 +1,6 @@ --- title: "Excessive DNS Failures" -excerpt: "DNS" +excerpt: "DNS, Application Layer Protocol" categories: - Network last_modified_at: 2020-07-21 @@ -11,6 +11,9 @@ tags: - T1071.004 - DNS - Command And Control + - T1071 + - Application Layer Protocol + - Command And Control - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +43,8 @@ This search identifies DNS query failures by counting the number of DNS response | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1071.004](https://attack.mitre.org/techniques/T1071/004/) | DNS | Command And Control | +| [T1071.004](https://attack.mitre.org/techniques/T1071/004/) | DNS | Command And Control || [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | + #### Search diff --git a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md index 41dc0d39e6..c4cf7ff3cc 100644 --- a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md +++ b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md @@ -1,6 +1,6 @@ --- title: "First Time Seen Running Windows Service" -excerpt: "Service Execution" +excerpt: "System Services, Service Execution" categories: - Endpoint last_modified_at: 2020-07-21 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Anomaly + - T1569 + - System Services + - Execution - T1569.002 - Service Execution - Execution @@ -40,6 +43,7 @@ This search looks for the first and last time a Windows service is seen running | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | | [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | diff --git a/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md b/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md index 181963f5ca..a83e8655c5 100644 --- a/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md +++ b/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md @@ -1,6 +1,6 @@ --- title: "Hiding Files And Directories With Attrib exe" -excerpt: "Windows File and Directory Permissions Modification" +excerpt: "File and Directory Permissions Modification, Windows File and Directory Permissions Modification" categories: - Endpoint last_modified_at: 2020-07-21 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1222 + - File and Directory Permissions Modification + - Defense Evasion - T1222.001 - Windows File and Directory Permissions Modification - Defense Evasion @@ -38,6 +41,7 @@ Attackers leverage an existing Windows binary, attrib.exe, to mark specific as h | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | | [T1222.001](https://attack.mitre.org/techniques/T1222/001/) | Windows File and Directory Permissions Modification | Defense Evasion | diff --git a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md index 3811759cab..66e7b98a50 100644 --- a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md +++ b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md @@ -1,6 +1,6 @@ --- title: "Hosts receiving high volume of network traffic from email server" -excerpt: "Remote Email Collection" +excerpt: "Remote Email Collection, Email Collection" categories: - Network last_modified_at: 2020-07-21 @@ -11,6 +11,9 @@ tags: - T1114.002 - Remote Email Collection - Collection + - T1114 + - Email Collection + - Collection - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +43,8 @@ This search looks for an increase of data transfers from your email server to yo | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1114.002](https://attack.mitre.org/techniques/T1114/002/) | Remote Email Collection | Collection | +| [T1114.002](https://attack.mitre.org/techniques/T1114/002/) | Remote Email Collection | Collection || [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | + #### Search diff --git a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md b/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md index db6fdd2803..80f81e68b2 100644 --- a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md +++ b/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md @@ -1,6 +1,6 @@ --- title: "Malicious PowerShell Process - Execution Policy Bypass" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2020-07-21 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -39,6 +42,7 @@ This search looks for PowerShell processes started with parameters used to bypas | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md index c9fe0ff09c..9ef5dd77c5 100644 --- a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md +++ b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md @@ -1,6 +1,6 @@ --- title: "Multiple Okta Users With Invalid Credentials From The Same IP" -excerpt: "Default Accounts" +excerpt: "Valid Accounts, Default Accounts" categories: - Application last_modified_at: 2020-07-21 @@ -8,6 +8,12 @@ toc: true toc_label: "" tags: - TTP + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - T1078.001 - Default Accounts - Defense Evasion @@ -41,6 +47,7 @@ This search detects Okta login failures due to bad credentials for multiple user | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | | [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | diff --git a/docs/_posts/2020-07-21-okta_account_lockout_events.md b/docs/_posts/2020-07-21-okta_account_lockout_events.md index a3ffe1effe..1dadc47f00 100644 --- a/docs/_posts/2020-07-21-okta_account_lockout_events.md +++ b/docs/_posts/2020-07-21-okta_account_lockout_events.md @@ -1,6 +1,6 @@ --- title: "Okta Account Lockout Events" -excerpt: "Default Accounts" +excerpt: "Valid Accounts, Default Accounts" categories: - Application last_modified_at: 2020-07-21 @@ -8,6 +8,12 @@ toc: true toc_label: "" tags: - Anomaly + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - T1078.001 - Default Accounts - Defense Evasion @@ -41,6 +47,7 @@ Detect Okta user lockout events | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | | [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | diff --git a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md index c78d22c437..ed960db85e 100644 --- a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md +++ b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md @@ -1,6 +1,6 @@ --- title: "Okta Failed SSO Attempts" -excerpt: "Default Accounts" +excerpt: "Valid Accounts, Default Accounts" categories: - Application last_modified_at: 2020-07-21 @@ -8,6 +8,12 @@ toc: true toc_label: "" tags: - Anomaly + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - T1078.001 - Default Accounts - Defense Evasion @@ -41,6 +47,7 @@ Detect failed Okta SSO events | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | | [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | diff --git a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md index 5be788a3f1..23f286be56 100644 --- a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md +++ b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md @@ -1,6 +1,6 @@ --- title: "Okta User Logins From Multiple Cities" -excerpt: "Default Accounts" +excerpt: "Valid Accounts, Default Accounts" categories: - Application last_modified_at: 2020-07-21 @@ -8,6 +8,12 @@ toc: true toc_label: "" tags: - Anomaly + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - T1078.001 - Default Accounts - Defense Evasion @@ -41,6 +47,7 @@ This search detects logins from the same user from different cities in a 24 hour | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | | [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | diff --git a/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md b/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md index 9c14a63a65..c90f558ae9 100644 --- a/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md +++ b/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md @@ -1,6 +1,6 @@ --- title: "Overwriting Accessibility Binaries" -excerpt: "Accessibility Features" +excerpt: "Event Triggered Execution, Accessibility Features" categories: - Endpoint last_modified_at: 2020-07-21 @@ -8,6 +8,10 @@ toc: true toc_label: "" tags: - TTP + - T1546 + - Event Triggered Execution + - Privilege Escalation + - Persistence - T1546.008 - Accessibility Features - Privilege Escalation @@ -39,6 +43,7 @@ Microsoft Windows contains accessibility features that can be launched with a ke | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | | [T1546.008](https://attack.mitre.org/techniques/T1546/008/) | Accessibility Features | Privilege Escalation, Persistence | diff --git a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md index bb97c0ab6f..d2942c777c 100644 --- a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md +++ b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md @@ -1,6 +1,6 @@ --- title: "Protocol or Port Mismatch" -excerpt: "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol" +excerpt: "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, Exfiltration Over Alternative Protocol" categories: - Network last_modified_at: 2020-07-21 @@ -11,6 +11,9 @@ tags: - T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol - Exfiltration + - T1048 + - Exfiltration Over Alternative Protocol + - Exfiltration - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +43,8 @@ This search looks for network traffic on common ports where a higher layer proto | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | +| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration || [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | + #### Search diff --git a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md index 8e972c5485..56b0282da3 100644 --- a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md +++ b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md @@ -1,6 +1,6 @@ --- title: "Remote Desktop Network Bruteforce" -excerpt: "Remote Desktop Protocol" +excerpt: "Remote Desktop Protocol, Remote Services" categories: - Network last_modified_at: 2020-07-21 @@ -11,6 +11,9 @@ tags: - T1021.001 - Remote Desktop Protocol - Lateral Movement + - T1021 + - Remote Services + - Lateral Movement - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +44,8 @@ This search looks for RDP application network traffic and filters any source/des | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | +| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement || [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | + #### Search diff --git a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md index ec8f2a636f..f44fdfa0ce 100644 --- a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md +++ b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md @@ -1,6 +1,6 @@ --- title: "Remote Desktop Process Running On System" -excerpt: "Remote Desktop Protocol" +excerpt: "Remote Desktop Protocol, Remote Services" categories: - Endpoint last_modified_at: 2020-07-21 @@ -11,6 +11,9 @@ tags: - T1021.001 - Remote Desktop Protocol - Lateral Movement + - T1021 + - Remote Services + - Lateral Movement - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +43,8 @@ This search looks for the remote desktop process mstsc.exe running on systems up | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | +| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement || [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | + #### Search diff --git a/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md b/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md index dfc817ea3b..c7aa00c044 100644 --- a/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md +++ b/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md @@ -1,6 +1,6 @@ --- title: "Sc exe Manipulating Windows Services" -excerpt: "Windows Service" +excerpt: "Windows Service, Create or Modify System Process" categories: - Endpoint last_modified_at: 2020-07-21 @@ -12,6 +12,10 @@ tags: - Windows Service - Persistence - Privilege Escalation + - T1543 + - Create or Modify System Process + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This search looks for arguments to sc.exe indicating the creation or modificatio | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | +| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation || [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2020-07-21-schtasks_scheduling_job_on_remote_system.md b/docs/_posts/2020-07-21-schtasks_scheduling_job_on_remote_system.md index a585437fdc..30031ecec7 100644 --- a/docs/_posts/2020-07-21-schtasks_scheduling_job_on_remote_system.md +++ b/docs/_posts/2020-07-21-schtasks_scheduling_job_on_remote_system.md @@ -1,6 +1,6 @@ --- title: "Schtasks scheduling job on remote system" -excerpt: "Scheduled Task" +excerpt: "Scheduled Task, Scheduled Task/Job" categories: - Endpoint last_modified_at: 2020-07-21 @@ -13,6 +13,11 @@ tags: - Execution - Persistence - Privilege Escalation + - T1053 + - Scheduled Task/Job + - Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +45,8 @@ This search looks for flags passed to schtasks.exe on the command-line that indi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | +| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation || [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2020-07-22-smb_traffic_spike.md b/docs/_posts/2020-07-22-smb_traffic_spike.md index 6ab1fafba8..fd6172a575 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike.md @@ -1,6 +1,6 @@ --- title: "SMB Traffic Spike" -excerpt: "SMB/Windows Admin Shares" +excerpt: "SMB/Windows Admin Shares, Remote Services" categories: - Network last_modified_at: 2020-07-22 @@ -11,6 +11,9 @@ tags: - T1021.002 - SMB/Windows Admin Shares - Lateral Movement + - T1021 + - Remote Services + - Lateral Movement - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +43,8 @@ This search looks for spikes in the number of Server Message Block (SMB) traffic | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | +| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement || [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | + #### Search diff --git a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md index cfda388b41..086922cfa4 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md @@ -1,6 +1,6 @@ --- title: "SMB Traffic Spike - MLTK" -excerpt: "SMB/Windows Admin Shares" +excerpt: "SMB/Windows Admin Shares, Remote Services" categories: - Network last_modified_at: 2020-07-22 @@ -11,6 +11,9 @@ tags: - T1021.002 - SMB/Windows Admin Shares - Lateral Movement + - T1021 + - Remote Services + - Lateral Movement - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +43,8 @@ This search uses the Machine Learning Toolkit (MLTK) to identify spikes in the n | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | +| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement || [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | + #### Search diff --git a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md index c267706c08..1b668c3365 100644 --- a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md +++ b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md @@ -1,6 +1,6 @@ --- title: "Suspicious Email Attachment Extensions" -excerpt: "Spearphishing Attachment" +excerpt: "Spearphishing Attachment, Phishing" categories: - Application last_modified_at: 2020-07-22 @@ -11,6 +11,9 @@ tags: - T1566.001 - Spearphishing Attachment - Initial Access + - T1566 + - Phishing + - Initial Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +43,8 @@ This search looks for emails that have attachments with suspicious file extensio | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | +| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access || [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | + #### Search diff --git a/docs/_posts/2020-07-22-tor_traffic.md b/docs/_posts/2020-07-22-tor_traffic.md index 187d77a577..8bee98bb21 100644 --- a/docs/_posts/2020-07-22-tor_traffic.md +++ b/docs/_posts/2020-07-22-tor_traffic.md @@ -1,6 +1,6 @@ --- title: "TOR Traffic" -excerpt: "Web Protocols" +excerpt: "Application Layer Protocol, Web Protocols" categories: - Network last_modified_at: 2020-07-22 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1071 + - Application Layer Protocol + - Command And Control - T1071.001 - Web Protocols - Command And Control @@ -40,6 +43,7 @@ This search looks for network traffic identified as The Onion Router (TOR), a be | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | | [T1071.001](https://attack.mitre.org/techniques/T1071/001/) | Web Protocols | Command And Control | diff --git a/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md b/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md index bcb6e5def5..aa235fa131 100644 --- a/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md +++ b/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md @@ -1,6 +1,6 @@ --- title: "Unload Sysmon Filter Driver" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2020-07-22 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ Attackers often disable security tools to avoid detection. This search looks for | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md b/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md index bedbdf9670..ded2914197 100644 --- a/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md +++ b/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md @@ -1,6 +1,6 @@ --- title: "Cloud Instance Modified By Previously Unseen User" -excerpt: "Cloud Accounts" +excerpt: "Cloud Accounts, Valid Accounts" categories: - Cloud last_modified_at: 2020-07-29 @@ -14,6 +14,12 @@ tags: - Persistence - Privilege Escalation - Initial Access + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -41,7 +47,8 @@ This search looks for cloud instances being modified by users who have not previ | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | +| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access || [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + #### Search diff --git a/docs/_posts/2020-08-11-detect_arp_poisoning.md b/docs/_posts/2020-08-11-detect_arp_poisoning.md index 95c57d4f38..6d7d94f3e5 100644 --- a/docs/_posts/2020-08-11-detect_arp_poisoning.md +++ b/docs/_posts/2020-08-11-detect_arp_poisoning.md @@ -1,6 +1,6 @@ --- title: "Detect ARP Poisoning" -excerpt: "Hardware Additions, Network Denial of Service, ARP Cache Poisoning" +excerpt: "Hardware Additions, Network Denial of Service, Man-in-the-Middle, ARP Cache Poisoning" categories: - Network last_modified_at: 2020-08-11 @@ -14,6 +14,10 @@ tags: - T1498 - Network Denial of Service - Impact + - T1557 + - Man-in-the-Middle + - Credential Access + - Collection - T1557.002 - ARP Cache Poisoning - Credential Access @@ -50,6 +54,7 @@ By enabling Dynamic ARP Inspection as a Layer 2 Security measure on the organiza | ----------- | ----------- | -------------- | | [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | | [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | +| [T1557](https://attack.mitre.org/techniques/T1557/) | Man-in-the-Middle | Credential Access, Collection | | [T1557.002](https://attack.mitre.org/techniques/T1557/002/) | ARP Cache Poisoning | Credential Access, Collection | diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md index 62faf29186..a13fc211bb 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md @@ -1,6 +1,6 @@ --- title: "Abnormally High Number Of Cloud Instances Destroyed" -excerpt: "Cloud Accounts" +excerpt: "Cloud Accounts, Valid Accounts" categories: - Cloud last_modified_at: 2020-08-21 @@ -14,6 +14,12 @@ tags: - Persistence - Privilege Escalation - Initial Access + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -44,7 +50,8 @@ This search finds for the number successfully destroyed cloud instances for ever | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | +| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access || [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + #### Search diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md index ee88833afa..74da500a7b 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md @@ -1,6 +1,6 @@ --- title: "Abnormally High Number Of Cloud Instances Launched" -excerpt: "Cloud Accounts" +excerpt: "Cloud Accounts, Valid Accounts" categories: - Cloud last_modified_at: 2020-08-21 @@ -14,6 +14,12 @@ tags: - Persistence - Privilege Escalation - Initial Access + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -44,7 +50,8 @@ This search finds for the number successfully created cloud instances for every | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | +| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access || [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + #### Search diff --git a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md index 3e97386ca4..be42dd8e7c 100644 --- a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md +++ b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md @@ -1,6 +1,6 @@ --- title: "Abnormally High Number Of Cloud Infrastructure API Calls" -excerpt: "Cloud Accounts" +excerpt: "Cloud Accounts, Valid Accounts" categories: - Cloud last_modified_at: 2020-09-07 @@ -14,6 +14,12 @@ tags: - Persistence - Privilege Escalation - Initial Access + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -42,7 +48,8 @@ This search will detect a spike in the number of API calls made to your cloud in | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | +| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access || [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + #### Search diff --git a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md index 15038a00d8..09167e8090 100644 --- a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md +++ b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md @@ -1,6 +1,6 @@ --- title: "Abnormally High Number Of Cloud Security Group API Calls" -excerpt: "Cloud Accounts" +excerpt: "Cloud Accounts, Valid Accounts" categories: - Cloud last_modified_at: 2020-09-07 @@ -14,6 +14,12 @@ tags: - Persistence - Privilege Escalation - Initial Access + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -42,7 +48,8 @@ This search will detect a spike in the number of API calls made to your cloud in | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | +| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access || [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + #### Search diff --git a/docs/_posts/2020-09-15-detect_dump_lsass_memory_using_comsvcs.md b/docs/_posts/2020-09-15-detect_dump_lsass_memory_using_comsvcs.md index 0f433a602c..69cd63e6f6 100644 --- a/docs/_posts/2020-09-15-detect_dump_lsass_memory_using_comsvcs.md +++ b/docs/_posts/2020-09-15-detect_dump_lsass_memory_using_comsvcs.md @@ -1,6 +1,6 @@ --- title: "Detect Dump LSASS Memory using comsvcs" -excerpt: "NTDS" +excerpt: "NTDS, OS Credential Dumping" categories: - Endpoint last_modified_at: 2020-09-15 @@ -11,6 +11,9 @@ tags: - T1003.003 - NTDS - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Behavioral Analytics - Actions on Objectives --- @@ -35,7 +38,8 @@ This search detects the memory of lsass.exe being dumped for offline credential | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | +| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md b/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md index 4bf46032ea..6b5f4bbbcf 100644 --- a/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md +++ b/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md @@ -1,6 +1,6 @@ --- title: "Create or delete windows shares using net exe" -excerpt: "Network Share Connection Removal" +excerpt: "Indicator Removal on Host, Network Share Connection Removal" categories: - Endpoint last_modified_at: 2020-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1070 + - Indicator Removal on Host + - Defense Evasion - T1070.005 - Network Share Connection Removal - Defense Evasion @@ -38,6 +41,7 @@ This search looks for the creation or deletion of hidden shares using net.exe. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | | [T1070.005](https://attack.mitre.org/techniques/T1070/005/) | Network Share Connection Removal | Defense Evasion | diff --git a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md index 78f425286a..bd44180439 100644 --- a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md +++ b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md @@ -1,6 +1,6 @@ --- title: "Detect Activity Related to Pass the Hash Attacks" -excerpt: "Pass the Hash" +excerpt: "Use Alternate Authentication Material, Pass the Hash" categories: - Endpoint last_modified_at: 2020-10-15 @@ -8,6 +8,10 @@ toc: true toc_label: "" tags: - TTP + - T1550 + - Use Alternate Authentication Material + - Defense Evasion + - Lateral Movement - T1550.002 - Pass the Hash - Defense Evasion @@ -38,6 +42,7 @@ This search looks for specific authentication events from the Windows Security E | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | | [T1550.002](https://attack.mitre.org/techniques/T1550/002/) | Pass the Hash | Defense Evasion, Lateral Movement | diff --git a/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md b/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md index c2ab220c76..2bbb319856 100644 --- a/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md +++ b/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md @@ -1,6 +1,6 @@ --- title: "Kerberoasting spn request with RC4 encryption" -excerpt: "Kerberoasting" +excerpt: "Kerberoasting, Steal or Forge Kerberos Tickets" categories: - Endpoint last_modified_at: 2020-10-16 @@ -11,6 +11,9 @@ tags: - T1558.003 - Kerberoasting - Credential Access + - T1558 + - Steal or Forge Kerberos Tickets + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -37,7 +40,8 @@ This search detects a potential kerberoasting attack via service principal name | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | +| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access || [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | + #### Search diff --git a/docs/_posts/2020-10-21-detect_kerberoasting.md b/docs/_posts/2020-10-21-detect_kerberoasting.md index ad7bdb92f9..2453d5ebe7 100644 --- a/docs/_posts/2020-10-21-detect_kerberoasting.md +++ b/docs/_posts/2020-10-21-detect_kerberoasting.md @@ -1,6 +1,6 @@ --- title: "Detect Kerberoasting" -excerpt: "Kerberoasting" +excerpt: "Kerberoasting, Steal or Forge Kerberos Tickets" categories: - Endpoint last_modified_at: 2020-10-21 @@ -11,6 +11,9 @@ tags: - T1558.003 - Kerberoasting - Credential Access + - T1558 + - Steal or Forge Kerberos Tickets + - Credential Access - Splunk Behavioral Analytics - Actions on Objectives --- @@ -35,7 +38,8 @@ This search detects a potential kerberoasting attack via service principal name | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | +| [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access || [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | + #### Search diff --git a/docs/_posts/2020-10-21-detect_pass_the_hash.md b/docs/_posts/2020-10-21-detect_pass_the_hash.md index 389eb0646c..c41ef18233 100644 --- a/docs/_posts/2020-10-21-detect_pass_the_hash.md +++ b/docs/_posts/2020-10-21-detect_pass_the_hash.md @@ -1,6 +1,6 @@ --- title: "Detect Pass the Hash" -excerpt: "Pass the Hash" +excerpt: "Use Alternate Authentication Material, Pass the Hash" categories: - Endpoint last_modified_at: 2020-10-21 @@ -8,6 +8,10 @@ toc: true toc_label: "" tags: - TTP + - T1550 + - Use Alternate Authentication Material + - Defense Evasion + - Lateral Movement - T1550.002 - Pass the Hash - Defense Evasion @@ -36,6 +40,7 @@ This search looks for specific authentication events from the Windows Security E | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | | [T1550.002](https://attack.mitre.org/techniques/T1550/002/) | Pass the Hash | Defense Evasion, Lateral Movement | diff --git a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md index f85bd65eb2..4ae537ae2b 100644 --- a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md +++ b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md @@ -1,6 +1,6 @@ --- title: "Detect IPv6 Network Infrastructure Threats" -excerpt: "Hardware Additions, Network Denial of Service, ARP Cache Poisoning" +excerpt: "Hardware Additions, Network Denial of Service, Man-in-the-Middle, ARP Cache Poisoning" categories: - Network last_modified_at: 2020-10-28 @@ -14,6 +14,10 @@ tags: - T1498 - Network Denial of Service - Impact + - T1557 + - Man-in-the-Middle + - Credential Access + - Collection - T1557.002 - ARP Cache Poisoning - Credential Access @@ -50,6 +54,7 @@ By enabling IPv6 First Hop Security as a Layer 2 Security measure on the organiz | ----------- | ----------- | -------------- | | [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | | [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | +| [T1557](https://attack.mitre.org/techniques/T1557/) | Man-in-the-Middle | Credential Access, Collection | | [T1557.002](https://attack.mitre.org/techniques/T1557/002/) | ARP Cache Poisoning | Credential Access, Collection | diff --git a/docs/_posts/2020-10-28-detect_port_security_violation.md b/docs/_posts/2020-10-28-detect_port_security_violation.md index 515c59d108..4fe5f87ed8 100644 --- a/docs/_posts/2020-10-28-detect_port_security_violation.md +++ b/docs/_posts/2020-10-28-detect_port_security_violation.md @@ -1,6 +1,6 @@ --- title: "Detect Port Security Violation" -excerpt: "Hardware Additions, Network Denial of Service, ARP Cache Poisoning" +excerpt: "Hardware Additions, Network Denial of Service, Man-in-the-Middle, ARP Cache Poisoning" categories: - Network last_modified_at: 2020-10-28 @@ -14,6 +14,10 @@ tags: - T1498 - Network Denial of Service - Impact + - T1557 + - Man-in-the-Middle + - Credential Access + - Collection - T1557.002 - ARP Cache Poisoning - Credential Access @@ -51,6 +55,7 @@ By enabling Port Security on a Cisco switch you can restrict input to an interfa | ----------- | ----------- | -------------- | | [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | | [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | +| [T1557](https://attack.mitre.org/techniques/T1557/) | Man-in-the-Middle | Credential Access, Collection | | [T1557.002](https://attack.mitre.org/techniques/T1557/002/) | ARP Cache Poisoning | Credential Access, Collection | diff --git a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md index 98f1c25a75..7de1bfbdb6 100644 --- a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md +++ b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md @@ -1,6 +1,6 @@ --- title: "Detect Software Download To Network Device" -excerpt: "TFTP Boot" +excerpt: "TFTP Boot, Pre-OS Boot" categories: - Network last_modified_at: 2020-10-28 @@ -12,6 +12,10 @@ tags: - TFTP Boot - Defense Evasion - Persistence + - T1542 + - Pre-OS Boot + - Defense Evasion + - Persistence - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +45,8 @@ Adversaries may abuse netbooting to load an unauthorized network device operatin | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1542.005](https://attack.mitre.org/techniques/T1542/005/) | TFTP Boot | Defense Evasion, Persistence | +| [T1542.005](https://attack.mitre.org/techniques/T1542/005/) | TFTP Boot | Defense Evasion, Persistence || [T1542](https://attack.mitre.org/techniques/T1542/) | Pre-OS Boot | Defense Evasion, Persistence | + #### Search diff --git a/docs/_posts/2020-10-28-detect_traffic_mirroring.md b/docs/_posts/2020-10-28-detect_traffic_mirroring.md index aa217e4911..f26921fa62 100644 --- a/docs/_posts/2020-10-28-detect_traffic_mirroring.md +++ b/docs/_posts/2020-10-28-detect_traffic_mirroring.md @@ -1,6 +1,6 @@ --- title: "Detect Traffic Mirroring" -excerpt: "Hardware Additions, Network Denial of Service, Traffic Duplication" +excerpt: "Hardware Additions, Automated Exfiltration, Network Denial of Service, Traffic Duplication" categories: - Network last_modified_at: 2020-10-28 @@ -11,6 +11,9 @@ tags: - T1200 - Hardware Additions - Initial Access + - T1020 + - Automated Exfiltration + - Exfiltration - T1498 - Network Denial of Service - Impact @@ -47,6 +50,7 @@ Adversaries may leverage traffic mirroring in order to automate data exfiltratio | ID | Technique | Tactic | | ----------- | ----------- | -------------- | | [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | +| [T1020](https://attack.mitre.org/techniques/T1020/) | Automated Exfiltration | Exfiltration | | [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | | [T1020.001](https://attack.mitre.org/techniques/T1020/001/) | Traffic Duplication | Exfiltration | diff --git a/docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md b/docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md index 39d95afda0..8144ca1973 100644 --- a/docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md @@ -1,6 +1,6 @@ --- title: "Reconnaissance of Credential Stores and Services via Mimikatz modules" -excerpt: "Credentials, Domain Properties, Network Trust Dependencies, Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation" +excerpt: "Account Manipulation, Domain Properties, Valid Accounts, Credentials, Gather Victim Network Information, Exploitation for Privilege Escalation, Gather Victim Identity Information, Network Trust Dependencies" categories: - Endpoint last_modified_at: 2020-11-03 @@ -8,27 +8,33 @@ toc: true toc_label: "" tags: - TTP - - T1589.001 - - Credentials - - Reconnaissance + - T1098 + - Account Manipulation + - Persistence - T1590.001 - Domain Properties - Reconnaissance - - T1590.003 - - Network Trust Dependencies - - Reconnaissance - - T1068 - - Exploitation for Privilege Escalation - - Privilege Escalation - T1078 - Valid Accounts - Defense Evasion - Persistence - Privilege Escalation - Initial Access - - T1098 - - Account Manipulation - - Persistence + - T1589.001 + - Credentials + - Reconnaissance + - T1590 + - Gather Victim Network Information + - Reconnaissance + - T1068 + - Exploitation for Privilege Escalation + - Privilege Escalation + - T1589 + - Gather Victim Identity Information + - Reconnaissance + - T1590.003 + - Network Trust Dependencies + - Reconnaissance - Splunk Behavioral Analytics - Actions on Objectives --- @@ -53,10 +59,12 @@ This detection identifies reconnaissance of credential stores and use of CryptoA | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1589.001](https://attack.mitre.org/techniques/T1589/001/) | Credentials | Reconnaissance || [T1590.001](https://attack.mitre.org/techniques/T1590/001/) | Domain Properties | Reconnaissance || [T1590.003](https://attack.mitre.org/techniques/T1590/003/) | Network Trust Dependencies | Reconnaissance || [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - +| [T1590.001](https://attack.mitre.org/techniques/T1590/001/) | Domain Properties | Reconnaissance || [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | +| [T1589.001](https://attack.mitre.org/techniques/T1589/001/) | Credentials | Reconnaissance || [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | +| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | +| [T1589](https://attack.mitre.org/techniques/T1589/) | Gather Victim Identity Information | Reconnaissance | +| [T1590.003](https://attack.mitre.org/techniques/T1590/003/) | Network Trust Dependencies | Reconnaissance | #### Search diff --git a/docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md b/docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md index 2629b4a341..efe575e469 100644 --- a/docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md +++ b/docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md @@ -1,6 +1,6 @@ --- title: "Reconnaissance of Defensive Tools via PowerSploit modules" -excerpt: "Vulnerability Scanning, Software" +excerpt: "Software, Vulnerability Scanning, Gather Victim Host Information, Active Scanning" categories: - Endpoint last_modified_at: 2020-11-05 @@ -8,11 +8,17 @@ toc: true toc_label: "" tags: - TTP + - T1592.002 + - Software + - Reconnaissance - T1595.002 - Vulnerability Scanning - Reconnaissance - - T1592.002 - - Software + - T1592 + - Gather Victim Host Information + - Reconnaissance + - T1595 + - Active Scanning - Reconnaissance - Splunk Behavioral Analytics - Actions on Objectives @@ -38,7 +44,9 @@ This detection identifies use of PowerSploit modules for assessment of presence | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1595.002](https://attack.mitre.org/techniques/T1595/002/) | Vulnerability Scanning | Reconnaissance || [T1592.002](https://attack.mitre.org/techniques/T1592/002/) | Software | Reconnaissance | +| [T1592.002](https://attack.mitre.org/techniques/T1592/002/) | Software | Reconnaissance || [T1595.002](https://attack.mitre.org/techniques/T1595/002/) | Vulnerability Scanning | Reconnaissance || [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | +| [T1595](https://attack.mitre.org/techniques/T1595/) | Active Scanning | Reconnaissance | + #### Search diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md index cec9d87542..21cce57a96 100644 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md @@ -1,6 +1,6 @@ --- title: "Reconnaissance and Access to Operating System Elements via PowerSploit modules" -excerpt: "System Service Discovery, Query Registry, Network Service Scanning, Windows Management Instrumentation, Process Discovery, File and Directory Discovery, Software Discovery, Software" +excerpt: "Process Discovery, File and Directory Discovery, Software, Network Service Scanning, Query Registry, System Service Discovery, Windows Management Instrumentation, Gather Victim Host Information, Software Discovery" categories: - Endpoint last_modified_at: 2020-11-06 @@ -8,30 +8,33 @@ toc: true toc_label: "" tags: - TTP - - T1007 - - System Service Discovery - - Discovery - - T1012 - - Query Registry - - Discovery - - T1046 - - Network Service Scanning - - Discovery - - T1047 - - Windows Management Instrumentation - - Execution - T1057 - Process Discovery - Discovery - T1083 - File and Directory Discovery - Discovery - - T1518 - - Software Discovery - - Discovery - T1592.002 - Software - Reconnaissance + - T1046 + - Network Service Scanning + - Discovery + - T1012 + - Query Registry + - Discovery + - T1007 + - System Service Discovery + - Discovery + - T1047 + - Windows Management Instrumentation + - Execution + - T1592 + - Gather Victim Host Information + - Reconnaissance + - T1518 + - Software Discovery + - Discovery - Splunk Behavioral Analytics - Actions on Objectives --- @@ -56,14 +59,15 @@ This detection identifies access to PowerSploit modules that discover and access | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1007](https://attack.mitre.org/techniques/T1007/) | System Service Discovery | Discovery | -| [T1012](https://attack.mitre.org/techniques/T1012/) | Query Registry | Discovery | -| [T1046](https://attack.mitre.org/techniques/T1046/) | Network Service Scanning | Discovery | -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | | [T1057](https://attack.mitre.org/techniques/T1057/) | Process Discovery | Discovery | | [T1083](https://attack.mitre.org/techniques/T1083/) | File and Directory Discovery | Discovery | +| [T1592.002](https://attack.mitre.org/techniques/T1592/002/) | Software | Reconnaissance || [T1046](https://attack.mitre.org/techniques/T1046/) | Network Service Scanning | Discovery | +| [T1012](https://attack.mitre.org/techniques/T1012/) | Query Registry | Discovery | +| [T1007](https://attack.mitre.org/techniques/T1007/) | System Service Discovery | Discovery | +| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | +| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | | [T1518](https://attack.mitre.org/techniques/T1518/) | Software Discovery | Discovery | -| [T1592.002](https://attack.mitre.org/techniques/T1592/002/) | Software | Reconnaissance | + #### Search diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md index 3b6b05a2d5..bd8a3f5de1 100644 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md @@ -1,6 +1,6 @@ --- title: "Reconnaissance and Access to Shared Resources via Mimikatz modules" -excerpt: "SMB/Windows Admin Shares, Network Share Discovery, Data from Network Shared Drive" +excerpt: "Remote Services, Data from Network Shared Drive, Network Share Discovery, SMB/Windows Admin Shares" categories: - Endpoint last_modified_at: 2020-11-06 @@ -8,15 +8,18 @@ toc: true toc_label: "" tags: - TTP - - T1021.002 - - SMB/Windows Admin Shares + - T1021 + - Remote Services - Lateral Movement - - T1135 - - Network Share Discovery - - Discovery - T1039 - Data from Network Shared Drive - Collection + - T1135 + - Network Share Discovery + - Discovery + - T1021.002 + - SMB/Windows Admin Shares + - Lateral Movement - Splunk Behavioral Analytics - Actions on Objectives --- @@ -41,9 +44,10 @@ This detection identifies use of Mimikatz modules for discovery and access to ne | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement || [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | +| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | | [T1039](https://attack.mitre.org/techniques/T1039/) | Data from Network Shared Drive | Collection | - +| [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | +| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | #### Search diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md index be82b6a29a..894d0a1f46 100644 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md @@ -1,6 +1,6 @@ --- title: "Reconnaissance and Access to Shared Resources via PowerSploit modules" -excerpt: "SMB/Windows Admin Shares, Network Share Discovery, Data from Network Shared Drive" +excerpt: "Remote Services, Data from Network Shared Drive, Network Share Discovery, SMB/Windows Admin Shares" categories: - Endpoint last_modified_at: 2020-11-06 @@ -8,15 +8,18 @@ toc: true toc_label: "" tags: - TTP - - T1021.002 - - SMB/Windows Admin Shares + - T1021 + - Remote Services - Lateral Movement - - T1135 - - Network Share Discovery - - Discovery - T1039 - Data from Network Shared Drive - Collection + - T1135 + - Network Share Discovery + - Discovery + - T1021.002 + - SMB/Windows Admin Shares + - Lateral Movement - Splunk Behavioral Analytics - Actions on Objectives --- @@ -41,9 +44,10 @@ This detection identifies access to PowerSploit modules that discover and access | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement || [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | +| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | | [T1039](https://attack.mitre.org/techniques/T1039/) | Data from Network Shared Drive | Collection | - +| [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | +| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | #### Search diff --git a/docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md index bea7096276..70573bef73 100644 --- a/docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md @@ -1,6 +1,6 @@ --- title: "Reconnaissance of Connectivity via PowerSploit modules" -excerpt: "SMB/Windows Admin Shares, Network Share Discovery, Data from Network Shared Drive" +excerpt: "Remote Services, Data from Network Shared Drive, Network Share Discovery, SMB/Windows Admin Shares" categories: - Endpoint last_modified_at: 2020-11-06 @@ -8,15 +8,18 @@ toc: true toc_label: "" tags: - TTP - - T1021.002 - - SMB/Windows Admin Shares + - T1021 + - Remote Services - Lateral Movement - - T1135 - - Network Share Discovery - - Discovery - T1039 - Data from Network Shared Drive - Collection + - T1135 + - Network Share Discovery + - Discovery + - T1021.002 + - SMB/Windows Admin Shares + - Lateral Movement - Splunk Behavioral Analytics - Actions on Objectives --- @@ -41,9 +44,10 @@ This detection identifies access to PowerSploit modules for reconnaissance of co | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement || [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | +| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | | [T1039](https://attack.mitre.org/techniques/T1039/) | Data from Network Shared Drive | Collection | - +| [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | +| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | #### Search diff --git a/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md b/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md index 12ca5e06eb..d5c75b2b7f 100644 --- a/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md +++ b/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md @@ -1,6 +1,6 @@ --- title: "Set Default PowerShell Execution Policy To Unrestricted or Bypass" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2020-11-06 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -39,6 +42,7 @@ Monitor for changes of the ExecutionPolicy in the registry to the values "un | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md b/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md index 1497ba7b73..a94962276a 100644 --- a/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md +++ b/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md @@ -1,6 +1,6 @@ --- title: "Detect Excessive Account Lockouts From Endpoint" -excerpt: "Domain Accounts" +excerpt: "Valid Accounts, Domain Accounts" categories: - Endpoint last_modified_at: 2020-11-09 @@ -8,6 +8,12 @@ toc: true toc_label: "" tags: - Anomaly + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - T1078.002 - Domain Accounts - Defense Evasion @@ -40,6 +46,7 @@ This search identifies endpoints that have caused a relatively high number of ac | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | | [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | diff --git a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md index fade550c78..a7be33e670 100644 --- a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md +++ b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md @@ -1,6 +1,6 @@ --- title: "Detect Prohibited Applications Spawning cmd exe" -excerpt: "Windows Command Shell" +excerpt: "Command and Scripting Interpreter, Windows Command Shell" categories: - Endpoint last_modified_at: 2020-11-10 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.003 - Windows Command Shell - Execution @@ -38,6 +41,7 @@ This search looks for executions of cmd.exe spawned by a process that is often a | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | diff --git a/docs/_posts/2020-11-18-disabling_remote_user_account_control.md b/docs/_posts/2020-11-18-disabling_remote_user_account_control.md index c16e985b56..5075cd6e06 100644 --- a/docs/_posts/2020-11-18-disabling_remote_user_account_control.md +++ b/docs/_posts/2020-11-18-disabling_remote_user_account_control.md @@ -1,6 +1,6 @@ --- title: "Disabling Remote User Account Control" -excerpt: "Bypass User Account Control" +excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint last_modified_at: 2020-11-18 @@ -12,6 +12,10 @@ tags: - Bypass User Account Control - Privilege Escalation - Defense Evasion + - T1548 + - Abuse Elevation Control Mechanism + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +42,8 @@ The search looks for modifications to registry keys that control the enforcement | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | +| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion || [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md b/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md index cada006e31..3d2fa49ec1 100644 --- a/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md +++ b/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md @@ -1,6 +1,6 @@ --- title: "Execution of File with Multiple Extensions" -excerpt: "Rename System Utilities" +excerpt: "Masquerading, Rename System Utilities" categories: - Endpoint last_modified_at: 2020-11-18 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1036 + - Masquerading + - Defense Evasion - T1036.003 - Rename System Utilities - Defense Evasion @@ -38,6 +41,7 @@ This search looks for processes launched from files that have double extensions | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | | [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | diff --git a/docs/_posts/2020-11-23-monitor_registry_keys_for_print_monitors.md b/docs/_posts/2020-11-23-monitor_registry_keys_for_print_monitors.md index 6a3611b622..f87d03635c 100644 --- a/docs/_posts/2020-11-23-monitor_registry_keys_for_print_monitors.md +++ b/docs/_posts/2020-11-23-monitor_registry_keys_for_print_monitors.md @@ -1,6 +1,6 @@ --- title: "Monitor Registry Keys for Print Monitors" -excerpt: "Port Monitors" +excerpt: "Port Monitors, Boot or Logon Autostart Execution" categories: - Endpoint last_modified_at: 2020-11-23 @@ -12,6 +12,10 @@ tags: - Port Monitors - Persistence - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +42,8 @@ This search looks for registry activity associated with modifications to the reg | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1547.010](https://attack.mitre.org/techniques/T1547/010/) | Port Monitors | Persistence, Privilege Escalation | +| [T1547.010](https://attack.mitre.org/techniques/T1547/010/) | Port Monitors | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md b/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md index 61fda801af..86066c159e 100644 --- a/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md +++ b/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md @@ -1,6 +1,6 @@ --- title: "Shim Database Installation With Suspicious Parameters" -excerpt: "Application Shimming" +excerpt: "Application Shimming, Event Triggered Execution" categories: - Endpoint last_modified_at: 2020-11-23 @@ -12,6 +12,10 @@ tags: - Application Shimming - Privilege Escalation - Persistence + - T1546 + - Event Triggered Execution + - Privilege Escalation + - Persistence - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This search detects the process execution and arguments required to silently cre | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Privilege Escalation, Persistence | +| [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Privilege Escalation, Persistence || [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | + #### Search diff --git a/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md b/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md index d74d8c60ab..40e2e74f16 100644 --- a/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md +++ b/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md @@ -1,6 +1,6 @@ --- title: "Reg exe Manipulating Windows Services Registry Keys" -excerpt: "Services Registry Permissions Weakness" +excerpt: "Services Registry Permissions Weakness, Hijack Execution Flow" categories: - Endpoint last_modified_at: 2020-11-26 @@ -13,6 +13,11 @@ tags: - Persistence - Privilege Escalation - Defense Evasion + - T1574 + - Hijack Execution Flow + - Persistence + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +45,8 @@ The search looks for reg.exe modifying registry keys that define Windows service | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1574.011](https://attack.mitre.org/techniques/T1574/011/) | Services Registry Permissions Weakness | Persistence, Privilege Escalation, Defense Evasion | +| [T1574.011](https://attack.mitre.org/techniques/T1574/011/) | Services Registry Permissions Weakness | Persistence, Privilege Escalation, Defense Evasion || [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Persistence, Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2020-11-26-registry_keys_for_creating_shim_databases.md b/docs/_posts/2020-11-26-registry_keys_for_creating_shim_databases.md index 58d24d8968..9c9818b556 100644 --- a/docs/_posts/2020-11-26-registry_keys_for_creating_shim_databases.md +++ b/docs/_posts/2020-11-26-registry_keys_for_creating_shim_databases.md @@ -1,6 +1,6 @@ --- title: "Registry Keys for Creating SHIM Databases" -excerpt: "Application Shimming" +excerpt: "Application Shimming, Event Triggered Execution" categories: - Endpoint last_modified_at: 2020-11-26 @@ -12,6 +12,10 @@ tags: - Application Shimming - Privilege Escalation - Persistence + - T1546 + - Event Triggered Execution + - Privilege Escalation + - Persistence - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +42,8 @@ This search looks for registry activity associated with application compatibilit | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Privilege Escalation, Persistence | +| [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Privilege Escalation, Persistence || [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | + #### Search diff --git a/docs/_posts/2020-11-27-registry_keys_used_for_privilege_escalation.md b/docs/_posts/2020-11-27-registry_keys_used_for_privilege_escalation.md index f6cd226bba..c28916af21 100644 --- a/docs/_posts/2020-11-27-registry_keys_used_for_privilege_escalation.md +++ b/docs/_posts/2020-11-27-registry_keys_used_for_privilege_escalation.md @@ -1,6 +1,6 @@ --- title: "Registry Keys Used For Privilege Escalation" -excerpt: "Image File Execution Options Injection" +excerpt: "Image File Execution Options Injection, Event Triggered Execution" categories: - Endpoint last_modified_at: 2020-11-27 @@ -12,6 +12,10 @@ tags: - Image File Execution Options Injection - Privilege Escalation - Persistence + - T1546 + - Event Triggered Execution + - Privilege Escalation + - Persistence - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +42,8 @@ This search looks for modifications to registry keys that can be used to elevate | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1546.012](https://attack.mitre.org/techniques/T1546/012/) | Image File Execution Options Injection | Privilege Escalation, Persistence | +| [T1546.012](https://attack.mitre.org/techniques/T1546/012/) | Image File Execution Options Injection | Privilege Escalation, Persistence || [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | + #### Search diff --git a/docs/_posts/2020-11-30-rundll_loading_dll_by_ordinal.md b/docs/_posts/2020-11-30-rundll_loading_dll_by_ordinal.md index 60eff6d597..2a15cb900a 100644 --- a/docs/_posts/2020-11-30-rundll_loading_dll_by_ordinal.md +++ b/docs/_posts/2020-11-30-rundll_loading_dll_by_ordinal.md @@ -1,6 +1,6 @@ --- title: "RunDLL Loading DLL By Ordinal" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2020-11-30 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ This search looks for executing scripts with rundll32. Adversaries may abuse run | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md b/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md index 4d627a2284..4fec906cd3 100644 --- a/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md +++ b/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md @@ -1,6 +1,6 @@ --- title: "Schtasks used for forcing a reboot" -excerpt: "Scheduled Task" +excerpt: "Scheduled Task, Scheduled Task/Job" categories: - Endpoint last_modified_at: 2020-12-07 @@ -13,6 +13,11 @@ tags: - Execution - Persistence - Privilege Escalation + - T1053 + - Scheduled Task/Job + - Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +45,8 @@ This search looks for flags passed to schtasks.exe on the command-line that indi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | +| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation || [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2020-12-08-shim_database_file_creation.md b/docs/_posts/2020-12-08-shim_database_file_creation.md index ee52a6cf26..6af4148552 100644 --- a/docs/_posts/2020-12-08-shim_database_file_creation.md +++ b/docs/_posts/2020-12-08-shim_database_file_creation.md @@ -1,6 +1,6 @@ --- title: "Shim Database File Creation" -excerpt: "Application Shimming" +excerpt: "Application Shimming, Event Triggered Execution" categories: - Endpoint last_modified_at: 2020-12-08 @@ -12,6 +12,10 @@ tags: - Application Shimming - Privilege Escalation - Persistence + - T1546 + - Event Triggered Execution + - Privilege Escalation + - Persistence - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +42,8 @@ This search looks for shim database files being written to default directories. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Privilege Escalation, Persistence | +| [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Privilege Escalation, Persistence || [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | + #### Search diff --git a/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md b/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md index b33105830f..23c6a786b5 100644 --- a/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md +++ b/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md @@ -1,6 +1,6 @@ --- title: "Single Letter Process On Endpoint" -excerpt: "Malicious File" +excerpt: "User Execution, Malicious File" categories: - Endpoint last_modified_at: 2020-12-08 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1204 + - User Execution + - Execution - T1204.002 - Malicious File - Execution @@ -38,6 +41,7 @@ This search looks for process names that consist only of a single letter. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | | [T1204.002](https://attack.mitre.org/techniques/T1204/002/) | Malicious File | Execution | diff --git a/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md b/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md index e20621be76..bc40027eaa 100644 --- a/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md +++ b/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md @@ -1,6 +1,6 @@ --- title: "System Processes Run From Unexpected Locations" -excerpt: "Rename System Utilities" +excerpt: "Masquerading, Rename System Utilities" categories: - Endpoint last_modified_at: 2020-12-08 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1036 + - Masquerading + - Defense Evasion - T1036.003 - Rename System Utilities - Defense Evasion @@ -40,6 +43,7 @@ During triage, review the parallel processes - what process moved the native Win | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | | [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | diff --git a/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md b/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md index e526e78208..2b9f7a4a6c 100644 --- a/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md +++ b/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md @@ -1,6 +1,6 @@ --- title: "WMI Permanent Event Subscription - Sysmon" -excerpt: "Windows Management Instrumentation Event Subscription" +excerpt: "Windows Management Instrumentation Event Subscription, Event Triggered Execution" categories: - Endpoint last_modified_at: 2020-12-08 @@ -12,6 +12,10 @@ tags: - Windows Management Instrumentation Event Subscription - Privilege Escalation - Persistence + - T1546 + - Event Triggered Execution + - Privilege Escalation + - Persistence - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -43,7 +47,8 @@ Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToCons | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1546.003](https://attack.mitre.org/techniques/T1546/003/) | Windows Management Instrumentation Event Subscription | Privilege Escalation, Persistence | +| [T1546.003](https://attack.mitre.org/techniques/T1546/003/) | Windows Management Instrumentation Event Subscription | Privilege Escalation, Persistence || [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | + #### Search diff --git a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md index 8823e1be3e..0bf0caf542 100644 --- a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md +++ b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md @@ -1,6 +1,6 @@ --- title: "O365 Suspicious Rights Delegation" -excerpt: "Remote Email Collection" +excerpt: "Remote Email Collection, Email Collection" categories: - Cloud last_modified_at: 2020-12-15 @@ -11,6 +11,9 @@ tags: - T1114.002 - Remote Email Collection - Collection + - T1114 + - Email Collection + - Collection - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ This search detects the assignment of rights to accesss content from another mai | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1114.002](https://attack.mitre.org/techniques/T1114/002/) | Remote Email Collection | Collection | +| [T1114.002](https://attack.mitre.org/techniques/T1114/002/) | Remote Email Collection | Collection || [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | + #### Search diff --git a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md index 85acdf5bc4..ffba5e3e75 100644 --- a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md +++ b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md @@ -1,6 +1,6 @@ --- title: "High Number of Login Failures from a single source" -excerpt: "Password Guessing" +excerpt: "Password Guessing, Brute Force" categories: - Cloud last_modified_at: 2020-12-16 @@ -11,6 +11,9 @@ tags: - T1110.001 - Password Guessing - Credential Access + - T1110 + - Brute Force + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +42,8 @@ This search will detect more than 5 login failures in Office365 Azure Active Dir | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1110.001](https://attack.mitre.org/techniques/T1110/001/) | Password Guessing | Credential Access | +| [T1110.001](https://attack.mitre.org/techniques/T1110/001/) | Password Guessing | Credential Access || [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + #### Search diff --git a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md index 00b582f383..e973bfd2d4 100644 --- a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md +++ b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md @@ -1,6 +1,6 @@ --- title: "O365 Suspicious Admin Email Forwarding" -excerpt: "Email Forwarding Rule" +excerpt: "Email Forwarding Rule, Email Collection" categories: - Cloud last_modified_at: 2020-12-16 @@ -11,6 +11,9 @@ tags: - T1114.003 - Email Forwarding Rule - Collection + - T1114 + - Email Collection + - Collection - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ This search detects when an admin configured a forwarding rule for multiple mail | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1114.003](https://attack.mitre.org/techniques/T1114/003/) | Email Forwarding Rule | Collection | +| [T1114.003](https://attack.mitre.org/techniques/T1114/003/) | Email Forwarding Rule | Collection || [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | + #### Search diff --git a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md index c8f655f2ab..28945b7039 100644 --- a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md +++ b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md @@ -1,6 +1,6 @@ --- title: "O365 Suspicious User Email Forwarding" -excerpt: "Email Forwarding Rule" +excerpt: "Email Forwarding Rule, Email Collection" categories: - Cloud last_modified_at: 2020-12-16 @@ -11,6 +11,9 @@ tags: - T1114.003 - Email Forwarding Rule - Collection + - T1114 + - Email Collection + - Collection - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ This search detects when multiple user configured a forwarding rule to the same | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1114.003](https://attack.mitre.org/techniques/T1114/003/) | Email Forwarding Rule | Collection | +| [T1114.003](https://attack.mitre.org/techniques/T1114/003/) | Email Forwarding Rule | Collection || [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | + #### Search diff --git a/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md b/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md index 9a98f0209e..faf6c73036 100644 --- a/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md +++ b/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md @@ -1,6 +1,6 @@ --- title: "Scheduled Task Deleted Or Created via CMD" -excerpt: "Scheduled Task" +excerpt: "Scheduled Task, Scheduled Task/Job" categories: - Endpoint last_modified_at: 2020-12-17 @@ -13,6 +13,11 @@ tags: - Execution - Persistence - Privilege Escalation + - T1053 + - Scheduled Task/Job + - Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +45,8 @@ This search looks for flags passed to schtasks.exe on the command-line that indi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | +| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation || [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md b/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md index 6ddf3dd376..b998a87230 100644 --- a/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md +++ b/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md @@ -1,6 +1,6 @@ --- title: "AWS Network Access Control List Created with All Open Ports" -excerpt: "Disable or Modify Cloud Firewall" +excerpt: "Disable or Modify Cloud Firewall, Impair Defenses" categories: - Cloud last_modified_at: 2021-01-11 @@ -11,6 +11,9 @@ tags: - T1562.007 - Disable or Modify Cloud Firewall - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ The search looks for AWS CloudTrail events to detect if any network ACLs were cr | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | +| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md b/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md index 8a27162491..3246a87df0 100644 --- a/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md +++ b/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md @@ -1,6 +1,6 @@ --- title: "AWS Network Access Control List Deleted" -excerpt: "Disable or Modify Cloud Firewall" +excerpt: "Disable or Modify Cloud Firewall, Impair Defenses" categories: - Cloud last_modified_at: 2021-01-12 @@ -11,6 +11,9 @@ tags: - T1562.007 - Disable or Modify Cloud Firewall - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ Enforcing network-access controls is one of the defensive mechanisms used by clo | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | +| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_path.md b/docs/_posts/2021-01-12-suspicious_msbuild_path.md index 87cdaba494..428942fb7e 100644 --- a/docs/_posts/2021-01-12-suspicious_msbuild_path.md +++ b/docs/_posts/2021-01-12-suspicious_msbuild_path.md @@ -1,6 +1,6 @@ --- title: "Suspicious msbuild path" -excerpt: "MSBuild, Rename System Utilities" +excerpt: "Masquerading, Trusted Developer Utilities Proxy Execution, Rename System Utilities, MSBuild" categories: - Endpoint last_modified_at: 2021-01-12 @@ -8,12 +8,18 @@ toc: true toc_label: "" tags: - TTP - - T1127.001 - - MSBuild + - T1036 + - Masquerading + - Defense Evasion + - T1127 + - Trusted Developer Utilities Proxy Execution - Defense Evasion - T1036.003 - Rename System Utilities - Defense Evasion + - T1127.001 + - MSBuild + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +47,9 @@ The following analytic identifies msbuild.exe executing from a non-standard path | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion || [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | +| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | +| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | +| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion || [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | #### Search diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_rename.md b/docs/_posts/2021-01-12-suspicious_msbuild_rename.md index d5a941f14c..0c58830783 100644 --- a/docs/_posts/2021-01-12-suspicious_msbuild_rename.md +++ b/docs/_posts/2021-01-12-suspicious_msbuild_rename.md @@ -1,6 +1,6 @@ --- title: "Suspicious MSBuild Rename" -excerpt: "MSBuild, Rename System Utilities" +excerpt: "Masquerading, Trusted Developer Utilities Proxy Execution, Rename System Utilities, MSBuild" categories: - Endpoint last_modified_at: 2021-01-12 @@ -8,12 +8,18 @@ toc: true toc_label: "" tags: - TTP - - T1127.001 - - MSBuild + - T1036 + - Masquerading + - Defense Evasion + - T1127 + - Trusted Developer Utilities Proxy Execution - Defense Evasion - T1036.003 - Rename System Utilities - Defense Evasion + - T1127.001 + - MSBuild + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +47,9 @@ The following analytic identifies renamed instances of msbuild.exe executing. Ms | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion || [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | +| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | +| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | +| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion || [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | #### Search diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md b/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md index fb446a3d9d..23f7f59f3e 100644 --- a/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md +++ b/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md @@ -1,6 +1,6 @@ --- title: "Suspicious MSBuild Spawn" -excerpt: "MSBuild" +excerpt: "Trusted Developer Utilities Proxy Execution, MSBuild" categories: - Endpoint last_modified_at: 2021-01-12 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1127 + - Trusted Developer Utilities Proxy Execution + - Defense Evasion - T1127.001 - MSBuild - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies wmiprvse.exe spawning msbuild.exe. This behavi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | | [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | diff --git a/docs/_posts/2021-01-12-suspicious_mshta_child_process.md b/docs/_posts/2021-01-12-suspicious_mshta_child_process.md index b564d621b6..0c560af9e8 100644 --- a/docs/_posts/2021-01-12-suspicious_mshta_child_process.md +++ b/docs/_posts/2021-01-12-suspicious_mshta_child_process.md @@ -1,6 +1,6 @@ --- title: "Suspicious mshta child process" -excerpt: "Mshta" +excerpt: "Signed Binary Proxy Execution, Mshta" categories: - Endpoint last_modified_at: 2021-01-12 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.005 - Mshta - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies child processes spawning from "mshta.exe& | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | diff --git a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md b/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md index ed5582c236..4802e912d6 100644 --- a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md +++ b/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md @@ -1,6 +1,6 @@ --- title: "Malicious PowerShell Process With Obfuscation Techniques" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2021-01-19 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -39,6 +42,7 @@ This search looks for PowerShell processes launched with arguments that have cha | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md b/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md index 2830d99230..9f8645aad4 100644 --- a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md +++ b/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md @@ -1,6 +1,6 @@ --- title: "Detect Rundll32 Inline HTA Execution" -excerpt: "Mshta" +excerpt: "Signed Binary Proxy Execution, Mshta" categories: - Endpoint last_modified_at: 2021-01-20 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.005 - Mshta - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies "rundll32.exe" execution with inline p | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | diff --git a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md b/docs/_posts/2021-01-20-suspicious_mshta_spawn.md index 354669dcc1..be3290541f 100644 --- a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md +++ b/docs/_posts/2021-01-20-suspicious_mshta_spawn.md @@ -1,6 +1,6 @@ --- title: "Suspicious mshta spawn" -excerpt: "Mshta" +excerpt: "Signed Binary Proxy Execution, Mshta" categories: - Endpoint last_modified_at: 2021-01-20 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.005 - Mshta - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies wmiprvse.exe spawning mshta.exe. This behavior | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | diff --git a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md index f49e72aa89..ead4a80ed8 100644 --- a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md +++ b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md @@ -1,6 +1,6 @@ --- title: "O365 Add App Role Assignment Grant User" -excerpt: "Cloud Account" +excerpt: "Cloud Account, Create Account" categories: - Cloud last_modified_at: 2021-01-26 @@ -11,6 +11,9 @@ tags: - T1136.003 - Cloud Account - Persistence + - T1136 + - Create Account + - Persistence - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ This search detects the creation of a new Federation setting by alerting about a | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | +| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence || [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | + #### Search diff --git a/docs/_posts/2021-01-26-o365_added_service_principal.md b/docs/_posts/2021-01-26-o365_added_service_principal.md index 18de310435..9d2b12db37 100644 --- a/docs/_posts/2021-01-26-o365_added_service_principal.md +++ b/docs/_posts/2021-01-26-o365_added_service_principal.md @@ -1,6 +1,6 @@ --- title: "O365 Added Service Principal" -excerpt: "Cloud Account" +excerpt: "Cloud Account, Create Account" categories: - Cloud last_modified_at: 2021-01-26 @@ -11,6 +11,9 @@ tags: - T1136.003 - Cloud Account - Persistence + - T1136 + - Create Account + - Persistence - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ This search detects the creation of a new Federation setting by alerting about a | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | +| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence || [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | + #### Search diff --git a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md index 5f4b48e76b..1d50707976 100644 --- a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md +++ b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md @@ -1,6 +1,6 @@ --- title: "O365 New Federated Domain Added" -excerpt: "Cloud Account" +excerpt: "Cloud Account, Create Account" categories: - Cloud last_modified_at: 2021-01-26 @@ -11,6 +11,9 @@ tags: - T1136.003 - Cloud Account - Persistence + - T1136 + - Create Account + - Persistence - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ This search detects the addition of a new Federated domain. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | +| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence || [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | + #### Search diff --git a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md b/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md index 9ac328538b..f770f0a945 100644 --- a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md +++ b/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md @@ -1,6 +1,6 @@ --- title: "Detect Regsvr32 Application Control Bypass" -excerpt: "Regsvr32" +excerpt: "Signed Binary Proxy Execution, Regsvr32" categories: - Endpoint last_modified_at: 2021-01-28 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.010 - Regsvr32 - Defense Evasion @@ -39,6 +42,7 @@ Upon investigating, look for network connections to remote destinations (interna | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | diff --git a/docs/_posts/2021-01-28-ntdsutil_export_ntds.md b/docs/_posts/2021-01-28-ntdsutil_export_ntds.md index 7f73989521..22dcaacec6 100644 --- a/docs/_posts/2021-01-28-ntdsutil_export_ntds.md +++ b/docs/_posts/2021-01-28-ntdsutil_export_ntds.md @@ -1,6 +1,6 @@ --- title: "Ntdsutil Export NTDS" -excerpt: "NTDS" +excerpt: "NTDS, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-01-28 @@ -11,6 +11,9 @@ tags: - T1003.003 - NTDS - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +43,8 @@ This technique uses "Install from Media" (IFM), which will extract a cop | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | +| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md b/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md index b585c7f7c5..4b3ca01bc7 100644 --- a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md +++ b/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md @@ -1,6 +1,6 @@ --- title: "Suspicious Regsvr32 Register Suspicious Path" -excerpt: "Regsvr32" +excerpt: "Signed Binary Proxy Execution, Regsvr32" categories: - Endpoint last_modified_at: 2021-01-28 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.010 - Regsvr32 - Defense Evasion @@ -38,6 +41,7 @@ Adversaries may abuse Regsvr32.exe to proxy execution of malicious code by using | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md index ffcbe58e76..dd3fa6bd73 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md @@ -1,6 +1,6 @@ --- title: "Detect Rundll32 Application Control Bypass - advpack" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-02-04 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies rundll32.exe loading advpack.dll and ieadvpack | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md index 5c5cda21a2..b748b7c8ab 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md @@ -1,6 +1,6 @@ --- title: "Detect Rundll32 Application Control Bypass - setupapi" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-02-04 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies rundll32.exe loading setupapi.dll and iesetupa | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md index 50eb744557..c1db5f0b1b 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md @@ -1,6 +1,6 @@ --- title: "Detect Rundll32 Application Control Bypass - syssetup" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-02-04 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies rundll32.exe loading syssetup.dll by calling t | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-02-04-suspicious_rundll32_rename.md b/docs/_posts/2021-02-04-suspicious_rundll32_rename.md index 8b9daf3fd8..389f039e0c 100644 --- a/docs/_posts/2021-02-04-suspicious_rundll32_rename.md +++ b/docs/_posts/2021-02-04-suspicious_rundll32_rename.md @@ -1,6 +1,6 @@ --- title: "Suspicious Rundll32 Rename" -excerpt: "Rundll32, Rename System Utilities" +excerpt: "Signed Binary Proxy Execution, Masquerading, Rundll32, Rename System Utilities" categories: - Endpoint last_modified_at: 2021-02-04 @@ -8,6 +8,12 @@ toc: true toc_label: "" tags: - Hunting + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion + - T1036 + - Masquerading + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -41,6 +47,8 @@ The following analytic identifies renamed instances of rundll32.exe executing. r | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | +| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion || [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | diff --git a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md b/docs/_posts/2021-02-04-suspicious_rundll32_startw.md index 9158d38fc4..7f3011bc82 100644 --- a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md +++ b/docs/_posts/2021-02-04-suspicious_rundll32_startw.md @@ -1,6 +1,6 @@ --- title: "Suspicious Rundll32 StartW" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-02-04 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies rundll32.exe executing a DLL function name, St | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md b/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md index 1bd08b9949..523883bd6b 100644 --- a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md +++ b/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md @@ -1,6 +1,6 @@ --- title: "Suspicious Rundll32 dllregisterserver" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-02-09 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies rundll32.exe using dllregisterserver on the co | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md b/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md index fc9e5f1271..a5195dbd8a 100644 --- a/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md +++ b/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md @@ -1,6 +1,6 @@ --- title: "Detect HTML Help Spawn Child Process" -excerpt: "Compiled HTML File" +excerpt: "Signed Binary Proxy Execution, Compiled HTML File" categories: - Endpoint last_modified_at: 2021-02-11 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.001 - Compiled HTML File - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | diff --git a/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md b/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md index 188f709d39..53a513892f 100644 --- a/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md +++ b/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md @@ -1,6 +1,6 @@ --- title: "Detect Regasm Spawning a Process" -excerpt: "Regsvcs/Regasm" +excerpt: "Signed Binary Proxy Execution, Regsvcs/Regasm" categories: - Endpoint last_modified_at: 2021-02-12 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.009 - Regsvcs/Regasm - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies regasm.exe spawning a process. This particular | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | diff --git a/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md b/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md index 3a80c39e31..25d5aa7c99 100644 --- a/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md +++ b/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md @@ -1,6 +1,6 @@ --- title: "Detect Regsvcs Spawning a Process" -excerpt: "Regsvcs/Regasm" +excerpt: "Signed Binary Proxy Execution, Regsvcs/Regasm" categories: - Endpoint last_modified_at: 2021-02-12 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.009 - Regsvcs/Regasm - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies regsvcs.exe spawning a process. This particula | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | diff --git a/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md b/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md index 1504162936..cb48e0033e 100644 --- a/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md +++ b/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md @@ -1,6 +1,6 @@ --- title: "Detect Regasm with Network Connection" -excerpt: "Regsvcs/Regasm" +excerpt: "Signed Binary Proxy Execution, Regsvcs/Regasm" categories: - Endpoint last_modified_at: 2021-02-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.009 - Regsvcs/Regasm - Defense Evasion @@ -37,6 +40,7 @@ The following analytic identifies regasm.exe with a network connection to a publ | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | diff --git a/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md b/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md index 9e39e563ec..6f436e092c 100644 --- a/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md +++ b/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md @@ -1,6 +1,6 @@ --- title: "Detect Regsvcs with Network Connection" -excerpt: "Regsvcs/Regasm" +excerpt: "Signed Binary Proxy Execution, Regsvcs/Regasm" categories: - Endpoint last_modified_at: 2021-02-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.009 - Regsvcs/Regasm - Defense Evasion @@ -37,6 +40,7 @@ The following analytic identifies Regsvcs.exe with a network connection to a pub | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | diff --git a/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md b/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md index 0260349ff1..f64fe794f5 100644 --- a/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md +++ b/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md @@ -1,6 +1,6 @@ --- title: "AWS Create Policy Version to allow all resources" -excerpt: "Cloud Accounts" +excerpt: "Cloud Accounts, Valid Accounts" categories: - Cloud last_modified_at: 2021-02-22 @@ -14,6 +14,12 @@ tags: - Persistence - Privilege Escalation - Initial Access + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -41,7 +47,8 @@ This search looks for AWS CloudTrail events where a user created a policy versio | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | +| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access || [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + #### Search diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md index 95da496f07..31454989c3 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md @@ -1,6 +1,6 @@ --- title: "Suspicious PlistBuddy Usage" -excerpt: "Launch Agent" +excerpt: "Launch Agent, Create or Modify System Process" categories: - Endpoint last_modified_at: 2021-02-22 @@ -12,6 +12,10 @@ tags: - Launch Agent - Persistence - Privilege Escalation + - T1543 + - Create or Modify System Process + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -48,7 +52,8 @@ Upon triage, capture the property list file being written to disk and review for | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1543.001](https://attack.mitre.org/techniques/T1543/001/) | Launch Agent | Persistence, Privilege Escalation | +| [T1543.001](https://attack.mitre.org/techniques/T1543/001/) | Launch Agent | Persistence, Privilege Escalation || [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md index 063270c2bf..30e8efc3ae 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md @@ -1,6 +1,6 @@ --- title: "Suspicious PlistBuddy Usage via OSquery" -excerpt: "Launch Agent" +excerpt: "Launch Agent, Create or Modify System Process" categories: - Endpoint last_modified_at: 2021-02-22 @@ -12,6 +12,10 @@ tags: - Launch Agent - Persistence - Privilege Escalation + - T1543 + - Create or Modify System Process + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -47,7 +51,8 @@ Upon triage, capture the property list file being written to disk and review for | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1543.001](https://attack.mitre.org/techniques/T1543/001/) | Launch Agent | Persistence, Privilege Escalation | +| [T1543.001](https://attack.mitre.org/techniques/T1543/001/) | Launch Agent | Persistence, Privilege Escalation || [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-03-01-any_powershell_downloadfile.md b/docs/_posts/2021-03-01-any_powershell_downloadfile.md index 6843874547..45d2c99ddf 100644 --- a/docs/_posts/2021-03-01-any_powershell_downloadfile.md +++ b/docs/_posts/2021-03-01-any_powershell_downloadfile.md @@ -1,6 +1,6 @@ --- title: "Any Powershell DownloadFile" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2021-03-01 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -38,6 +41,7 @@ The following analytic identifies the use of PowerShell downloading a file using | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-03-01-any_powershell_downloadstring.md b/docs/_posts/2021-03-01-any_powershell_downloadstring.md index f1f60c68ae..e611eb6416 100644 --- a/docs/_posts/2021-03-01-any_powershell_downloadstring.md +++ b/docs/_posts/2021-03-01-any_powershell_downloadstring.md @@ -1,6 +1,6 @@ --- title: "Any Powershell DownloadString" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2021-03-01 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -38,6 +41,7 @@ The following analytic identifies the use of PowerShell downloading a file using | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-03-01-eventvwr_uac_bypass.md b/docs/_posts/2021-03-01-eventvwr_uac_bypass.md index 72e94a3d17..cdfd9f59c4 100644 --- a/docs/_posts/2021-03-01-eventvwr_uac_bypass.md +++ b/docs/_posts/2021-03-01-eventvwr_uac_bypass.md @@ -1,6 +1,6 @@ --- title: "Eventvwr UAC Bypass" -excerpt: "Bypass User Account Control" +excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint last_modified_at: 2021-03-01 @@ -12,6 +12,10 @@ tags: - Bypass User Account Control - Privilege Escalation - Defense Evasion + - T1548 + - Abuse Elevation Control Mechanism + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +44,8 @@ The following search identifies Eventvwr bypass by identifying the registry modi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | +| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion || [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-01-fodhelper_uac_bypass.md b/docs/_posts/2021-03-01-fodhelper_uac_bypass.md index e6d4e626c3..99c3f2914c 100644 --- a/docs/_posts/2021-03-01-fodhelper_uac_bypass.md +++ b/docs/_posts/2021-03-01-fodhelper_uac_bypass.md @@ -1,6 +1,6 @@ --- title: "FodHelper UAC Bypass" -excerpt: "Modify Registry, Bypass User Account Control" +excerpt: "Modify Registry, Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint last_modified_at: 2021-03-01 @@ -15,6 +15,10 @@ tags: - Bypass User Account Control - Privilege Escalation - Defense Evasion + - T1548 + - Abuse Elevation Control Mechanism + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -48,7 +52,8 @@ Upon triage, fodhelper.exe will have a child process and read access will occur | ID | Technique | Tactic | | ----------- | ----------- | -------------- | | [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | +| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion || [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md b/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md index bc650975f9..ca606fda0a 100644 --- a/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md +++ b/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md @@ -1,6 +1,6 @@ --- title: "Ryuk Wake on LAN Command" -excerpt: "Windows Command Shell" +excerpt: "Command and Scripting Interpreter, Windows Command Shell" categories: - Endpoint last_modified_at: 2021-03-01 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.003 - Windows Command Shell - Execution @@ -39,6 +42,7 @@ This Splunk query identifies the use of Wake-on-LAN utilized by Ryuk ransomware. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | diff --git a/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md b/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md index 44c449167f..2c297eaf7e 100644 --- a/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md +++ b/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md @@ -1,6 +1,6 @@ --- title: "Suspicious Scheduled Task from Public Directory" -excerpt: "Scheduled Task" +excerpt: "Scheduled Task, Scheduled Task/Job" categories: - Endpoint last_modified_at: 2021-03-01 @@ -13,6 +13,11 @@ tags: - Execution - Persistence - Privilege Escalation + - T1053 + - Scheduled Task/Job + - Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +46,8 @@ The following detection identifies Scheduled Tasks registering (creating a new t | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | +| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation || [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md b/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md index 2430d5750c..c8421e8318 100644 --- a/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md +++ b/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md @@ -1,6 +1,6 @@ --- title: "AWS SetDefaultPolicyVersion" -excerpt: "Cloud Accounts" +excerpt: "Cloud Accounts, Valid Accounts" categories: - Cloud last_modified_at: 2021-03-02 @@ -14,6 +14,12 @@ tags: - Persistence - Privilege Escalation - Initial Access + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -41,7 +47,8 @@ This search looks for AWS CloudTrail events where a user has set a default polic | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | +| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access || [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + #### Search diff --git a/docs/_posts/2021-03-02-windows_disableantispyware_registry.md b/docs/_posts/2021-03-02-windows_disableantispyware_registry.md index ce1dafdd3e..64ef82624d 100644 --- a/docs/_posts/2021-03-02-windows_disableantispyware_registry.md +++ b/docs/_posts/2021-03-02-windows_disableantispyware_registry.md @@ -1,6 +1,6 @@ --- title: "Windows DisableAntiSpyware Registry" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-02 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The search looks for the Registry Key DisableAntiSpyware set to disable. This is | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md b/docs/_posts/2021-03-03-nishang_powershelltcponeline.md index 85b83daff3..cc12ed1a17 100644 --- a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md +++ b/docs/_posts/2021-03-03-nishang_powershelltcponeline.md @@ -1,6 +1,6 @@ --- title: "Nishang PowershellTCPOneLine" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2021-03-03 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -38,6 +41,7 @@ This query detects the Nishang Invoke-PowerShellTCPOneLine utility that spawns a | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-03-03-w3wp_spawning_shell.md b/docs/_posts/2021-03-03-w3wp_spawning_shell.md index 1a387ac7f9..039f17d79c 100644 --- a/docs/_posts/2021-03-03-w3wp_spawning_shell.md +++ b/docs/_posts/2021-03-03-w3wp_spawning_shell.md @@ -1,6 +1,6 @@ --- title: "W3WP Spawning Shell" -excerpt: "Web Shell" +excerpt: "Server Software Component, Web Shell" categories: - Endpoint last_modified_at: 2021-03-03 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1505 + - Server Software Component + - Persistence - T1505.003 - Web Shell - Persistence @@ -38,6 +41,7 @@ This query identifies a shell, PowerShell.exe or Cmd.exe, spawning from W3WP.exe | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | | [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | diff --git a/docs/_posts/2021-03-12-create_service_in_suspicious_file_path.md b/docs/_posts/2021-03-12-create_service_in_suspicious_file_path.md index 7623e82aa8..84caa63564 100644 --- a/docs/_posts/2021-03-12-create_service_in_suspicious_file_path.md +++ b/docs/_posts/2021-03-12-create_service_in_suspicious_file_path.md @@ -1,6 +1,6 @@ --- title: "Create Service In Suspicious File Path" -excerpt: "Service Execution" +excerpt: "System Services, Service Execution" categories: - Endpoint last_modified_at: 2021-03-12 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1569 + - System Services + - Execution - T1569.002 - Service Execution - Execution @@ -38,6 +41,7 @@ This detection is to identify a creation of "user mode service" where th | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | | [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | diff --git a/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md b/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md index c892d50767..6573b6390f 100644 --- a/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md +++ b/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md @@ -1,6 +1,6 @@ --- title: "AWS IAM Successful Group Deletion" -excerpt: "Cloud Groups, Account Manipulation" +excerpt: "Cloud Groups, Account Manipulation, Permission Groups Discovery" categories: - Cloud last_modified_at: 2021-03-31 @@ -14,6 +14,9 @@ tags: - T1098 - Account Manipulation - Persistence + - T1069 + - Permission Groups Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -42,6 +45,7 @@ The following query uses IAM events to track the success of a group being delete | ID | Technique | Tactic | | ----------- | ----------- | -------------- | | [T1069.003](https://attack.mitre.org/techniques/T1069/003/) | Cloud Groups | Discovery || [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | diff --git a/docs/_posts/2021-03-31-disable_registry_tool.md b/docs/_posts/2021-03-31-disable_registry_tool.md index 19dd5b8b86..53c449c924 100644 --- a/docs/_posts/2021-03-31-disable_registry_tool.md +++ b/docs/_posts/2021-03-31-disable_registry_tool.md @@ -1,6 +1,6 @@ --- title: "Disable Registry Tool" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-31 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search identifies modification of registry to disable the regedit or regist | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-31-disable_show_hidden_files.md b/docs/_posts/2021-03-31-disable_show_hidden_files.md index 993e1c78c9..22110372c1 100644 --- a/docs/_posts/2021-03-31-disable_show_hidden_files.md +++ b/docs/_posts/2021-03-31-disable_show_hidden_files.md @@ -1,6 +1,6 @@ --- title: "Disable Show Hidden Files" -excerpt: "Hidden Files and Directories, Disable or Modify Tools" +excerpt: "Hidden Files and Directories, Disable or Modify Tools, Hide Artifacts, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-31 @@ -14,6 +14,12 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1564 + - Hide Artifacts + - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +47,9 @@ The following analytic is to identify a modification in the Windows registry to | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1564.001](https://attack.mitre.org/techniques/T1564/001/) | Hidden Files and Directories | Defense Evasion || [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1564.001](https://attack.mitre.org/techniques/T1564/001/) | Hidden Files and Directories | Defense Evasion || [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1564](https://attack.mitre.org/techniques/T1564/) | Hide Artifacts | Defense Evasion | +| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-31-disable_windows_behavior_monitoring.md b/docs/_posts/2021-03-31-disable_windows_behavior_monitoring.md index b9577f98bb..6ac1c2dc9e 100644 --- a/docs/_posts/2021-03-31-disable_windows_behavior_monitoring.md +++ b/docs/_posts/2021-03-31-disable_windows_behavior_monitoring.md @@ -1,6 +1,6 @@ --- title: "Disable Windows Behavior Monitoring" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-31 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to identifies a modification in registry to disable the windows d | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-31-disable_windows_smartscreen_protection.md b/docs/_posts/2021-03-31-disable_windows_smartscreen_protection.md index 535f7bcde3..6da7a5c616 100644 --- a/docs/_posts/2021-03-31-disable_windows_smartscreen_protection.md +++ b/docs/_posts/2021-03-31-disable_windows_smartscreen_protection.md @@ -1,6 +1,6 @@ --- title: "Disable Windows SmartScreen Protection" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-31 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following search identifies a modification of registry to disable the smarts | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-31-disabling_cmd_application.md b/docs/_posts/2021-03-31-disabling_cmd_application.md index 279b07d087..9ff0099a37 100644 --- a/docs/_posts/2021-03-31-disabling_cmd_application.md +++ b/docs/_posts/2021-03-31-disabling_cmd_application.md @@ -1,6 +1,6 @@ --- title: "Disabling CMD Application" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-31 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ this search is to identify modification in registry to disable cmd prompt applic | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-31-disabling_controlpanel.md b/docs/_posts/2021-03-31-disabling_controlpanel.md index 583c5c7722..02a1f65115 100644 --- a/docs/_posts/2021-03-31-disabling_controlpanel.md +++ b/docs/_posts/2021-03-31-disabling_controlpanel.md @@ -1,6 +1,6 @@ --- title: "Disabling ControlPanel" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-31 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ this search is to identify registry modification to disable control panel window | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md b/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md index e5dc00ebf7..a1f03b4d25 100644 --- a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md +++ b/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md @@ -1,6 +1,6 @@ --- title: "Disabling Firewall with Netsh" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-31 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to identifies suspicious firewall disabling using netsh applicati | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-31-disabling_folderoptions_windows_feature.md b/docs/_posts/2021-03-31-disabling_folderoptions_windows_feature.md index cdf3ed43e2..eb3c568634 100644 --- a/docs/_posts/2021-03-31-disabling_folderoptions_windows_feature.md +++ b/docs/_posts/2021-03-31-disabling_folderoptions_windows_feature.md @@ -1,6 +1,6 @@ --- title: "Disabling FolderOptions Windows Feature" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-31 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to identify registry modification to disable folder options featu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-31-disabling_norun_windows_app.md b/docs/_posts/2021-03-31-disabling_norun_windows_app.md index 161103c4d1..5328199ff5 100644 --- a/docs/_posts/2021-03-31-disabling_norun_windows_app.md +++ b/docs/_posts/2021-03-31-disabling_norun_windows_app.md @@ -1,6 +1,6 @@ --- title: "Disabling NoRun Windows App" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-31 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to identify modification of registry to disable run application i | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-31-disabling_systemrestore_in_registry.md b/docs/_posts/2021-03-31-disabling_systemrestore_in_registry.md index 19424c0020..b214c5522a 100644 --- a/docs/_posts/2021-03-31-disabling_systemrestore_in_registry.md +++ b/docs/_posts/2021-03-31-disabling_systemrestore_in_registry.md @@ -1,6 +1,6 @@ --- title: "Disabling SystemRestore In Registry" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-31 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following search identifies the modification of registry related in disablin | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-03-31-disabling_task_manager.md b/docs/_posts/2021-03-31-disabling_task_manager.md index 71e9c0f0b8..6ffef1fa2d 100644 --- a/docs/_posts/2021-03-31-disabling_task_manager.md +++ b/docs/_posts/2021-03-31-disabling_task_manager.md @@ -1,6 +1,6 @@ --- title: "Disabling Task Manager" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-03-31 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to identifies modification of registry to disable the task manage | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md b/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md index cc9b0afbbc..0d7d664171 100644 --- a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md +++ b/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md @@ -1,6 +1,6 @@ --- title: "Malicious Powershell Executed As A Service" -excerpt: "Service Execution" +excerpt: "System Services, Service Execution" categories: - Endpoint last_modified_at: 2021-04-07 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1569 + - System Services + - Execution - T1569.002 - Service Execution - Execution @@ -38,6 +41,7 @@ This detection is to identify the abuse the Windows SC.exe to execute malicious | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | | [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | diff --git a/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md index ffc4333087..97bdb52083 100644 --- a/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md +++ b/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md @@ -1,6 +1,6 @@ --- title: "Multiple Users Failing To Authenticate From Host Using Kerberos" -excerpt: "Password Spraying" +excerpt: "Password Spraying, Brute Force" categories: - Endpoint last_modified_at: 2021-04-08 @@ -11,6 +11,9 @@ tags: - T1110.003 - Password Spraying - Credential Access + - T1110 + - Brute Force + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +44,8 @@ The analytics returned fields allow analysts to investigate the event further by | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | +| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access || [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + #### Search diff --git a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md index 9798a5c278..43f09a4ff4 100644 --- a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md +++ b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md @@ -1,6 +1,6 @@ --- title: "WinEvent Scheduled Task Created Within Public Path" -excerpt: "Scheduled Task" +excerpt: "Scheduled Task, Scheduled Task/Job" categories: - Endpoint last_modified_at: 2021-04-08 @@ -13,6 +13,11 @@ tags: - Execution - Persistence - Privilege Escalation + - T1053 + - Scheduled Task/Job + - Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -43,7 +48,8 @@ Upon triage, identify the task scheduled source. Was it schtasks.exe or was it v | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | +| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation || [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-04-12-excel_spawning_powershell.md b/docs/_posts/2021-04-12-excel_spawning_powershell.md index 401bc26f49..1cee7bc67b 100644 --- a/docs/_posts/2021-04-12-excel_spawning_powershell.md +++ b/docs/_posts/2021-04-12-excel_spawning_powershell.md @@ -1,6 +1,6 @@ --- title: "Excel Spawning PowerShell" -excerpt: "Security Account Manager" +excerpt: "Security Account Manager, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-04-12 @@ -11,6 +11,9 @@ tags: - T1003.002 - Security Account Manager - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following detection identifies Microsoft Excel spawning PowerShell. Typicall | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | +| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md b/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md index 923da4c316..852cada8c1 100644 --- a/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md +++ b/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md @@ -1,6 +1,6 @@ --- title: "Excel Spawning Windows Script Host" -excerpt: "Security Account Manager" +excerpt: "Security Account Manager, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-04-12 @@ -11,6 +11,9 @@ tags: - T1003.002 - Security Account Manager - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following detection identifies Microsoft Excel spawning Windows Script Host | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | +| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md b/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md index cd0319302d..c89ca9130e 100644 --- a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md +++ b/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md @@ -1,6 +1,6 @@ --- title: "WinEvent Scheduled Task Created to Spawn Shell" -excerpt: "Scheduled Task" +excerpt: "Scheduled Task, Scheduled Task/Job" categories: - Endpoint last_modified_at: 2021-04-12 @@ -13,6 +13,11 @@ tags: - Execution - Persistence - Privilege Escalation + - T1053 + - Scheduled Task/Job + - Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -43,7 +48,8 @@ Upon triage, identify the task scheduled source. Was it schtasks.exe or via Task | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | +| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation || [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-04-12-winword_spawning_powershell.md b/docs/_posts/2021-04-12-winword_spawning_powershell.md index b45d735e08..6126879072 100644 --- a/docs/_posts/2021-04-12-winword_spawning_powershell.md +++ b/docs/_posts/2021-04-12-winword_spawning_powershell.md @@ -1,6 +1,6 @@ --- title: "Winword Spawning PowerShell" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-04-12 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ The following detection identifies Microsoft Word spawning PowerShell. Typically | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md b/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md index f5d3885b63..51cbd98e32 100644 --- a/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md +++ b/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md @@ -1,6 +1,6 @@ --- title: "Winword Spawning Windows Script Host" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-04-12 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ The following detection identifies Microsoft Winword.exe spawning Windows Script | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md b/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md index 684868a64b..b2e4f90148 100644 --- a/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md +++ b/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md @@ -1,6 +1,6 @@ --- title: "Multiple Users Attempting To Authenticate Using Explicit Credentials" -excerpt: "Password Spraying" +excerpt: "Password Spraying, Brute Force" categories: - Endpoint last_modified_at: 2021-04-13 @@ -11,6 +11,9 @@ tags: - T1110.003 - Password Spraying - Credential Access + - T1110 + - Brute Force + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +44,8 @@ The analytics returned fields allow analysts to investigate the event further by | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | +| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access || [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + #### Search diff --git a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md index 200bda345c..494f2a1fdd 100644 --- a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md +++ b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md @@ -1,6 +1,6 @@ --- title: "Multiple Users Failing To Authenticate From Host Using NTLM" -excerpt: "Password Spraying" +excerpt: "Password Spraying, Brute Force" categories: - Endpoint last_modified_at: 2021-04-13 @@ -11,6 +11,9 @@ tags: - T1110.003 - Password Spraying - Credential Access + - T1110 + - Brute Force + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +44,8 @@ The analytics returned fields allow analysts to investigate the event further by | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | +| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access || [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + #### Search diff --git a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md index 46854a8454..64e9a94b53 100644 --- a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md +++ b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md @@ -1,6 +1,6 @@ --- title: "Multiple Users Failing To Authenticate From Process" -excerpt: "Password Spraying" +excerpt: "Password Spraying, Brute Force" categories: - Endpoint last_modified_at: 2021-04-13 @@ -11,6 +11,9 @@ tags: - T1110.003 - Password Spraying - Credential Access + - T1110 + - Brute Force + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +44,8 @@ The analytics returned fields allow analysts to investigate the event further by | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | +| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access || [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + #### Search diff --git a/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md b/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md index 9be61a4d7f..b365c11ac5 100644 --- a/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md +++ b/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md @@ -1,6 +1,6 @@ --- title: "Multiple Users Remotely Failing To Authenticate From Host" -excerpt: "Password Spraying" +excerpt: "Password Spraying, Brute Force" categories: - Endpoint last_modified_at: 2021-04-13 @@ -11,6 +11,9 @@ tags: - T1110.003 - Password Spraying - Credential Access + - T1110 + - Brute Force + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +44,8 @@ The analytics returned fields allow analysts to investigate the event further by | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | +| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access || [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + #### Search diff --git a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md b/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md index 94bbf4b715..10ce60dc0c 100644 --- a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md +++ b/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md @@ -1,6 +1,6 @@ --- title: "Office Application Spawn rundll32 process" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-04-13 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ this detection was designed to identifies suspicious spawned process of known MS | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md index cd3287c4a5..01c9f5f118 100644 --- a/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md +++ b/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md @@ -1,6 +1,6 @@ --- title: "Multiple Disabled Users Failing To Authenticate From Host Using Kerberos" -excerpt: "Password Spraying" +excerpt: "Password Spraying, Brute Force" categories: - Endpoint last_modified_at: 2021-04-14 @@ -11,6 +11,9 @@ tags: - T1110.003 - Password Spraying - Credential Access + - T1110 + - Brute Force + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +44,8 @@ The analytics returned fields allow analysts to investigate the event further by | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | +| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access || [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + #### Search diff --git a/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md index 1d828ef654..20977d77f5 100644 --- a/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md +++ b/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md @@ -1,6 +1,6 @@ --- title: "Multiple Invalid Users Failing To Authenticate From Host Using Kerberos" -excerpt: "Password Spraying" +excerpt: "Password Spraying, Brute Force" categories: - Endpoint last_modified_at: 2021-04-14 @@ -11,6 +11,9 @@ tags: - T1110.003 - Password Spraying - Credential Access + - T1110 + - Brute Force + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +44,8 @@ The analytics returned fields allow analysts to investigate the event further by | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | +| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access || [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + #### Search diff --git a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md b/docs/_posts/2021-04-14-office_document_creating_schedule_task.md index 74aab63408..533fe1c60c 100644 --- a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md +++ b/docs/_posts/2021-04-14-office_document_creating_schedule_task.md @@ -1,6 +1,6 @@ --- title: "Office Document Creating Schedule Task" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-04-14 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ this search detects a potential malicious office document that create schedule t | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-04-14-office_document_executing_macro_code.md b/docs/_posts/2021-04-14-office_document_executing_macro_code.md index 26d20db2b5..0290b10869 100644 --- a/docs/_posts/2021-04-14-office_document_executing_macro_code.md +++ b/docs/_posts/2021-04-14-office_document_executing_macro_code.md @@ -1,6 +1,6 @@ --- title: "Office Document Executing Macro Code" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-04-14 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ this detection was designed to identifies suspicious office documents that using | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md b/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md index 71d368ae11..43827ef784 100644 --- a/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md +++ b/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md @@ -1,6 +1,6 @@ --- title: "Multiple Invalid Users Failing To Authenticate From Host Using NTLM" -excerpt: "Password Spraying" +excerpt: "Password Spraying, Brute Force" categories: - Endpoint last_modified_at: 2021-04-15 @@ -11,6 +11,9 @@ tags: - T1110.003 - Password Spraying - Credential Access + - T1110 + - Brute Force + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +44,8 @@ The analytics returned fields allow analysts to investigate the event further by | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | +| [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access || [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | + #### Search diff --git a/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md index 514819b7dc..3cce85ba97 100644 --- a/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md +++ b/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md @@ -47,16 +47,16 @@ The following analytic identifies gpupdate.exe with no command line arguments an ``` -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=gpupdate.exe by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=gpupdate.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | regex process="(gpupdate\.exe.{0,4}$)" -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_id Ports.dest Ports.dest_port +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port | `drop_dm_object_name(Ports)` | rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_id connection_to_CNC dest_port +| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port | `gpupdate_with_no_command_line_arguments_with_network_filter` ``` diff --git a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md b/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md index f211d7243f..af2c409153 100644 --- a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md +++ b/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md @@ -1,6 +1,6 @@ --- title: "Wermgr Process Connecting To IP Check Web Services" -excerpt: "IP Addresses" +excerpt: "Gather Victim Network Information, IP Addresses" categories: - Endpoint last_modified_at: 2021-04-19 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1590 + - Gather Victim Network Information + - Reconnaissance - T1590.005 - IP Addresses - Reconnaissance @@ -38,6 +41,7 @@ this search is designed to detect suspicious wermgr.exe process that tries to co | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | | [T1590.005](https://attack.mitre.org/techniques/T1590/005/) | IP Addresses | Reconnaissance | diff --git a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md index e65ff32d92..0bf9ba08b7 100644 --- a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md +++ b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md @@ -1,6 +1,6 @@ --- title: "Multiple Archive Files Http Post Traffic" -excerpt: "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol" +excerpt: "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, Exfiltration Over Alternative Protocol" categories: - Network last_modified_at: 2021-04-21 @@ -11,6 +11,9 @@ tags: - T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol - Exfiltration + - T1048 + - Exfiltration Over Alternative Protocol + - Exfiltration - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is designed to detect high frequency of archive files data exfiltrat | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | +| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration || [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | + #### Search diff --git a/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md b/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md index 41d14ec462..3b570783a9 100644 --- a/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md +++ b/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md @@ -1,6 +1,6 @@ --- title: "Anomalous usage of 7zip" -excerpt: "Archive via Utility" +excerpt: "Archive via Utility, Archive Collected Data" categories: - Endpoint last_modified_at: 2021-04-22 @@ -11,6 +11,9 @@ tags: - T1560.001 - Archive via Utility - Collection + - T1560 + - Archive Collected Data + - Collection - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following detection identifies a 7z.exe spawned from `Rundll32.exe` or `Dllh | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | +| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection || [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | + #### Search diff --git a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md b/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md index a5f0631389..6fda858d8c 100644 --- a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md +++ b/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md @@ -1,6 +1,6 @@ --- title: "Office Product Spawning Rundll32 with no DLL" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-04-22 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ The following detection identifies the latest behavior utilized by IcedID malwar | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md index 45ff6fdefe..ba9c6283a6 100644 --- a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md +++ b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md @@ -1,6 +1,6 @@ --- title: "Plain HTTP POST Exfiltrated Data" -excerpt: "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol" +excerpt: "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, Exfiltration Over Alternative Protocol" categories: - Network last_modified_at: 2021-04-22 @@ -11,6 +11,9 @@ tags: - T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol - Exfiltration + - T1048 + - Exfiltration Over Alternative Protocol + - Exfiltration - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect potential plain HTTP POST method data exfiltration. Thi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | +| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration || [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | + #### Search diff --git a/docs/_posts/2021-04-22-winword_spawning_cmd.md b/docs/_posts/2021-04-22-winword_spawning_cmd.md index 968056a86a..e6b7af4122 100644 --- a/docs/_posts/2021-04-22-winword_spawning_cmd.md +++ b/docs/_posts/2021-04-22-winword_spawning_cmd.md @@ -1,6 +1,6 @@ --- title: "Winword Spawning Cmd" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-04-22 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ The following detection identifies Microsoft Word spawning `cmd.exe`. Typically, | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-04-23-write_executable_in_smb_share.md b/docs/_posts/2021-04-23-write_executable_in_smb_share.md index a8d1ab763e..61128cfe66 100644 --- a/docs/_posts/2021-04-23-write_executable_in_smb_share.md +++ b/docs/_posts/2021-04-23-write_executable_in_smb_share.md @@ -1,6 +1,6 @@ --- title: "Write Executable in SMB Share" -excerpt: "SMB/Windows Admin Shares" +excerpt: "Remote Services, SMB/Windows Admin Shares" categories: - Endpoint last_modified_at: 2021-04-23 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1021 + - Remote Services + - Lateral Movement - T1021.002 - SMB/Windows Admin Shares - Lateral Movement @@ -38,6 +41,7 @@ This search is to detect suspicious dropping or creating an executable file in k | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | | [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | diff --git a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md index 69074c1d73..cc65e79f09 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md +++ b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md @@ -1,6 +1,6 @@ --- title: "Office Product Spawning BITSAdmin" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-04-26 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ The following detection identifies the latest behavior utilized by different mal | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-04-26-office_product_spawning_certutil.md b/docs/_posts/2021-04-26-office_product_spawning_certutil.md index 1a60e2cf43..383daad39f 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_certutil.md +++ b/docs/_posts/2021-04-26-office_product_spawning_certutil.md @@ -1,6 +1,6 @@ --- title: "Office Product Spawning CertUtil" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-04-26 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ The following detection identifies the latest behavior utilized by different mal | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-04-26-office_product_spawning_mshta.md b/docs/_posts/2021-04-26-office_product_spawning_mshta.md index 67b19c28c6..ec43a31847 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_mshta.md +++ b/docs/_posts/2021-04-26-office_product_spawning_mshta.md @@ -1,6 +1,6 @@ --- title: "Office Product Spawning MSHTA" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-04-26 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ The following detection identifies the latest behavior utilized by different mal | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md b/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md index 370e2e4c65..022deab0d6 100644 --- a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md +++ b/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md @@ -1,6 +1,6 @@ --- title: "Suspicious Driver Loaded Path" -excerpt: "Windows Service" +excerpt: "Windows Service, Create or Modify System Process" categories: - Endpoint last_modified_at: 2021-04-29 @@ -12,6 +12,10 @@ tags: - Windows Service - Persistence - Privilege Escalation + - T1543 + - Create or Modify System Process + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This analytic will detect suspicious driver loaded paths. This technique is comm | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | +| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation || [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-04-29-xmrig_driver_loaded.md b/docs/_posts/2021-04-29-xmrig_driver_loaded.md index 8f8aba2d7e..4aabd9d918 100644 --- a/docs/_posts/2021-04-29-xmrig_driver_loaded.md +++ b/docs/_posts/2021-04-29-xmrig_driver_loaded.md @@ -1,6 +1,6 @@ --- title: "XMRIG Driver Loaded" -excerpt: "Windows Service" +excerpt: "Windows Service, Create or Modify System Process" categories: - Endpoint last_modified_at: 2021-04-29 @@ -12,6 +12,10 @@ tags: - Windows Service - Persistence - Privilege Escalation + - T1543 + - Create or Modify System Process + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This analytic identifies XMRIG coinminer driver installation on the system. The | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | +| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation || [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md b/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md index d16d279de9..c1fbbeaccb 100644 --- a/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md +++ b/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md @@ -1,6 +1,6 @@ --- title: "Excessive Usage Of Taskkill" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-05-04 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic identifies excessive usage of `taskkill.exe` application. This app | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md b/docs/_posts/2021-05-04-process_kill_base_on_file_path.md index 4a4858cf4c..d827907959 100644 --- a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md +++ b/docs/_posts/2021-05-04-process_kill_base_on_file_path.md @@ -1,6 +1,6 @@ --- title: "Process Kill Base On File Path" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-05-04 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following analytic identifies the use of `wmic.exe` using `delete` to remove | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-05-05-disable_windows_app_hotkeys.md b/docs/_posts/2021-05-05-disable_windows_app_hotkeys.md index 758a867438..dc0140d603 100644 --- a/docs/_posts/2021-05-05-disable_windows_app_hotkeys.md +++ b/docs/_posts/2021-05-05-disable_windows_app_hotkeys.md @@ -1,6 +1,6 @@ --- title: "Disable Windows App Hotkeys" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-05-05 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic detects a suspicious registry modification to disable Windows hotk | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-05-05-hide_user_account_from_sign-in_screen.md b/docs/_posts/2021-05-05-hide_user_account_from_sign-in_screen.md index 53e01b313e..25378dcad2 100644 --- a/docs/_posts/2021-05-05-hide_user_account_from_sign-in_screen.md +++ b/docs/_posts/2021-05-05-hide_user_account_from_sign-in_screen.md @@ -1,6 +1,6 @@ --- title: "Hide User Account From Sign-In Screen" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-05-05 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic identifies a suspicious registry modification to hide a user accou | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md b/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md index 83173242bb..8083284ce9 100644 --- a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md +++ b/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md @@ -1,6 +1,6 @@ --- title: "CMLUA Or CMSTPLUA UAC Bypass" -excerpt: "CMSTP" +excerpt: "Signed Binary Proxy Execution, CMSTP" categories: - Endpoint last_modified_at: 2021-05-13 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.003 - CMSTP - Defense Evasion @@ -38,6 +41,7 @@ This analytic detects a potential process using COM Object like CMLUA or CMSTPLU | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.003](https://attack.mitre.org/techniques/T1218/003/) | CMSTP | Defense Evasion | diff --git a/docs/_posts/2021-05-13-slui_runas_elevated.md b/docs/_posts/2021-05-13-slui_runas_elevated.md index 6e07e3fff0..b4eda915d7 100644 --- a/docs/_posts/2021-05-13-slui_runas_elevated.md +++ b/docs/_posts/2021-05-13-slui_runas_elevated.md @@ -1,6 +1,6 @@ --- title: "SLUI RunAs Elevated" -excerpt: "Bypass User Account Control" +excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint last_modified_at: 2021-05-13 @@ -12,6 +12,10 @@ tags: - Bypass User Account Control - Privilege Escalation - Defense Evasion + - T1548 + - Abuse Elevation Control Mechanism + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ The following analytic identifies the Microsoft Software Licensing User Interfac | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | +| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion || [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2021-05-13-slui_spawning_a_process.md b/docs/_posts/2021-05-13-slui_spawning_a_process.md index 32f40f520a..a8724776fb 100644 --- a/docs/_posts/2021-05-13-slui_spawning_a_process.md +++ b/docs/_posts/2021-05-13-slui_spawning_a_process.md @@ -1,6 +1,6 @@ --- title: "SLUI Spawning a Process" -excerpt: "Bypass User Account Control" +excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint last_modified_at: 2021-05-13 @@ -12,6 +12,10 @@ tags: - Bypass User Account Control - Privilege Escalation - Defense Evasion + - T1548 + - Abuse Elevation Control Mechanism + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ The following analytic identifies the Microsoft Software Licensing User Interfac | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | +| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion || [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md b/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md index 05e82effe3..72f6d4bf1f 100644 --- a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md +++ b/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md @@ -1,6 +1,6 @@ --- title: "Allow Inbound Traffic In Firewall Rule" -excerpt: "Remote Desktop Protocol" +excerpt: "Remote Desktop Protocol, Remote Services" categories: - Endpoint last_modified_at: 2021-05-19 @@ -11,6 +11,9 @@ tags: - T1021.001 - Remote Desktop Protocol - Lateral Movement + - T1021 + - Remote Services + - Lateral Movement - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following analytic identifies suspicious PowerShell command to allow inbound | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | +| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement || [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | + #### Search diff --git a/docs/_posts/2021-05-19-mailsniper_invoke_functions.md b/docs/_posts/2021-05-19-mailsniper_invoke_functions.md index 0c92bd2ccc..fc366be4cd 100644 --- a/docs/_posts/2021-05-19-mailsniper_invoke_functions.md +++ b/docs/_posts/2021-05-19-mailsniper_invoke_functions.md @@ -1,6 +1,6 @@ --- title: "Mailsniper Invoke functions" -excerpt: "Local Email Collection" +excerpt: "Email Collection, Local Email Collection" categories: - Endpoint last_modified_at: 2021-05-19 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1114 + - Email Collection + - Collection - T1114.001 - Local Email Collection - Collection @@ -38,6 +41,7 @@ This search is to detect known mailsniper.ps1 functions executed in a machine. T | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | | [T1114.001](https://attack.mitre.org/techniques/T1114/001/) | Local Email Collection | Collection | diff --git a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md b/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md index c2cc2049d7..0eaacd8d1c 100644 --- a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md +++ b/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md @@ -1,6 +1,6 @@ --- title: "CMD Echo Pipe - Escalation" -excerpt: "Windows Command Shell, Windows Service" +excerpt: "Command and Scripting Interpreter, Windows Command Shell, Windows Service, Create or Modify System Process" categories: - Endpoint last_modified_at: 2021-05-20 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.003 - Windows Command Shell - Execution @@ -15,6 +18,10 @@ tags: - Windows Service - Persistence - Privilege Escalation + - T1543 + - Create or Modify System Process + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -43,7 +50,9 @@ This analytic identifies a common behavior by Cobalt Strike and other frameworks | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution || [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | +| [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution || [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation || [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md b/docs/_posts/2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md index 9882460fb6..9058306cbc 100644 --- a/docs/_posts/2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md +++ b/docs/_posts/2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md @@ -1,6 +1,6 @@ --- title: "Allow Inbound Traffic By Firewall Rule Registry" -excerpt: "Remote Desktop Protocol" +excerpt: "Remote Desktop Protocol, Remote Services" categories: - Endpoint last_modified_at: 2021-05-26 @@ -11,6 +11,9 @@ tags: - T1021.001 - Remote Desktop Protocol - Lateral Movement + - T1021 + - Remote Services + - Lateral Movement - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic detects a potential suspicious modification of firewall rule regis | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | +| [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement || [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | + #### Search diff --git a/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md b/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md index f6b9a63393..c692dbb0a6 100644 --- a/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md +++ b/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md @@ -1,6 +1,6 @@ --- title: "SecretDumps Offline NTDS Dumping Tool" -excerpt: "NTDS" +excerpt: "NTDS, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-05-26 @@ -11,6 +11,9 @@ tags: - T1003.003 - NTDS - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic detects a potential usage of secretsdump.py tool for dumping crede | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | +| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md b/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md index 2a507d4662..79b49452ec 100644 --- a/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md +++ b/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md @@ -1,6 +1,6 @@ --- title: "Detect SharpHound File Modifications" -excerpt: "Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups" +excerpt: "Domain Account, Local Groups, Domain Trust Discovery, Local Account, Account Discovery, Domain Groups, Permission Groups Discovery" categories: - Endpoint last_modified_at: 2021-05-27 @@ -11,17 +11,23 @@ tags: - T1087.002 - Domain Account - Discovery - - T1087.001 - - Local Account + - T1069.001 + - Local Groups - Discovery - T1482 - Domain Trust Discovery - Discovery + - T1087.001 + - Local Account + - Discovery + - T1087 + - Account Discovery + - Discovery - T1069.002 - Domain Groups - Discovery - - T1069.001 - - Local Groups + - T1069 + - Permission Groups Discovery - Discovery - Splunk Enterprise - Splunk Enterprise Security @@ -50,8 +56,10 @@ SharpHound is used as a reconnaissance collector, ingestor, for BloodHound. Shar | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery || [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery || [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery || [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | +| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | +| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery || [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-05-27-detect_sharphound_usage.md b/docs/_posts/2021-05-27-detect_sharphound_usage.md index cb96bc6bc5..45e4b65f35 100644 --- a/docs/_posts/2021-05-27-detect_sharphound_usage.md +++ b/docs/_posts/2021-05-27-detect_sharphound_usage.md @@ -1,6 +1,6 @@ --- title: "Detect SharpHound Usage" -excerpt: "Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups" +excerpt: "Domain Account, Local Groups, Domain Trust Discovery, Local Account, Account Discovery, Domain Groups, Permission Groups Discovery" categories: - Endpoint last_modified_at: 2021-05-27 @@ -11,17 +11,23 @@ tags: - T1087.002 - Domain Account - Discovery - - T1087.001 - - Local Account + - T1069.001 + - Local Groups - Discovery - T1482 - Domain Trust Discovery - Discovery + - T1087.001 + - Local Account + - Discovery + - T1087 + - Account Discovery + - Discovery - T1069.002 - Domain Groups - Discovery - - T1069.001 - - Local Groups + - T1069 + - Permission Groups Discovery - Discovery - Splunk Enterprise - Splunk Enterprise Security @@ -50,8 +56,10 @@ The following analytic identifies SharpHound binary usage by using the original | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery || [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery || [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery || [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | +| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | +| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery || [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md b/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md index a806327270..a23cd9ebd5 100644 --- a/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md +++ b/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md @@ -1,6 +1,6 @@ --- title: "Detect AzureHound Command-Line Arguments" -excerpt: "Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups" +excerpt: "Domain Account, Local Groups, Domain Trust Discovery, Local Account, Account Discovery, Domain Groups, Permission Groups Discovery" categories: - Endpoint last_modified_at: 2021-06-01 @@ -11,17 +11,23 @@ tags: - T1087.002 - Domain Account - Discovery - - T1087.001 - - Local Account + - T1069.001 + - Local Groups - Discovery - T1482 - Domain Trust Discovery - Discovery + - T1087.001 + - Local Account + - Discovery + - T1087 + - Account Discovery + - Discovery - T1069.002 - Domain Groups - Discovery - - T1069.001 - - Local Groups + - T1069 + - Permission Groups Discovery - Discovery - Splunk Enterprise - Splunk Enterprise Security @@ -50,8 +56,10 @@ The following analytic identifies the common command-line argument used by Azure | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery || [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery || [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery || [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | +| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | +| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery || [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md b/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md index c565783178..31bb8cef18 100644 --- a/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md +++ b/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md @@ -1,6 +1,6 @@ --- title: "Detect AzureHound File Modifications" -excerpt: "Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups" +excerpt: "Domain Account, Local Groups, Domain Trust Discovery, Local Account, Account Discovery, Domain Groups, Permission Groups Discovery" categories: - Endpoint last_modified_at: 2021-06-01 @@ -11,17 +11,23 @@ tags: - T1087.002 - Domain Account - Discovery - - T1087.001 - - Local Account + - T1069.001 + - Local Groups - Discovery - T1482 - Domain Trust Discovery - Discovery + - T1087.001 + - Local Account + - Discovery + - T1087 + - Account Discovery + - Discovery - T1069.002 - Domain Groups - Discovery - - T1069.001 - - Local Groups + - T1069 + - Permission Groups Discovery - Discovery - Splunk Enterprise - Splunk Enterprise Security @@ -50,8 +56,10 @@ The following analytic is similar to SharpHound file modifications, but this ins | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery || [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery || [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery || [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | +| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | +| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery || [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md b/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md index d71a32531e..ad72e49694 100644 --- a/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md +++ b/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md @@ -1,6 +1,6 @@ --- title: "Detect SharpHound Command-Line Arguments" -excerpt: "Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups" +excerpt: "Domain Account, Local Groups, Domain Trust Discovery, Local Account, Account Discovery, Domain Groups, Permission Groups Discovery" categories: - Endpoint last_modified_at: 2021-06-01 @@ -11,17 +11,23 @@ tags: - T1087.002 - Domain Account - Discovery - - T1087.001 - - Local Account + - T1069.001 + - Local Groups - Discovery - T1482 - Domain Trust Discovery - Discovery + - T1087.001 + - Local Account + - Discovery + - T1087 + - Account Discovery + - Discovery - T1069.002 - Domain Groups - Discovery - - T1069.001 - - Local Groups + - T1069 + - Permission Groups Discovery - Discovery - Splunk Enterprise - Splunk Enterprise Security @@ -50,8 +56,10 @@ The following analytic identifies common command-line arguments used by SharpHou | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery || [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | -| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery || [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery || [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | +| [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | +| [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery || [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md b/docs/_posts/2021-06-02-wbemprox_com_object_execution.md index b707c2a634..a3b667c064 100644 --- a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md +++ b/docs/_posts/2021-06-02-wbemprox_com_object_execution.md @@ -1,6 +1,6 @@ --- title: "Wbemprox COM Object Execution" -excerpt: "CMSTP" +excerpt: "Signed Binary Proxy Execution, CMSTP" categories: - Endpoint last_modified_at: 2021-06-02 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.003 - CMSTP - Defense Evasion @@ -38,6 +41,7 @@ this search is designed to detect potential malicious process loading COM object | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.003](https://attack.mitre.org/techniques/T1218/003/) | CMSTP | Defense Evasion | diff --git a/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md b/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md index 1a7f6abe4b..7b6317dee6 100644 --- a/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md +++ b/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md @@ -1,6 +1,6 @@ --- title: "Powershell Fileless Process Injection via GetProcAddress" -excerpt: "Process Injection, PowerShell" +excerpt: "Command and Scripting Interpreter, Process Injection, PowerShell" categories: - Endpoint last_modified_at: 2021-06-08 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1055 - Process Injection - Defense Evasion @@ -44,6 +47,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md b/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md index ff048dfbf9..8cdf811ccc 100644 --- a/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md +++ b/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md @@ -1,6 +1,6 @@ --- title: "Powershell Fileless Script Contains Base64 Encoded Content" -excerpt: "Obfuscated Files or Information, PowerShell" +excerpt: "Command and Scripting Interpreter, Obfuscated Files or Information, PowerShell" categories: - Endpoint last_modified_at: 2021-06-08 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1027 - Obfuscated Files or Information - Defense Evasion @@ -44,6 +47,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md b/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md index 2b314a5758..191d0a4c80 100644 --- a/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md +++ b/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md @@ -1,6 +1,6 @@ --- title: "Detect Empire with PowerShell Script Block Logging" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2021-06-09 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -39,6 +42,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md b/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md index 147e40dd41..e09bf881be 100644 --- a/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md +++ b/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md @@ -1,6 +1,6 @@ --- title: "Clear Unallocated Sector Using Cipher App" -excerpt: "File Deletion" +excerpt: "File Deletion, Indicator Removal on Host" categories: - Endpoint last_modified_at: 2021-06-10 @@ -11,6 +11,9 @@ tags: - T1070.004 - File Deletion - Defense Evasion + - T1070 + - Indicator Removal on Host + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ this search is to detect execution of `cipher.exe` to clear the unallocated sect | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | +| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion || [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md b/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md index 729771c1ce..72d8d7035e 100644 --- a/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md +++ b/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md @@ -1,6 +1,6 @@ --- title: "Disable Logs Using WevtUtil" -excerpt: "Clear Windows Event Logs" +excerpt: "Indicator Removal on Host, Clear Windows Event Logs" categories: - Endpoint last_modified_at: 2021-06-10 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1070 + - Indicator Removal on Host + - Defense Evasion - T1070.001 - Clear Windows Event Logs - Defense Evasion @@ -38,6 +41,7 @@ This search is to detect execution of wevtutil.exe to disable logs. This techniq | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | | [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | diff --git a/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md b/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md index 90f6e77b1c..54d17dea92 100644 --- a/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md +++ b/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md @@ -1,6 +1,6 @@ --- title: "Powershell Creating Thread Mutex" -excerpt: "Indicator Removal from Tools" +excerpt: "Obfuscated Files or Information, Indicator Removal from Tools" categories: - Endpoint last_modified_at: 2021-06-10 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1027 + - Obfuscated Files or Information + - Defense Evasion - T1027.005 - Indicator Removal from Tools - Defense Evasion @@ -37,6 +40,7 @@ The following analytic identifies suspicious PowerShell script execution via Eve | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | | [T1027.005](https://attack.mitre.org/techniques/T1027/005/) | Indicator Removal from Tools | Defense Evasion | diff --git a/docs/_posts/2021-06-10-powershell_domain_enumeration.md b/docs/_posts/2021-06-10-powershell_domain_enumeration.md index 6b21279b79..5d1f053f69 100644 --- a/docs/_posts/2021-06-10-powershell_domain_enumeration.md +++ b/docs/_posts/2021-06-10-powershell_domain_enumeration.md @@ -1,6 +1,6 @@ --- title: "PowerShell Domain Enumeration" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2021-06-10 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -39,6 +42,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md b/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md index 2bf2385c4e..3183721742 100644 --- a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md +++ b/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md @@ -1,6 +1,6 @@ --- title: "PowerShell Loading DotNET into Memory via System Reflection Assembly" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2021-06-10 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -39,6 +42,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md b/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md index 3f60968b29..6737a5b801 100644 --- a/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md +++ b/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md @@ -1,6 +1,6 @@ --- title: "Powershell Processing Stream Of Data" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2021-06-10 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -37,6 +40,7 @@ The following analytic identifies suspicious PowerShell script execution via Eve | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-06-10-start_up_during_safe_mode_boot.md b/docs/_posts/2021-06-10-start_up_during_safe_mode_boot.md index b860d78977..fe9e60545b 100644 --- a/docs/_posts/2021-06-10-start_up_during_safe_mode_boot.md +++ b/docs/_posts/2021-06-10-start_up_during_safe_mode_boot.md @@ -1,6 +1,6 @@ --- title: "Start Up During Safe Mode Boot" -excerpt: "Registry Run Keys / Startup Folder" +excerpt: "Registry Run Keys / Startup Folder, Boot or Logon Autostart Execution" categories: - Endpoint last_modified_at: 2021-06-10 @@ -12,6 +12,10 @@ tags: - Registry Run Keys / Startup Folder - Persistence - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This search is to detect a modification or registry add to the safeboot registry | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1547.001](https://attack.mitre.org/techniques/T1547/001/) | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation | +| [T1547.001](https://attack.mitre.org/techniques/T1547/001/) | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md b/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md index efed70ec90..7b85616c10 100644 --- a/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md +++ b/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md @@ -1,6 +1,6 @@ --- title: "WevtUtil Usage To Clear Logs" -excerpt: "Clear Windows Event Logs" +excerpt: "Indicator Removal on Host, Clear Windows Event Logs" categories: - Endpoint last_modified_at: 2021-06-15 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1070 + - Indicator Removal on Host + - Defense Evasion - T1070.001 - Clear Windows Event Logs - Defense Evasion @@ -36,6 +39,7 @@ The wevtutil.exe application is the windows event log utility. This searches for | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | | [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | diff --git a/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md b/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md index c34d070119..08c236fb18 100644 --- a/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md +++ b/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md @@ -1,6 +1,6 @@ --- title: "Wevtutil Usage To Disable Logs" -excerpt: "Clear Windows Event Logs" +excerpt: "Indicator Removal on Host, Clear Windows Event Logs" categories: - Endpoint last_modified_at: 2021-06-15 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1070 + - Indicator Removal on Host + - Defense Evasion - T1070.001 - Clear Windows Event Logs - Defense Evasion @@ -36,6 +39,7 @@ This search is to detect execution of wevtutil.exe to disable logs. This techniq | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | | [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | diff --git a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md b/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md index ced804b45a..8baacd1878 100644 --- a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md +++ b/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md @@ -1,6 +1,6 @@ --- title: "Detect WMI Event Subscription Persistence" -excerpt: "Windows Management Instrumentation Event Subscription" +excerpt: "Windows Management Instrumentation Event Subscription, Event Triggered Execution" categories: - Endpoint last_modified_at: 2021-06-16 @@ -12,6 +12,10 @@ tags: - Windows Management Instrumentation Event Subscription - Privilege Escalation - Persistence + - T1546 + - Event Triggered Execution + - Privilege Escalation + - Persistence - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -43,7 +47,8 @@ Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToCons | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1546.003](https://attack.mitre.org/techniques/T1546/003/) | Windows Management Instrumentation Event Subscription | Privilege Escalation, Persistence | +| [T1546.003](https://attack.mitre.org/techniques/T1546/003/) | Windows Management Instrumentation Event Subscription | Privilege Escalation, Persistence || [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | + #### Search diff --git a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md b/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md index 48fed249bd..d93bba7157 100644 --- a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md +++ b/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md @@ -1,6 +1,6 @@ --- title: "Suspicious Event Log Service Behavior" -excerpt: "Clear Windows Event Logs" +excerpt: "Indicator Removal on Host, Clear Windows Event Logs" categories: - Endpoint last_modified_at: 2021-06-17 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1070 + - Indicator Removal on Host + - Defense Evasion - T1070.001 - Clear Windows Event Logs - Defense Evasion @@ -37,6 +40,7 @@ The following analytic utilizes Windows Event ID 1100 to identify when Windows e | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | | [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | diff --git a/docs/_posts/2021-06-21-attacker_tools_on_endpoint.md b/docs/_posts/2021-06-21-attacker_tools_on_endpoint.md index 4da564bc85..40bff9c5d7 100644 --- a/docs/_posts/2021-06-21-attacker_tools_on_endpoint.md +++ b/docs/_posts/2021-06-21-attacker_tools_on_endpoint.md @@ -1,6 +1,6 @@ --- title: "Attacker Tools On Endpoint" -excerpt: "Match Legitimate Name or Location, Active Scanning, OS Credential Dumping" +excerpt: "Match Legitimate Name or Location, Masquerading, OS Credential Dumping, Active Scanning" categories: - Endpoint last_modified_at: 2021-06-21 @@ -11,12 +11,15 @@ tags: - T1036.005 - Match Legitimate Name or Location - Defense Evasion - - T1595 - - Active Scanning - - Reconnaissance + - T1036 + - Masquerading + - Defense Evasion - T1003 - OS Credential Dumping - Credential Access + - T1595 + - Active Scanning + - Reconnaissance - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -46,8 +49,9 @@ This search looks for execution of commonly used attacker tools on an endpoint. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1036.005](https://attack.mitre.org/techniques/T1036/005/) | Match Legitimate Name or Location | Defense Evasion || [T1595](https://attack.mitre.org/techniques/T1595/) | Active Scanning | Reconnaissance | +| [T1036.005](https://attack.mitre.org/techniques/T1036/005/) | Match Legitimate Name or Location | Defense Evasion || [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | +| [T1595](https://attack.mitre.org/techniques/T1595/) | Active Scanning | Reconnaissance | diff --git a/docs/_posts/2021-06-22-disable_amsi_through_registry.md b/docs/_posts/2021-06-22-disable_amsi_through_registry.md index cab9839222..dda843a77d 100644 --- a/docs/_posts/2021-06-22-disable_amsi_through_registry.md +++ b/docs/_posts/2021-06-22-disable_amsi_through_registry.md @@ -1,6 +1,6 @@ --- title: "Disable AMSI Through Registry" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-06-22 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ this search is to identify modification in registry to disable AMSI windows feat | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-06-22-disable_etw_through_registry.md b/docs/_posts/2021-06-22-disable_etw_through_registry.md index d043123630..2b7d656662 100644 --- a/docs/_posts/2021-06-22-disable_etw_through_registry.md +++ b/docs/_posts/2021-06-22-disable_etw_through_registry.md @@ -1,6 +1,6 @@ --- title: "Disable ETW Through Registry" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-06-22 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ this search is to identify modification in registry to disable ETW windows featu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md b/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md index 9fe88b96c8..a9b93f7d60 100644 --- a/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md +++ b/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md @@ -1,6 +1,6 @@ --- title: "Execute Javascript With Jscript COM CLSID" -excerpt: "Visual Basic" +excerpt: "Command and Scripting Interpreter, Visual Basic" categories: - Endpoint last_modified_at: 2021-06-22 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.005 - Visual Basic - Execution @@ -38,6 +41,7 @@ This analytic will identify suspicious process of cscript.exe where it tries to | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.005](https://attack.mitre.org/techniques/T1059/005/) | Visual Basic | Execution | diff --git a/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md b/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md index b28e216ca0..81b348e666 100644 --- a/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md +++ b/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md @@ -1,6 +1,6 @@ --- title: "Powershell Enable SMB1Protocol Feature" -excerpt: "Indicator Removal from Tools" +excerpt: "Obfuscated Files or Information, Indicator Removal from Tools" categories: - Endpoint last_modified_at: 2021-06-22 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1027 + - Obfuscated Files or Information + - Defense Evasion - T1027.005 - Indicator Removal from Tools - Defense Evasion @@ -38,6 +41,7 @@ This search is to detect a suspicious enabling of smb1protocol through "powe | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | | [T1027.005](https://attack.mitre.org/techniques/T1027/005/) | Indicator Removal from Tools | Defense Evasion | diff --git a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md b/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md index c717105ff9..beab5c68a8 100644 --- a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md +++ b/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md @@ -1,6 +1,6 @@ --- title: "Recursive Delete of Directory In Batch CMD" -excerpt: "File Deletion" +excerpt: "File Deletion, Indicator Removal on Host" categories: - Endpoint last_modified_at: 2021-06-22 @@ -11,6 +11,9 @@ tags: - T1070.004 - File Deletion - Defense Evasion + - T1070 + - Indicator Removal on Host + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect a suspicious commandline designed to delete files or di | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | +| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion || [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md b/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md index b8eaebe8d7..2f62e9086d 100644 --- a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md +++ b/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md @@ -1,6 +1,6 @@ --- title: "Allow File And Printing Sharing In Firewall" -excerpt: "Disable or Modify Cloud Firewall" +excerpt: "Disable or Modify Cloud Firewall, Impair Defenses" categories: - Endpoint last_modified_at: 2021-06-23 @@ -11,6 +11,9 @@ tags: - T1562.007 - Disable or Modify Cloud Firewall - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect a suspicious modification of firewall to allow file and | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | +| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md b/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md index 05262c1467..305de964c7 100644 --- a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md +++ b/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md @@ -1,6 +1,6 @@ --- title: "Allow Network Discovery In Firewall" -excerpt: "Disable or Modify Cloud Firewall" +excerpt: "Disable or Modify Cloud Firewall, Impair Defenses" categories: - Endpoint last_modified_at: 2021-06-23 @@ -11,6 +11,9 @@ tags: - T1562.007 - Disable or Modify Cloud Firewall - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect a suspicious modification to the firewall to allow netw | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | +| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md b/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md index 6a948faeb5..8a7cf4334c 100644 --- a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md +++ b/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md @@ -1,6 +1,6 @@ --- title: "Excessive Usage Of SC Service Utility" -excerpt: "Service Execution" +excerpt: "System Services, Service Execution" categories: - Endpoint last_modified_at: 2021-06-24 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Anomaly + - T1569 + - System Services + - Execution - T1569.002 - Service Execution - Execution @@ -38,6 +41,7 @@ This search is to detect a suspicious excessive usage of sc.exe in a host machin | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | | [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | diff --git a/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md b/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md index 84ee6013be..637f6256ad 100644 --- a/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md +++ b/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md @@ -1,6 +1,6 @@ --- title: "Excessive number of service control start as disabled" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-06-25 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This detection targets behaviors observed when threat actors have used sc.exe to | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md b/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md index dc6044b3cb..47703331ce 100644 --- a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md +++ b/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md @@ -1,6 +1,6 @@ --- title: "Print Spooler Adding A Printer Driver" -excerpt: "Print Processors" +excerpt: "Print Processors, Boot or Logon Autostart Execution" categories: - Endpoint last_modified_at: 2021-07-01 @@ -12,6 +12,10 @@ tags: - Print Processors - Persistence - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -41,7 +45,8 @@ During triage, isolate the endpoint and review for source of exploitation. Captu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | +| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md b/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md index 71a000e8e4..146a6fe96c 100644 --- a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md +++ b/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md @@ -1,6 +1,6 @@ --- title: "Print Spooler Failed to Load a Plug-in" -excerpt: "Print Processors" +excerpt: "Print Processors, Boot or Logon Autostart Execution" categories: - Endpoint last_modified_at: 2021-07-01 @@ -12,6 +12,10 @@ tags: - Print Processors - Persistence - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -42,7 +46,8 @@ During triage, isolate the endpoint and review for source of exploitation. Captu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | +| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-07-01-sdclt_uac_bypass.md b/docs/_posts/2021-07-01-sdclt_uac_bypass.md index 07ed7791a4..6db979d8a6 100644 --- a/docs/_posts/2021-07-01-sdclt_uac_bypass.md +++ b/docs/_posts/2021-07-01-sdclt_uac_bypass.md @@ -1,6 +1,6 @@ --- title: "Sdclt UAC Bypass" -excerpt: "Bypass User Account Control" +excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint last_modified_at: 2021-07-01 @@ -12,6 +12,10 @@ tags: - Bypass User Account Control - Privilege Escalation - Defense Evasion + - T1548 + - Abuse Elevation Control Mechanism + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This search is to detect a suspicious sdclt.exe registry modification. This tech | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | +| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion || [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2021-07-01-silentcleanup_uac_bypass.md b/docs/_posts/2021-07-01-silentcleanup_uac_bypass.md index d3b7d2e1e7..66b2eb1428 100644 --- a/docs/_posts/2021-07-01-silentcleanup_uac_bypass.md +++ b/docs/_posts/2021-07-01-silentcleanup_uac_bypass.md @@ -1,6 +1,6 @@ --- title: "SilentCleanup UAC Bypass" -excerpt: "Bypass User Account Control" +excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint last_modified_at: 2021-07-01 @@ -12,6 +12,10 @@ tags: - Bypass User Account Control - Privilege Escalation - Defense Evasion + - T1548 + - Abuse Elevation Control Mechanism + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This search is to detect a suspicious modification of registry that may related | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | +| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion || [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md b/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md index da293dfadc..b8fa3af688 100644 --- a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md +++ b/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md @@ -1,6 +1,6 @@ --- title: "Spoolsv Spawning Rundll32" -excerpt: "Print Processors" +excerpt: "Print Processors, Boot or Logon Autostart Execution" categories: - Endpoint last_modified_at: 2021-07-01 @@ -12,6 +12,10 @@ tags: - Print Processors - Persistence - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ The following analytic identifies a suspicious child process, `rundll32.exe`, wi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | +| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md b/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md index 0d14ec3e0c..c7d4bf1244 100644 --- a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md +++ b/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md @@ -1,6 +1,6 @@ --- title: "Spoolsv Suspicious Loaded Modules" -excerpt: "Print Processors" +excerpt: "Print Processors, Boot or Logon Autostart Execution" categories: - Endpoint last_modified_at: 2021-07-01 @@ -12,6 +12,10 @@ tags: - Print Processors - Persistence - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This search is to detect suspicious loading of dll in specific path relative to | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | +| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md b/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md index f5fa863333..b5d6ba38ca 100644 --- a/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md +++ b/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md @@ -1,6 +1,6 @@ --- title: "Spoolsv Writing a DLL" -excerpt: "Print Processors" +excerpt: "Print Processors, Boot or Logon Autostart Execution" categories: - Endpoint last_modified_at: 2021-07-01 @@ -12,6 +12,10 @@ tags: - Print Processors - Persistence - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ The following analytic identifies a `.dll` being written by `spoolsv.exe`. This | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | +| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md b/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md index 2101932568..7ededbc7ac 100644 --- a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md +++ b/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md @@ -1,6 +1,6 @@ --- title: "Spoolsv Writing a DLL - Sysmon" -excerpt: "Print Processors" +excerpt: "Print Processors, Boot or Logon Autostart Execution" categories: - Endpoint last_modified_at: 2021-07-01 @@ -12,6 +12,10 @@ tags: - Print Processors - Persistence - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ The following analytic identifies a `.dll` being written by `spoolsv.exe`. This | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | +| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + #### Search diff --git a/docs/_posts/2021-07-01-wsreset_uac_bypass.md b/docs/_posts/2021-07-01-wsreset_uac_bypass.md index f8695fb529..3758b493e0 100644 --- a/docs/_posts/2021-07-01-wsreset_uac_bypass.md +++ b/docs/_posts/2021-07-01-wsreset_uac_bypass.md @@ -1,6 +1,6 @@ --- title: "WSReset UAC Bypass" -excerpt: "Bypass User Account Control" +excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint last_modified_at: 2021-07-01 @@ -12,6 +12,10 @@ tags: - Bypass User Account Control - Privilege Escalation - Defense Evasion + - T1548 + - Abuse Elevation Control Mechanism + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This search is to detect a suspicious modification of registry related to UAC by | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | +| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion || [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md b/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md index 04ff2f179e..74a6464eab 100644 --- a/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md +++ b/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md @@ -1,6 +1,6 @@ --- title: "Msmpeng Application DLL Side Loading" -excerpt: "DLL Side-Loading" +excerpt: "DLL Side-Loading, Hijack Execution Flow" categories: - Endpoint last_modified_at: 2021-07-05 @@ -13,6 +13,11 @@ tags: - Persistence - Privilege Escalation - Defense Evasion + - T1574 + - Hijack Execution Flow + - Persistence + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -40,7 +45,8 @@ This search is to detect a suspicious creation of msmpeng.exe or mpsvc.dll in no | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1574.002](https://attack.mitre.org/techniques/T1574/002/) | DLL Side-Loading | Persistence, Privilege Escalation, Defense Evasion | +| [T1574.002](https://attack.mitre.org/techniques/T1574/002/) | DLL Side-Loading | Persistence, Privilege Escalation, Defense Evasion || [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Persistence, Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md b/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md index df03495eb4..5931016dfb 100644 --- a/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md +++ b/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md @@ -1,6 +1,6 @@ --- title: "Powershell Disable Security Monitoring" -excerpt: "Disable or Modify Tools" +excerpt: "Disable or Modify Tools, Impair Defenses" categories: - Endpoint last_modified_at: 2021-07-05 @@ -11,6 +11,9 @@ tags: - T1562.001 - Disable or Modify Tools - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to identifies a modification in registry to disable the windows d | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | +| [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-07-12-net_profiler_uac_bypass.md b/docs/_posts/2021-07-12-net_profiler_uac_bypass.md index 63d0ace49f..d6eb5a707f 100644 --- a/docs/_posts/2021-07-12-net_profiler_uac_bypass.md +++ b/docs/_posts/2021-07-12-net_profiler_uac_bypass.md @@ -1,6 +1,6 @@ --- title: "NET Profiler UAC bypass" -excerpt: "Bypass User Account Control" +excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint last_modified_at: 2021-07-12 @@ -12,6 +12,10 @@ tags: - Bypass User Account Control - Privilege Escalation - Defense Evasion + - T1548 + - Abuse Elevation Control Mechanism + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This search is to detect modification of registry to bypass UAC windows feature. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | +| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion || [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md b/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md index 4f0fc6fd35..e3cbb3e57e 100644 --- a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md +++ b/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md @@ -1,6 +1,6 @@ --- title: "UAC Bypass MMC Load Unsigned Dll" -excerpt: "Bypass User Account Control" +excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" categories: - Endpoint last_modified_at: 2021-07-12 @@ -12,6 +12,10 @@ tags: - Bypass User Account Control - Privilege Escalation - Defense Evasion + - T1548 + - Abuse Elevation Control Mechanism + - Privilege Escalation + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This search is to detect a suspicious loaded unsigned dll by MMC.exe application | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | +| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion || [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | + #### Search diff --git a/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md b/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md index b8859f83c1..323a29b108 100644 --- a/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md +++ b/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md @@ -1,6 +1,6 @@ --- title: "Cloud Compute Instance Created By Previously Unseen User" -excerpt: "Cloud Accounts" +excerpt: "Cloud Accounts, Valid Accounts" categories: - Cloud last_modified_at: 2021-07-13 @@ -14,6 +14,12 @@ tags: - Persistence - Privilege Escalation - Initial Access + - T1078 + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -41,7 +47,8 @@ This search looks for cloud compute instances created by users who have not crea | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | +| [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access || [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + #### Search diff --git a/docs/_posts/2021-07-19-aws_createaccesskey.md b/docs/_posts/2021-07-19-aws_createaccesskey.md index 0f03e49a55..21b3ee486d 100644 --- a/docs/_posts/2021-07-19-aws_createaccesskey.md +++ b/docs/_posts/2021-07-19-aws_createaccesskey.md @@ -1,6 +1,6 @@ --- title: "AWS CreateAccessKey" -excerpt: "Cloud Account" +excerpt: "Cloud Account, Create Account" categories: - Cloud last_modified_at: 2021-07-19 @@ -11,6 +11,9 @@ tags: - T1136.003 - Cloud Account - Persistence + - T1136 + - Create Account + - Persistence - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ This search looks for AWS CloudTrail events where a user A who has already permi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | +| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence || [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | + #### Search diff --git a/docs/_posts/2021-07-19-aws_createloginprofile.md b/docs/_posts/2021-07-19-aws_createloginprofile.md index c7bf324555..c3f8ef3d22 100644 --- a/docs/_posts/2021-07-19-aws_createloginprofile.md +++ b/docs/_posts/2021-07-19-aws_createloginprofile.md @@ -1,6 +1,6 @@ --- title: "AWS CreateLoginProfile" -excerpt: "Cloud Account" +excerpt: "Cloud Account, Create Account" categories: - Cloud last_modified_at: 2021-07-19 @@ -11,6 +11,9 @@ tags: - T1136.003 - Cloud Account - Persistence + - T1136 + - Create Account + - Persistence - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ This search looks for AWS CloudTrail events where a user A(victim A) creates a l | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | +| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence || [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | + #### Search diff --git a/docs/_posts/2021-07-19-aws_updateloginprofile.md b/docs/_posts/2021-07-19-aws_updateloginprofile.md index a3b4b0d9e1..7242f994dc 100644 --- a/docs/_posts/2021-07-19-aws_updateloginprofile.md +++ b/docs/_posts/2021-07-19-aws_updateloginprofile.md @@ -1,6 +1,6 @@ --- title: "AWS UpdateLoginProfile" -excerpt: "Cloud Account" +excerpt: "Cloud Account, Create Account" categories: - Cloud last_modified_at: 2021-07-19 @@ -11,6 +11,9 @@ tags: - T1136.003 - Cloud Account - Persistence + - T1136 + - Create Account + - Persistence - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ This search looks for AWS CloudTrail events where a user A who has already permi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | +| [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence || [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | + #### Search diff --git a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md index 3f2c99e795..7db4e4c52a 100644 --- a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md +++ b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md @@ -1,6 +1,6 @@ --- title: "Mshta spawning Rundll32 OR Regsvr32 Process" -excerpt: "Mshta" +excerpt: "Signed Binary Proxy Execution, Mshta" categories: - Endpoint last_modified_at: 2021-07-19 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.005 - Mshta - Defense Evasion @@ -38,6 +41,7 @@ This search is to detect a suspicious mshta.exe process that spawn rundll32 or r | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | diff --git a/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md b/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md index 7b8da829c6..a4e748c2d7 100644 --- a/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md +++ b/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md @@ -1,6 +1,6 @@ --- title: "O365 Bypass MFA via Trusted IP" -excerpt: "Disable or Modify Cloud Firewall" +excerpt: "Disable or Modify Cloud Firewall, Impair Defenses" categories: - Cloud last_modified_at: 2021-07-19 @@ -11,6 +11,9 @@ tags: - T1562.007 - Disable or Modify Cloud Firewall - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Security Analytics for AWS - Splunk Enterprise - Splunk Enterprise Security @@ -38,7 +41,8 @@ This search detects newly added IP addresses/CIDR blocks to the list of MFA Trus | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | +| [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md b/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md index 8842e242a3..f8b4e39eaf 100644 --- a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md +++ b/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md @@ -1,6 +1,6 @@ --- title: "Office Product Spawn CMD Process" -excerpt: "Mshta" +excerpt: "Signed Binary Proxy Execution, Mshta" categories: - Endpoint last_modified_at: 2021-07-19 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.005 - Mshta - Defense Evasion @@ -38,6 +41,7 @@ this search is to detect a suspicious office product process that spawn cmd chil | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | diff --git a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md b/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md index d5d936ed38..840712a14f 100644 --- a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md +++ b/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md @@ -1,6 +1,6 @@ --- title: "Detect Copy of ShadowCopy with Script Block Logging" -excerpt: "Security Account Manager" +excerpt: "Security Account Manager, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-07-21 @@ -11,6 +11,9 @@ tags: - T1003.002 - Security Account Manager - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +42,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | +| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-07-23-sam_database_file_access_attempt.md b/docs/_posts/2021-07-23-sam_database_file_access_attempt.md index fa08150c7b..dae939c453 100644 --- a/docs/_posts/2021-07-23-sam_database_file_access_attempt.md +++ b/docs/_posts/2021-07-23-sam_database_file_access_attempt.md @@ -1,6 +1,6 @@ --- title: "SAM Database File Access Attempt" -excerpt: "Security Account Manager" +excerpt: "Security Account Manager, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-07-23 @@ -11,6 +11,9 @@ tags: - T1003.002 - Security Account Manager - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following analytic identifies access to SAM, SYSTEM or SECURITY databases | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | +| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-07-26-rundll32_dnsquery.md b/docs/_posts/2021-07-26-rundll32_dnsquery.md index 6ff9d542e1..b27867485e 100644 --- a/docs/_posts/2021-07-26-rundll32_dnsquery.md +++ b/docs/_posts/2021-07-26-rundll32_dnsquery.md @@ -1,6 +1,6 @@ --- title: "Rundll32 DNSQuery" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-07-26 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ This search is to detect a suspicious rundll32.exe process having a http connect | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md b/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md index 69407547e0..24cf1545ac 100644 --- a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md +++ b/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md @@ -1,6 +1,6 @@ --- title: "Rundll32 Process Creating Exe Dll Files" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-07-26 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ This search is to detect a suspicious rundll32 process that drops executable (.e | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md b/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md index c6ee931414..d019086756 100644 --- a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md +++ b/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md @@ -1,6 +1,6 @@ --- title: "Suspicious IcedID Rundll32 Cmdline" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-07-26 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ This search is to detect a suspicious rundll32.exe commandline to execute dll fi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md b/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md index 0ccdb4c52d..f32aa8f8b7 100644 --- a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md +++ b/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md @@ -1,6 +1,6 @@ --- title: "Suspicious Rundll32 PluginInit" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-07-26 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ This search is to detect a suspicious rundll32.exe process with plugininit param | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-07-27-suspicious_icedid_regsvr32_cmdline.md b/docs/_posts/2021-07-27-suspicious_icedid_regsvr32_cmdline.md index bb5b7dd6cf..cff5d1ed82 100644 --- a/docs/_posts/2021-07-27-suspicious_icedid_regsvr32_cmdline.md +++ b/docs/_posts/2021-07-27-suspicious_icedid_regsvr32_cmdline.md @@ -1,6 +1,6 @@ --- title: "Suspicious IcedID Regsvr32 Cmdline" -excerpt: "Regsvr32" +excerpt: "Signed Binary Proxy Execution, Regsvr32" categories: - Endpoint last_modified_at: 2021-07-27 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.010 - Regsvr32 - Defense Evasion @@ -38,6 +41,7 @@ this search is to detect a suspicious regsvr32 commandline "-s" to execu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | diff --git a/docs/_posts/2021-07-30-drop_icedid_license_dat.md b/docs/_posts/2021-07-30-drop_icedid_license_dat.md index c9e4642fc3..a6c16569c3 100644 --- a/docs/_posts/2021-07-30-drop_icedid_license_dat.md +++ b/docs/_posts/2021-07-30-drop_icedid_license_dat.md @@ -1,6 +1,6 @@ --- title: "Drop IcedID License dat" -excerpt: "Malicious File" +excerpt: "User Execution, Malicious File" categories: - Endpoint last_modified_at: 2021-07-30 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1204 + - User Execution + - Execution - T1204.002 - Malicious File - Execution @@ -38,6 +41,7 @@ This search is to detect dropping a suspicious file named as "license.dat | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | | [T1204.002](https://attack.mitre.org/techniques/T1204/002/) | Malicious File | Execution | diff --git a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md b/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md index eeb3675e0c..91c2a481b6 100644 --- a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md +++ b/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md @@ -1,6 +1,6 @@ --- title: "IcedID Exfiltrated Archived File Creation" -excerpt: "Archive via Utility" +excerpt: "Archive via Utility, Archive Collected Data" categories: - Endpoint last_modified_at: 2021-07-30 @@ -11,6 +11,9 @@ tags: - T1560.001 - Archive via Utility - Collection + - T1560 + - Archive Collected Data + - Collection - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect a suspicious file creation namely passff.tar and cookie | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | +| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection || [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | + #### Search diff --git a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md b/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md index 2b3a6eb92a..038b925800 100644 --- a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md +++ b/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md @@ -1,6 +1,6 @@ --- title: "Office Application Spawn Regsvr32 process" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-07-30 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ this detection was designed to identifies suspicious spawned process of known MS | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md b/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md index d16b9ce54a..642bfb9f14 100644 --- a/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md +++ b/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md @@ -1,6 +1,6 @@ --- title: "Uninstall App Using MsiExec" -excerpt: "Msiexec" +excerpt: "Msiexec, Signed Binary Proxy Execution" categories: - Endpoint last_modified_at: 2021-08-09 @@ -11,6 +11,9 @@ tags: - T1218.007 - Msiexec - Defense Evasion + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect a suspicious un-installation of application using msiex | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1218.007](https://attack.mitre.org/techniques/T1218/007/) | Msiexec | Defense Evasion | +| [T1218.007](https://attack.mitre.org/techniques/T1218/007/) | Msiexec | Defense Evasion || [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-08-10-powershell_execute_com_object.md b/docs/_posts/2021-08-10-powershell_execute_com_object.md index 03e85b4933..4a75f62b99 100644 --- a/docs/_posts/2021-08-10-powershell_execute_com_object.md +++ b/docs/_posts/2021-08-10-powershell_execute_com_object.md @@ -1,6 +1,6 @@ --- title: "Powershell Execute COM Object" -excerpt: "Component Object Model Hijacking" +excerpt: "Component Object Model Hijacking, Event Triggered Execution" categories: - Endpoint last_modified_at: 2021-08-10 @@ -12,6 +12,10 @@ tags: - Component Object Model Hijacking - Privilege Escalation - Persistence + - T1546 + - Event Triggered Execution + - Privilege Escalation + - Persistence - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +43,8 @@ This search is to detect a COM CLSID execution through powershell. This techniqu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1546.015](https://attack.mitre.org/techniques/T1546/015/) | Component Object Model Hijacking | Privilege Escalation, Persistence | +| [T1546.015](https://attack.mitre.org/techniques/T1546/015/) | Component Object Model Hijacking | Privilege Escalation, Persistence || [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | + #### Search diff --git a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md b/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md index c0cc1c4199..4a6ac6b2e4 100644 --- a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md +++ b/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md @@ -1,6 +1,6 @@ --- title: "UAC Bypass With Colorui COM Object" -excerpt: "CMSTP" +excerpt: "Signed Binary Proxy Execution, CMSTP" categories: - Endpoint last_modified_at: 2021-08-13 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.003 - CMSTP - Defense Evasion @@ -38,6 +41,7 @@ This search is to detect a possible uac bypass using the colorui.dll COM Object. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.003](https://attack.mitre.org/techniques/T1218/003/) | CMSTP | Defense Evasion | diff --git a/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md b/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md index afe54bd61a..39167a2d96 100644 --- a/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md +++ b/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md @@ -1,6 +1,6 @@ --- title: "Gsuite Drive Share In External Email" -excerpt: "Exfiltration to Cloud Storage" +excerpt: "Exfiltration to Cloud Storage, Exfiltration Over Web Service" categories: - Cloud last_modified_at: 2021-08-16 @@ -11,6 +11,9 @@ tags: - T1567.002 - Exfiltration to Cloud Storage - Exfiltration + - T1567 + - Exfiltration Over Web Service + - Exfiltration - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect suspicious google drive or google docs files shared out | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1567.002](https://attack.mitre.org/techniques/T1567/002/) | Exfiltration to Cloud Storage | Exfiltration | +| [T1567.002](https://attack.mitre.org/techniques/T1567/002/) | Exfiltration to Cloud Storage | Exfiltration || [T1567](https://attack.mitre.org/techniques/T1567/) | Exfiltration Over Web Service | Exfiltration | + #### Search @@ -58,11 +62,11 @@ This search is to detect suspicious google drive or google docs files shared out ``` #### Associated Analytic Story -* [DevSecOps](/stories/devsecops) +* [Dev Sec Ops](/stories/dev_sec_ops) #### How To Implement -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. +To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. In order for the search to work for your environment, please edit the query to use your company specific email domain instead of `internal_test_email.com`. #### Required field * _time diff --git a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md b/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md index 88c90cb58b..9e5df0f5f2 100644 --- a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md +++ b/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md @@ -1,6 +1,6 @@ --- title: "GSuite Email Suspicious Attachment" -excerpt: "Spearphishing Attachment" +excerpt: "Spearphishing Attachment, Phishing" categories: - Cloud last_modified_at: 2021-08-16 @@ -11,6 +11,9 @@ tags: - T1566.001 - Spearphishing Attachment - Initial Access + - T1566 + - Phishing + - Initial Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect a suspicious attachment file extension in Gsuite email | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | +| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access || [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | + #### Search @@ -54,7 +58,7 @@ This search is to detect a suspicious attachment file extension in Gsuite email ``` #### Associated Analytic Story -* [DevSecOps](/stories/devsecops) +* [Dev Sec Ops](/stories/dev_sec_ops) #### How To Implement diff --git a/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md b/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md index cb7e2ec3bb..4d2e189f9a 100644 --- a/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md +++ b/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md @@ -1,6 +1,6 @@ --- title: "7zip CommandLine To SMB Share Path" -excerpt: "Archive via Utility" +excerpt: "Archive via Utility, Archive Collected Data" categories: - Endpoint last_modified_at: 2021-08-17 @@ -11,6 +11,9 @@ tags: - T1560.001 - Archive via Utility - Collection + - T1560 + - Archive Collected Data + - Collection - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect a suspicious 7z process with commandline pointing to SM | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | +| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection || [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | + #### Search diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md index 6cf02a210a..bc7107cd95 100644 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md +++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md @@ -1,6 +1,6 @@ --- title: "AWS ECR Container Scanning Findings High" -excerpt: "Malicious Image" +excerpt: "Malicious Image, User Execution" categories: - Cloud last_modified_at: 2021-08-17 @@ -11,6 +11,9 @@ tags: - T1204.003 - Malicious Image - Execution + - T1204 + - User Execution + - Execution - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | +| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution || [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | + #### Search diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md index bbc82e334f..7a5e6508f3 100644 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md +++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md @@ -1,6 +1,6 @@ --- title: "AWS ECR Container Scanning Findings Low Informational Unknown" -excerpt: "Malicious Image" +excerpt: "Malicious Image, User Execution" categories: - Cloud last_modified_at: 2021-08-17 @@ -11,6 +11,9 @@ tags: - T1204.003 - Malicious Image - Execution + - T1204 + - User Execution + - Execution - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | +| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution || [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | + #### Search diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md index db241c2718..3d52d59f0e 100644 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md +++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md @@ -1,6 +1,6 @@ --- title: "AWS ECR Container Scanning Findings Medium" -excerpt: "Malicious Image" +excerpt: "Malicious Image, User Execution" categories: - Cloud last_modified_at: 2021-08-17 @@ -11,6 +11,9 @@ tags: - T1204.003 - Malicious Image - Execution + - T1204 + - User Execution + - Execution - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | +| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution || [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | + #### Search diff --git a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md b/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md index c4d335254f..899edae724 100644 --- a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md +++ b/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md @@ -1,6 +1,6 @@ --- title: "Gsuite Outbound Email With Attachment To External Domain" -excerpt: "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol" +excerpt: "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, Exfiltration Over Alternative Protocol" categories: - Cloud last_modified_at: 2021-08-17 @@ -11,6 +11,9 @@ tags: - T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol - Exfiltration + - T1048 + - Exfiltration Over Alternative Protocol + - Exfiltration - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect a suspicious outbound e-mail from internal email to ext | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | +| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration || [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | + #### Search @@ -59,7 +63,7 @@ This search is to detect a suspicious outbound e-mail from internal email to ext ``` #### Associated Analytic Story -* [DevSecOps](/stories/devsecops) +* [Dev Sec Ops](/stories/dev_sec_ops) #### How To Implement diff --git a/docs/_posts/2021-08-18-esentutl_sam_copy.md b/docs/_posts/2021-08-18-esentutl_sam_copy.md index 2a224f4adf..a1c7d32d67 100644 --- a/docs/_posts/2021-08-18-esentutl_sam_copy.md +++ b/docs/_posts/2021-08-18-esentutl_sam_copy.md @@ -1,6 +1,6 @@ --- title: "Esentutl SAM Copy" -excerpt: "Security Account Manager" +excerpt: "Security Account Manager, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-08-18 @@ -11,6 +11,9 @@ tags: - T1003.002 - Security Account Manager - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +42,8 @@ The following analytic identifies the process - `esentutl.exe` - being used to c | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | +| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-08-18-powershell_4104_hunting.md b/docs/_posts/2021-08-18-powershell_4104_hunting.md index 01acaecee0..f520eedf6f 100644 --- a/docs/_posts/2021-08-18-powershell_4104_hunting.md +++ b/docs/_posts/2021-08-18-powershell_4104_hunting.md @@ -1,6 +1,6 @@ --- title: "PowerShell 4104 Hunting" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2021-08-18 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -37,6 +40,7 @@ The following Hunting analytic assists with identifying suspicious PowerShell ex | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md index 25df3e4ad1..1092fafc4f 100644 --- a/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md +++ b/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md @@ -1,6 +1,6 @@ --- title: "AWS ECR Container Upload Outside Business Hours" -excerpt: "Malicious Image" +excerpt: "Malicious Image, User Execution" categories: - Cloud last_modified_at: 2021-08-19 @@ -11,6 +11,9 @@ tags: - T1204.003 - Malicious Image - Execution + - T1204 + - User Execution + - Execution - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | +| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution || [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | + #### Search diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md index 85015fc4b3..3d84329a9b 100644 --- a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md +++ b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md @@ -1,6 +1,6 @@ --- title: "AWS ECR Container Upload Unknown User" -excerpt: "Malicious Image" +excerpt: "Malicious Image, User Execution" categories: - Cloud last_modified_at: 2021-08-19 @@ -11,6 +11,9 @@ tags: - T1204.003 - Malicious Image - Execution + - T1204 + - User Execution + - Execution - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | +| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution || [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | + #### Search diff --git a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md b/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md index 59fe798d36..9835150430 100644 --- a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md +++ b/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md @@ -1,6 +1,6 @@ --- title: "Gsuite Email Suspicious Subject With Attachment" -excerpt: "Spearphishing Attachment" +excerpt: "Spearphishing Attachment, Phishing" categories: - Cloud last_modified_at: 2021-08-19 @@ -11,6 +11,9 @@ tags: - T1566.001 - Spearphishing Attachment - Initial Access + - T1566 + - Phishing + - Initial Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect a gsuite email contains suspicious subject having known | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | +| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access || [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | + #### Search @@ -57,7 +61,7 @@ This search is to detect a gsuite email contains suspicious subject having known ``` #### Associated Analytic Story -* [DevSecOps](/stories/devsecops) +* [Dev Sec Ops](/stories/dev_sec_ops) #### How To Implement diff --git a/docs/_posts/2021-08-20-github_commit_changes_in_master.md b/docs/_posts/2021-08-20-github_commit_changes_in_master.md index 9a3008715c..f38f6fb8a8 100644 --- a/docs/_posts/2021-08-20-github_commit_changes_in_master.md +++ b/docs/_posts/2021-08-20-github_commit_changes_in_master.md @@ -56,7 +56,7 @@ This search is to detect a pushed or commit to master or main branch. This is to ``` #### Associated Analytic Story -* [DevSecOps](/stories/devsecops) +* [Dev Sec Ops](/stories/dev_sec_ops) #### How To Implement diff --git a/docs/_posts/2021-08-23-getlocaluser_with_powershell.md b/docs/_posts/2021-08-23-getlocaluser_with_powershell.md index eed0d2fc11..c4a44069ab 100644 --- a/docs/_posts/2021-08-23-getlocaluser_with_powershell.md +++ b/docs/_posts/2021-08-23-getlocaluser_with_powershell.md @@ -1,6 +1,6 @@ --- title: "GetLocalUser with PowerShell" -excerpt: "Local Account" +excerpt: "Account Discovery, Local Account" categories: - Endpoint last_modified_at: 2021-08-23 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1087 + - Account Discovery + - Discovery - T1087.001 - Local Account - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | diff --git a/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md b/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md index 0f2ff9d6b9..0d68714a03 100644 --- a/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md +++ b/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md @@ -1,6 +1,6 @@ --- title: "GetLocalUser with PowerShell Script Block" -excerpt: "Local Account" +excerpt: "Account Discovery, Local Account" categories: - Endpoint last_modified_at: 2021-08-23 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1087 + - Account Discovery + - Discovery - T1087.001 - Local Account - Discovery @@ -38,6 +41,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | diff --git a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md index 9e78db3a6a..4025992bb6 100644 --- a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md +++ b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md @@ -1,6 +1,6 @@ --- title: "GetWmiObject User Account with PowerShell" -excerpt: "Local Account" +excerpt: "Account Discovery, Local Account" categories: - Endpoint last_modified_at: 2021-08-23 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1087 + - Account Discovery + - Discovery - T1087.001 - Local Account - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | diff --git a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md index 915829d14d..e9197fabbc 100644 --- a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md +++ b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md @@ -1,6 +1,6 @@ --- title: "GetWmiObject User Account with PowerShell Script Block" -excerpt: "Local Account" +excerpt: "Account Discovery, Local Account" categories: - Endpoint last_modified_at: 2021-08-23 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1087 + - Account Discovery + - Discovery - T1087.001 - Local Account - Discovery @@ -38,6 +41,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | diff --git a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md b/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md index 6d4bd01d15..b76321e3c3 100644 --- a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md +++ b/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md @@ -1,6 +1,6 @@ --- title: "Gsuite Email With Known Abuse Web Service Link" -excerpt: "Spearphishing Attachment" +excerpt: "Spearphishing Attachment, Phishing" categories: - Cloud last_modified_at: 2021-08-23 @@ -11,6 +11,9 @@ tags: - T1566.001 - Spearphishing Attachment - Initial Access + - T1566 + - Phishing + - Initial Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytics is to detect a gmail containing a link that are known to be abuse | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | +| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access || [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | + #### Search @@ -57,7 +61,7 @@ This analytics is to detect a gmail containing a link that are known to be abuse ``` #### Associated Analytic Story -* [DevSecOps](/stories/devsecops) +* [Dev Sec Ops](/stories/dev_sec_ops) #### How To Implement diff --git a/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md b/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md index 4098eb80bb..557b4bd6cc 100644 --- a/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md +++ b/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md @@ -1,6 +1,6 @@ --- title: "Gsuite Suspicious Shared File Name" -excerpt: "Spearphishing Attachment" +excerpt: "Spearphishing Attachment, Phishing" categories: - Cloud last_modified_at: 2021-08-23 @@ -11,6 +11,9 @@ tags: - T1566.001 - Spearphishing Attachment - Initial Access + - T1566 + - Phishing + - Initial Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search is to detect a shared file in google drive with suspicious file name | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | +| [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access || [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | + #### Search @@ -58,11 +62,11 @@ This search is to detect a shared file in google drive with suspicious file name ``` #### Associated Analytic Story -* [DevSecOps](/stories/devsecops) +* [Dev Sec Ops](/stories/dev_sec_ops) #### How To Implement -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. +To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. In order for the search to work for your environment, please edit the query to use your company specific email domain instead of `internal_test_email.com`. #### Required field * _time diff --git a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md b/docs/_posts/2021-08-24-adsisearcher_account_discovery.md index 113597705a..f67e522119 100644 --- a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md +++ b/docs/_posts/2021-08-24-adsisearcher_account_discovery.md @@ -1,6 +1,6 @@ --- title: "AdsiSearcher Account Discovery" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-08-24 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md b/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md index 90275f24bf..2b40251fba 100644 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md +++ b/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md @@ -1,6 +1,6 @@ --- title: "Domain Account Discovery with Dsquery" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-08-24 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic looks for the execution of `dsquery.exe` with command-line argumen | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md b/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md index 65583237ad..a3c7afe505 100644 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md +++ b/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md @@ -1,6 +1,6 @@ --- title: "Domain Account Discovery With Net App" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-08-24 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command-li | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md b/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md index b27f2d5725..7c026af395 100644 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md +++ b/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md @@ -1,6 +1,6 @@ --- title: "Domain Account Discovery with Wmic" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-08-24 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-08-24-get_aduser_with_powershell.md b/docs/_posts/2021-08-24-get_aduser_with_powershell.md index 599f00a72b..4763ad2451 100644 --- a/docs/_posts/2021-08-24-get_aduser_with_powershell.md +++ b/docs/_posts/2021-08-24-get_aduser_with_powershell.md @@ -1,6 +1,6 @@ --- title: "Get ADUser with PowerShell" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-08-24 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic looks for the execution of `powershell.exe` with command-line argu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md b/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md index c189cc6d04..6fc5d8148f 100644 --- a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md @@ -1,6 +1,6 @@ --- title: "Get ADUser with PowerShell Script Block" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-08-24 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-08-24-get_domainuser_with_powershell.md b/docs/_posts/2021-08-24-get_domainuser_with_powershell.md index 9e90b67d91..0ea337b37e 100644 --- a/docs/_posts/2021-08-24-get_domainuser_with_powershell.md +++ b/docs/_posts/2021-08-24-get_domainuser_with_powershell.md @@ -1,6 +1,6 @@ --- title: "Get DomainUser with PowerShell" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-08-24 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic looks for the execution of `powershell.exe` with command-line argu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md b/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md index a0f8b7e199..720008903e 100644 --- a/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md @@ -1,6 +1,6 @@ --- title: "Get DomainUser with PowerShell Script Block" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-08-24 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md index f16c96080d..347d64458b 100644 --- a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md +++ b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md @@ -1,6 +1,6 @@ --- title: "GetWmiObject DS User with PowerShell" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-08-24 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic looks for the execution of `powershell.exe` with command-line argu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md index bcd37bd048..cdf0e72ef2 100644 --- a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md @@ -1,6 +1,6 @@ --- title: "GetWmiObject DS User with PowerShell Script Block" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-08-24 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md b/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md index 60269c375c..b5636e3f7d 100644 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md +++ b/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md @@ -1,6 +1,6 @@ --- title: "Domain Group Discovery with Adsisearcher" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-25 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_net.md b/docs/_posts/2021-08-25-domain_group_discovery_with_net.md index 35760654b0..255f8d1b56 100644 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_net.md +++ b/docs/_posts/2021-08-25-domain_group_discovery_with_net.md @@ -1,6 +1,6 @@ --- title: "Domain Group Discovery With Net" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-25 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `net.exe` with command-line arguments u | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md b/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md index 02d98a6413..837d36d100 100644 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md +++ b/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md @@ -1,6 +1,6 @@ --- title: "Domain Group Discovery With Wmic" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-25 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md index 8895a3addb..560506e438 100644 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md +++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md @@ -1,6 +1,6 @@ --- title: "Elevated Group Discovery With Net" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-25 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command-l | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md index c924ff245e..1afe429f3e 100644 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md +++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md @@ -1,6 +1,6 @@ --- title: "Elevated Group Discovery with PowerView" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-25 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md index 89d13a53fa..f5782e2654 100644 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md +++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md @@ -1,6 +1,6 @@ --- title: "Elevated Group Discovery With Wmic" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-25 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-25-getadgroup_with_powershell.md b/docs/_posts/2021-08-25-getadgroup_with_powershell.md index 94ea59455b..786f4c0c3d 100644 --- a/docs/_posts/2021-08-25-getadgroup_with_powershell.md +++ b/docs/_posts/2021-08-25-getadgroup_with_powershell.md @@ -1,6 +1,6 @@ --- title: "GetAdGroup with PowerShell" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-25 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md b/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md index c6028b8c4d..23c971bdbe 100644 --- a/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md +++ b/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md @@ -1,6 +1,6 @@ --- title: "GetAdGroup with PowerShell Script Block" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-25 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md b/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md index 0a7469125f..7b91c7fab9 100644 --- a/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md +++ b/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md @@ -1,6 +1,6 @@ --- title: "GetDomainGroup with PowerShell" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-25 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md index 26ad5c0f55..78fa6089a0 100644 --- a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md +++ b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md @@ -1,6 +1,6 @@ --- title: "GetWmiObject Ds Group with PowerShell" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-25 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md index 70648bb977..5cca9b6ef2 100644 --- a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md +++ b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md @@ -1,6 +1,6 @@ --- title: "GetWmiObject Ds Group with PowerShell Script Block" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-25 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md b/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md index ec48c51c03..6c12bea920 100644 --- a/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md +++ b/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md @@ -1,6 +1,6 @@ --- title: "GetDomainGroup with PowerShell Script Block" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-08-26 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md b/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md index da00993432..b5796d74aa 100644 --- a/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md +++ b/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md @@ -1,6 +1,6 @@ --- title: "Process Creating LNK file in Suspicious Location" -excerpt: "Spearphishing Link" +excerpt: "Phishing, Spearphishing Link" categories: - Endpoint last_modified_at: 2021-08-26 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.002 - Spearphishing Link - Initial Access @@ -39,6 +42,7 @@ This search looks for a process launching an `*.lnk` file under `C:\User*` or `* | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.002](https://attack.mitre.org/techniques/T1566/002/) | Spearphishing Link | Initial Access | diff --git a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md index ff3d0d1d43..ce43a6a850 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md +++ b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md @@ -1,6 +1,6 @@ --- title: "Exchange PowerShell Module Usage" -excerpt: "PowerShell" +excerpt: "Command and Scripting Interpreter, PowerShell" categories: - Endpoint last_modified_at: 2021-08-27 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.001 - PowerShell - Execution @@ -43,6 +46,7 @@ Module - New-managementroleassignment can assign a management role to a manageme | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | diff --git a/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md b/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md index bc51a3bec2..efcf1c7130 100644 --- a/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md +++ b/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md @@ -1,6 +1,6 @@ --- title: "Domain Group Discovery With Dsquery" -excerpt: "Domain Groups" +excerpt: "Permission Groups Discovery, Domain Groups" categories: - Endpoint last_modified_at: 2021-09-01 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.002 - Domain Groups - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `dsquery.exe` with command-line argumen | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | diff --git a/docs/_posts/2021-09-01-github_commit_in_develop.md b/docs/_posts/2021-09-01-github_commit_in_develop.md index 95884508b8..88ed3453af 100644 --- a/docs/_posts/2021-09-01-github_commit_in_develop.md +++ b/docs/_posts/2021-09-01-github_commit_in_develop.md @@ -54,7 +54,7 @@ This search is to detect a pushed or commit to develop branch. This is to avoid ``` #### Associated Analytic Story -* [DevSecOps](/stories/devsecops) +* [Dev Sec Ops](/stories/dev_sec_ops) #### How To Implement diff --git a/docs/_posts/2021-09-01-github_dependabot_alert.md b/docs/_posts/2021-09-01-github_dependabot_alert.md index 3af3e9c1b1..d9a2a3a395 100644 --- a/docs/_posts/2021-09-01-github_dependabot_alert.md +++ b/docs/_posts/2021-09-01-github_dependabot_alert.md @@ -1,6 +1,6 @@ --- title: "GitHub Dependabot Alert" -excerpt: "Compromise Software Dependencies and Development Tools" +excerpt: "Compromise Software Dependencies and Development Tools, Supply Chain Compromise" categories: - Cloud last_modified_at: 2021-09-01 @@ -11,6 +11,9 @@ tags: - T1195.001 - Compromise Software Dependencies and Development Tools - Initial Access + - T1195 + - Supply Chain Compromise + - Initial Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search looks for Dependabot Alerts in Github logs. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1195.001](https://attack.mitre.org/techniques/T1195/001/) | Compromise Software Dependencies and Development Tools | Initial Access | +| [T1195.001](https://attack.mitre.org/techniques/T1195/001/) | Compromise Software Dependencies and Development Tools | Initial Access || [T1195](https://attack.mitre.org/techniques/T1195/) | Supply Chain Compromise | Initial Access | + #### Search diff --git a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md index 6840e35bc1..07f7548805 100644 --- a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md +++ b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md @@ -1,6 +1,6 @@ --- title: "GitHub Pull Request from Unknown User" -excerpt: "Compromise Software Dependencies and Development Tools" +excerpt: "Compromise Software Dependencies and Development Tools, Supply Chain Compromise" categories: - Cloud last_modified_at: 2021-09-01 @@ -11,6 +11,9 @@ tags: - T1195.001 - Compromise Software Dependencies and Development Tools - Initial Access + - T1195 + - Supply Chain Compromise + - Initial Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search looks for Pull Request from unknown user. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1195.001](https://attack.mitre.org/techniques/T1195/001/) | Compromise Software Dependencies and Development Tools | Initial Access | +| [T1195.001](https://attack.mitre.org/techniques/T1195/001/) | Compromise Software Dependencies and Development Tools | Initial Access || [T1195](https://attack.mitre.org/techniques/T1195/) | Supply Chain Compromise | Initial Access | + #### Search diff --git a/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_at_the_destination_device.md b/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_at_the_destination_device.md index c7bc0cda31..a5572bd55c 100644 --- a/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_at_the_destination_device.md +++ b/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_at_the_destination_device.md @@ -1,6 +1,6 @@ --- title: "Potential Pass the Token or Hash Observed at the Destination Device" -excerpt: "Pass the Hash" +excerpt: "Use Alternate Authentication Material, Pass the Hash" categories: - Endpoint last_modified_at: 2021-09-01 @@ -8,6 +8,10 @@ toc: true toc_label: "" tags: - TTP + - T1550 + - Use Alternate Authentication Material + - Defense Evasion + - Lateral Movement - T1550.002 - Pass the Hash - Defense Evasion @@ -36,6 +40,7 @@ This detection identifies potential Pass the Token or Pass the Hash credential e | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | | [T1550.002](https://attack.mitre.org/techniques/T1550/002/) | Pass the Hash | Defense Evasion, Lateral Movement | diff --git a/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md b/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md index ebf9b5c469..e96a0c78d6 100644 --- a/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md +++ b/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md @@ -1,6 +1,6 @@ --- title: "Potential Pass the Token or Hash Observed by an Event Collecting Device" -excerpt: "Pass the Hash" +excerpt: "Use Alternate Authentication Material, Pass the Hash" categories: - Endpoint last_modified_at: 2021-09-01 @@ -8,6 +8,10 @@ toc: true toc_label: "" tags: - TTP + - T1550 + - Use Alternate Authentication Material + - Defense Evasion + - Lateral Movement - T1550.002 - Pass the Hash - Defense Evasion @@ -36,6 +40,7 @@ This detection identifies potential Pass the Token or Pass the Hash credential e | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | | [T1550.002](https://attack.mitre.org/techniques/T1550/002/) | Pass the Hash | Defense Evasion, Lateral Movement | diff --git a/docs/_posts/2021-09-06-add_defaultuser_and_password_in_registry.md b/docs/_posts/2021-09-06-add_defaultuser_and_password_in_registry.md index da3c1296a9..d8ef1940fb 100644 --- a/docs/_posts/2021-09-06-add_defaultuser_and_password_in_registry.md +++ b/docs/_posts/2021-09-06-add_defaultuser_and_password_in_registry.md @@ -1,6 +1,6 @@ --- title: "Add DefaultUser And Password In Registry" -excerpt: "Credentials in Registry" +excerpt: "Credentials in Registry, Unsecured Credentials" categories: - Endpoint last_modified_at: 2021-09-06 @@ -11,6 +11,9 @@ tags: - T1552.002 - Credentials in Registry - Credential Access + - T1552 + - Unsecured Credentials + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ this search is to detect a suspicious registry modification to implement auto ad | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1552.002](https://attack.mitre.org/techniques/T1552/002/) | Credentials in Registry | Credential Access | +| [T1552.002](https://attack.mitre.org/techniques/T1552/002/) | Credentials in Registry | Credential Access || [T1552](https://attack.mitre.org/techniques/T1552/) | Unsecured Credentials | Credential Access | + #### Search diff --git a/docs/_posts/2021-09-06-auto_admin_logon_registry_entry.md b/docs/_posts/2021-09-06-auto_admin_logon_registry_entry.md index 7d5ced6fe8..d53137a7da 100644 --- a/docs/_posts/2021-09-06-auto_admin_logon_registry_entry.md +++ b/docs/_posts/2021-09-06-auto_admin_logon_registry_entry.md @@ -1,6 +1,6 @@ --- title: "Auto Admin Logon Registry Entry" -excerpt: "Credentials in Registry" +excerpt: "Credentials in Registry, Unsecured Credentials" categories: - Endpoint last_modified_at: 2021-09-06 @@ -11,6 +11,9 @@ tags: - T1552.002 - Credentials in Registry - Credential Access + - T1552 + - Unsecured Credentials + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ this search is to detect a suspicious registry modification to implement auto ad | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1552.002](https://attack.mitre.org/techniques/T1552/002/) | Credentials in Registry | Credential Access | +| [T1552.002](https://attack.mitre.org/techniques/T1552/002/) | Credentials in Registry | Credential Access || [T1552](https://attack.mitre.org/techniques/T1552/) | Unsecured Credentials | Credential Access | + #### Search diff --git a/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md b/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md index 9e592fd06e..034f58b8d3 100644 --- a/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md +++ b/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md @@ -1,6 +1,6 @@ --- title: "Correlation by Repository and Risk" -excerpt: "Malicious Image" +excerpt: "Malicious Image, User Execution" categories: - Cloud last_modified_at: 2021-09-06 @@ -11,6 +11,9 @@ tags: - T1204.003 - Malicious Image - Execution + - T1204 + - User Execution + - Execution - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search correlations detections by repository and risk_score | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | +| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution || [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | + #### Search diff --git a/docs/_posts/2021-09-06-correlation_by_user_and_risk.md b/docs/_posts/2021-09-06-correlation_by_user_and_risk.md index 76320b98ef..c954d27ab4 100644 --- a/docs/_posts/2021-09-06-correlation_by_user_and_risk.md +++ b/docs/_posts/2021-09-06-correlation_by_user_and_risk.md @@ -1,6 +1,6 @@ --- title: "Correlation by User and Risk" -excerpt: "Malicious Image" +excerpt: "Malicious Image, User Execution" categories: - Cloud last_modified_at: 2021-09-06 @@ -11,6 +11,9 @@ tags: - T1204.003 - Malicious Image - Execution + - T1204 + - User Execution + - Execution - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search correlations detections by user and risk_score | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | +| [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution || [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | + #### Search diff --git a/docs/_posts/2021-09-07-registry_keys_used_for_persistence.md b/docs/_posts/2021-09-07-registry_keys_used_for_persistence.md index 69bd0e80b5..c8ffbcbff9 100644 --- a/docs/_posts/2021-09-07-registry_keys_used_for_persistence.md +++ b/docs/_posts/2021-09-07-registry_keys_used_for_persistence.md @@ -1,6 +1,6 @@ --- title: "Registry Keys Used For Persistence" -excerpt: "Registry Run Keys / Startup Folder" +excerpt: "Registry Run Keys / Startup Folder, Boot or Logon Autostart Execution" categories: - Endpoint last_modified_at: 2021-09-07 @@ -12,6 +12,10 @@ tags: - Registry Run Keys / Startup Folder - Persistence - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,14 +43,15 @@ The search looks for modifications to registry keys that can be used to launch a | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1547.001](https://attack.mitre.org/techniques/T1547/001/) | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation | +| [T1547.001](https://attack.mitre.org/techniques/T1547/001/) | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + #### Search ``` -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user +| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` diff --git a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md b/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md index 2cc6b26192..f5070deaab 100644 --- a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md +++ b/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md @@ -1,6 +1,6 @@ --- title: "SchCache Change By App Connect And Create ADSI Object" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-09-07 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This analytic is to detect an application try to connect and create ADSI Object | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md b/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md index 8a29f691c0..48473238a2 100644 --- a/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md +++ b/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md @@ -1,6 +1,6 @@ --- title: "Control Loading from World Writable Directory" -excerpt: "Control Panel" +excerpt: "Signed Binary Proxy Execution, Control Panel" categories: - Endpoint last_modified_at: 2021-09-08 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.002 - Control Panel - Defense Evasion @@ -38,6 +41,7 @@ The following detection identifies control.exe loading either a .cpl or .inf fro | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.002](https://attack.mitre.org/techniques/T1218/002/) | Control Panel | Defense Evasion | diff --git a/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md b/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md index 0de244fcba..70029d72df 100644 --- a/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md +++ b/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md @@ -1,6 +1,6 @@ --- title: "Create local admin accounts using net exe" -excerpt: "Local Account" +excerpt: "Local Account, Create Account" categories: - Endpoint last_modified_at: 2021-09-08 @@ -11,6 +11,9 @@ tags: - T1136.001 - Local Account - Persistence + - T1136 + - Create Account + - Persistence - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search looks for the creation of local administrator accounts using net.exe | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence | +| [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence || [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | + #### Search diff --git a/docs/_posts/2021-09-08-office_spawning_control.md b/docs/_posts/2021-09-08-office_spawning_control.md index 39c365312a..c6fe399e37 100644 --- a/docs/_posts/2021-09-08-office_spawning_control.md +++ b/docs/_posts/2021-09-08-office_spawning_control.md @@ -1,6 +1,6 @@ --- title: "Office Spawning Control" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-09-08 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ The following detection identifies control.exe spawning from an office product. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md b/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md index 290ae60171..7f58215e5e 100644 --- a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md +++ b/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md @@ -1,6 +1,6 @@ --- title: "Rundll32 Control RunDLL Hunt" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-09-08 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ The following hunting detection identifies rundll32.exe with `control_rundll` wi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md b/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md index 93ab573296..6a832ce72a 100644 --- a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md +++ b/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md @@ -1,6 +1,6 @@ --- title: "Rundll32 Control RunDLL World Writable Directory" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-09-08 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ The following detection identifies rundll32.exe with `control_rundll` within the | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-09-09-extraction_of_registry_hives.md b/docs/_posts/2021-09-09-extraction_of_registry_hives.md index 9a73c26ee8..e74aab4b8c 100644 --- a/docs/_posts/2021-09-09-extraction_of_registry_hives.md +++ b/docs/_posts/2021-09-09-extraction_of_registry_hives.md @@ -1,6 +1,6 @@ --- title: "Extraction of Registry Hives" -excerpt: "Security Account Manager" +excerpt: "Security Account Manager, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-09-09 @@ -11,6 +11,9 @@ tags: - T1003.002 - Security Account Manager - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following analytic identifies the use of `reg.exe` exporting Windows Registr | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | +| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md b/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md index 8c389cb550..e833c6176e 100644 --- a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md +++ b/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md @@ -1,6 +1,6 @@ --- title: "MSHTML Module Load in Office Product" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-09-09 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ The following detection identifies the module load of mshtml.dll into an Office | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md b/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md index 29f9d7c643..cf925a4997 100644 --- a/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md +++ b/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md @@ -1,6 +1,6 @@ --- title: "Office Product Writing cab or inf" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-09-10 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ The following analytic identifies behavior related to CVE-2021-40444. Whereas th | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md b/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md index c88df03de3..ddbedbebb3 100644 --- a/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md +++ b/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md @@ -1,6 +1,6 @@ --- title: "Jscript Execution Using Cscript App" -excerpt: "JavaScript" +excerpt: "Command and Scripting Interpreter, JavaScript" categories: - Endpoint last_modified_at: 2021-09-13 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.007 - JavaScript - Execution @@ -38,6 +41,7 @@ This search is to detect a execution of jscript using cscript process. Commonly | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md index 517d55c240..08e0d2030c 100644 --- a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md +++ b/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md @@ -1,6 +1,6 @@ --- title: "MS Scripting Process Loading Ldap Module" -excerpt: "JavaScript" +excerpt: "Command and Scripting Interpreter, JavaScript" categories: - Endpoint last_modified_at: 2021-09-13 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Anomaly + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.007 - JavaScript - Execution @@ -38,6 +41,7 @@ This search is to detect a suspicious MS scripting process such as wscript.exe o | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md index 262b7a86d1..1a89ed9dd0 100644 --- a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md +++ b/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md @@ -1,6 +1,6 @@ --- title: "MS Scripting Process Loading WMI Module" -excerpt: "JavaScript" +excerpt: "Command and Scripting Interpreter, JavaScript" categories: - Endpoint last_modified_at: 2021-09-13 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Anomaly + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.007 - JavaScript - Execution @@ -38,6 +41,7 @@ This search is to detect a suspicious MS scripting process such as wscript.exe o | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | diff --git a/docs/_posts/2021-09-13-office_application_drop_executable.md b/docs/_posts/2021-09-13-office_application_drop_executable.md index f956024878..6aec8981dd 100644 --- a/docs/_posts/2021-09-13-office_application_drop_executable.md +++ b/docs/_posts/2021-09-13-office_application_drop_executable.md @@ -1,6 +1,6 @@ --- title: "Office Application Drop Executable" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-09-13 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ This search is to detect a suspicious MS office application that drop or create | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md b/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md index e4b477a9ef..c953f9a313 100644 --- a/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md +++ b/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md @@ -1,6 +1,6 @@ --- title: "Cmdline Tool Not Executed In CMD Shell" -excerpt: "JavaScript" +excerpt: "Command and Scripting Interpreter, JavaScript" categories: - Endpoint last_modified_at: 2021-09-14 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1059 + - Command and Scripting Interpreter + - Execution - T1059.007 - JavaScript - Execution @@ -38,6 +41,7 @@ This search is to detect a suspicious parent process execution of commandline to | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | | [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | diff --git a/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md b/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md index 38763a11db..8613c9c195 100644 --- a/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md +++ b/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md @@ -1,6 +1,6 @@ --- title: "Get WMIObject Group Discovery" -excerpt: "Local Groups" +excerpt: "Permission Groups Discovery, Local Groups" categories: - Endpoint last_modified_at: 2021-09-14 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.001 - Local Groups - Discovery @@ -38,6 +41,7 @@ The following hunting analytic identifies the use of `Get-WMIObject Win32_Group` | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | diff --git a/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md b/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md index 61927dd9fa..9e4d51291f 100644 --- a/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md +++ b/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md @@ -1,6 +1,6 @@ --- title: "Get WMIObject Group Discovery with Script Block Logging" -excerpt: "Local Groups" +excerpt: "Permission Groups Discovery, Local Groups" categories: - Endpoint last_modified_at: 2021-09-14 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.001 - Local Groups - Discovery @@ -39,6 +42,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | diff --git a/docs/_posts/2021-09-14-net_localgroup_discovery.md b/docs/_posts/2021-09-14-net_localgroup_discovery.md index bd1cf59262..4559c66128 100644 --- a/docs/_posts/2021-09-14-net_localgroup_discovery.md +++ b/docs/_posts/2021-09-14-net_localgroup_discovery.md @@ -1,6 +1,6 @@ --- title: "Net Localgroup Discovery" -excerpt: "Local Groups" +excerpt: "Permission Groups Discovery, Local Groups" categories: - Endpoint last_modified_at: 2021-09-14 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.001 - Local Groups - Discovery @@ -38,6 +41,7 @@ The following hunting analytic will identify the use of localgroup discovery usi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | diff --git a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md index 3b62f3329f..40a62bfad8 100644 --- a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md +++ b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md @@ -1,6 +1,6 @@ --- title: "PowerShell Get LocalGroup Discovery" -excerpt: "Local Groups" +excerpt: "Permission Groups Discovery, Local Groups" categories: - Endpoint last_modified_at: 2021-09-14 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.001 - Local Groups - Discovery @@ -38,6 +41,7 @@ The following hunting analytic identifies the use of `get-localgroup` being used | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | diff --git a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md index 2812dcf0ed..725bf2565f 100644 --- a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md +++ b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md @@ -1,6 +1,6 @@ --- title: "Powershell Get LocalGroup Discovery with Script Block Logging" -excerpt: "Local Groups" +excerpt: "Permission Groups Discovery, Local Groups" categories: - Endpoint last_modified_at: 2021-09-14 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.001 - Local Groups - Discovery @@ -40,6 +43,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | diff --git a/docs/_posts/2021-09-14-wmic_group_discovery.md b/docs/_posts/2021-09-14-wmic_group_discovery.md index 728eccc346..6c806fbc10 100644 --- a/docs/_posts/2021-09-14-wmic_group_discovery.md +++ b/docs/_posts/2021-09-14-wmic_group_discovery.md @@ -1,6 +1,6 @@ --- title: "Wmic Group Discovery" -excerpt: "Local Groups" +excerpt: "Permission Groups Discovery, Local Groups" categories: - Endpoint last_modified_at: 2021-09-14 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1069 + - Permission Groups Discovery + - Discovery - T1069.001 - Local Groups - Discovery @@ -40,6 +43,7 @@ During triage, review parallel processes and identify any further suspicious beh | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | diff --git a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md b/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md index af03104393..7df917d3be 100644 --- a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md +++ b/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md @@ -1,6 +1,6 @@ --- title: "Non Chrome Process Accessing Chrome Default Dir" -excerpt: "Credentials from Web Browsers" +excerpt: "Credentials from Password Stores, Credentials from Web Browsers" categories: - Endpoint last_modified_at: 2021-09-15 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Anomaly + - T1555 + - Credentials from Password Stores + - Credential Access - T1555.003 - Credentials from Web Browsers - Credential Access @@ -38,6 +41,7 @@ This search is to detect an anomaly event of non-chrome process accessing the fi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | | [T1555.003](https://attack.mitre.org/techniques/T1555/003/) | Credentials from Web Browsers | Credential Access | diff --git a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md b/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md index ddf32b3af1..e4ba8a86c7 100644 --- a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md +++ b/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md @@ -1,6 +1,6 @@ --- title: "Non Firefox Process Access Firefox Profile Dir" -excerpt: "Credentials from Web Browsers" +excerpt: "Credentials from Password Stores, Credentials from Web Browsers" categories: - Endpoint last_modified_at: 2021-09-15 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Anomaly + - T1555 + - Credentials from Password Stores + - Credential Access - T1555.003 - Credentials from Web Browsers - Credential Access @@ -38,6 +41,7 @@ This search is to detect an anomaly event of non-firefox process accessing the f | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | | [T1555.003](https://attack.mitre.org/techniques/T1555/003/) | Credentials from Web Browsers | Credential Access | diff --git a/docs/_posts/2021-09-16-account_discovery_with_net_app.md b/docs/_posts/2021-09-16-account_discovery_with_net_app.md index 3f3ced3e02..4225c1bb7c 100644 --- a/docs/_posts/2021-09-16-account_discovery_with_net_app.md +++ b/docs/_posts/2021-09-16-account_discovery_with_net_app.md @@ -1,6 +1,6 @@ --- title: "Account Discovery With Net App" -excerpt: "Domain Account" +excerpt: "Domain Account, Account Discovery" categories: - Endpoint last_modified_at: 2021-09-16 @@ -11,6 +11,9 @@ tags: - T1087.002 - Domain Account - Discovery + - T1087 + - Account Discovery + - Discovery - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ this search is to detect a potential account discovery series of command used by | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | +| [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery || [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | + #### Search diff --git a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md b/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md index 17dcb34226..90de9fe432 100644 --- a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md +++ b/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md @@ -1,6 +1,6 @@ --- title: "Attempt To Add Certificate To Untrusted Store" -excerpt: "Install Root Certificate" +excerpt: "Install Root Certificate, Subvert Trust Controls" categories: - Endpoint last_modified_at: 2021-09-16 @@ -11,6 +11,9 @@ tags: - T1553.004 - Install Root Certificate - Defense Evasion + - T1553 + - Subvert Trust Controls + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +42,8 @@ Attempt To Add Certificate To Untrusted Store | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1553.004](https://attack.mitre.org/techniques/T1553/004/) | Install Root Certificate | Defense Evasion | +| [T1553.004](https://attack.mitre.org/techniques/T1553/004/) | Install Root Certificate | Defense Evasion || [T1553](https://attack.mitre.org/techniques/T1553/) | Subvert Trust Controls | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md b/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md index fcc6793998..ae4a11f94b 100644 --- a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md +++ b/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md @@ -1,6 +1,6 @@ --- title: "Attempted Credential Dump From Registry via Reg exe" -excerpt: "Security Account Manager" +excerpt: "Security Account Manager, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-09-16 @@ -11,6 +11,9 @@ tags: - T1003.002 - Security Account Manager - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ Monitor for execution of reg.exe with parameters specifying an export of keys th | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | +| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-09-16-batch_file_write_to_system32.md b/docs/_posts/2021-09-16-batch_file_write_to_system32.md index af49ba77a6..c971bbd484 100644 --- a/docs/_posts/2021-09-16-batch_file_write_to_system32.md +++ b/docs/_posts/2021-09-16-batch_file_write_to_system32.md @@ -1,6 +1,6 @@ --- title: "Batch File Write to System32" -excerpt: "Malicious File" +excerpt: "User Execution, Malicious File" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1204 + - User Execution + - Execution - T1204.002 - Malicious File - Execution @@ -38,6 +41,7 @@ The search looks for a batch file (.bat) written to the Windows system directory | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | | [T1204.002](https://attack.mitre.org/techniques/T1204/002/) | Malicious File | Execution | diff --git a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md index 231b300b44..b3377c7058 100644 --- a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md +++ b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md @@ -1,6 +1,6 @@ --- title: "Creation of Shadow Copy with wmic and powershell" -excerpt: "NTDS" +excerpt: "NTDS, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-09-16 @@ -11,6 +11,9 @@ tags: - T1003.003 - NTDS - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search detects the use of wmic and Powershell to create a shadow copy. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | +| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md index 22f74ed622..fca0b5c874 100644 --- a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md +++ b/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md @@ -1,6 +1,6 @@ --- title: "Credential Dumping via Copy Command from Shadow Copy" -excerpt: "NTDS" +excerpt: "NTDS, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-09-16 @@ -11,6 +11,9 @@ tags: - T1003.003 - NTDS - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search detects credential dumping using copy command from a shadow copy. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | +| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md index 2d28a7dbbc..789410dda4 100644 --- a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md +++ b/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md @@ -1,6 +1,6 @@ --- title: "Credential Dumping via Symlink to Shadow Copy" -excerpt: "NTDS" +excerpt: "NTDS, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-09-16 @@ -11,6 +11,9 @@ tags: - T1003.003 - NTDS - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search detects the creation of a symlink to a shadow copy. | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | +| [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-09-16-detect_html_help_renamed.md b/docs/_posts/2021-09-16-detect_html_help_renamed.md index 94535c8421..fcfe1e02cc 100644 --- a/docs/_posts/2021-09-16-detect_html_help_renamed.md +++ b/docs/_posts/2021-09-16-detect_html_help_renamed.md @@ -1,6 +1,6 @@ --- title: "Detect HTML Help Renamed" -excerpt: "Compiled HTML File" +excerpt: "Signed Binary Proxy Execution, Compiled HTML File" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.001 - Compiled HTML File - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies a renamed instance of hh.exe (HTML Help) execu | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | diff --git a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md b/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md index a0a6e85c38..23ebd66506 100644 --- a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md +++ b/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md @@ -1,6 +1,6 @@ --- title: "Detect HTML Help URL in Command Line" -excerpt: "Compiled HTML File" +excerpt: "Signed Binary Proxy Execution, Compiled HTML File" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.001 - Compiled HTML File - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | diff --git a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md b/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md index a2696a7605..cbecea14f0 100644 --- a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md +++ b/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md @@ -1,6 +1,6 @@ --- title: "Detect HTML Help Using InfoTech Storage Handlers" -excerpt: "Compiled HTML File" +excerpt: "Signed Binary Proxy Execution, Compiled HTML File" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.001 - Compiled HTML File - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | diff --git a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md b/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md index 9d80c21654..818bb1f275 100644 --- a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md +++ b/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md @@ -1,6 +1,6 @@ --- title: "Detect mshta inline hta execution" -excerpt: "Mshta" +excerpt: "Signed Binary Proxy Execution, Mshta" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.005 - Mshta - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies "mshta.exe" execution with inline prot | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | diff --git a/docs/_posts/2021-09-16-detect_mshta_renamed.md b/docs/_posts/2021-09-16-detect_mshta_renamed.md index a881084da7..b793652272 100644 --- a/docs/_posts/2021-09-16-detect_mshta_renamed.md +++ b/docs/_posts/2021-09-16-detect_mshta_renamed.md @@ -1,6 +1,6 @@ --- title: "Detect mshta renamed" -excerpt: "Mshta" +excerpt: "Signed Binary Proxy Execution, Mshta" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.005 - Mshta - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies renamed instances of mshta.exe executing. Msht | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | diff --git a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md b/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md index 09f2b553ca..3adb040e00 100644 --- a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md +++ b/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md @@ -1,6 +1,6 @@ --- title: "Detect MSHTA Url in Command Line" -excerpt: "Mshta" +excerpt: "Signed Binary Proxy Execution, Mshta" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.005 - Mshta - Defense Evasion @@ -38,6 +41,7 @@ This analytic identifies when Microsoft HTML Application Host (mshta.exe) utilit | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | diff --git a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md index 406a82c40d..ef77f564a2 100644 --- a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md +++ b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md @@ -1,6 +1,6 @@ --- title: "Detect PsExec With accepteula Flag" -excerpt: "SMB/Windows Admin Shares" +excerpt: "Remote Services, SMB/Windows Admin Shares" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1021 + - Remote Services + - Lateral Movement - T1021.002 - SMB/Windows Admin Shares - Lateral Movement @@ -38,6 +41,7 @@ This search looks for events where `PsExec.exe` is run with the `accepteula` fla | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | | [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | diff --git a/docs/_posts/2021-09-16-detect_renamed_7-zip.md b/docs/_posts/2021-09-16-detect_renamed_7-zip.md index 5bfa53c9af..b772d0a6d1 100644 --- a/docs/_posts/2021-09-16-detect_renamed_7-zip.md +++ b/docs/_posts/2021-09-16-detect_renamed_7-zip.md @@ -1,6 +1,6 @@ --- title: "Detect Renamed 7-Zip" -excerpt: "Archive via Utility" +excerpt: "Archive via Utility, Archive Collected Data" categories: - Endpoint last_modified_at: 2021-09-16 @@ -11,6 +11,9 @@ tags: - T1560.001 - Archive via Utility - Collection + - T1560 + - Archive Collected Data + - Collection - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ The following analytic identifies renamed 7-Zip usage using Sysmon. At this stag | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | +| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection || [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | + #### Search diff --git a/docs/_posts/2021-09-16-detect_renamed_psexec.md b/docs/_posts/2021-09-16-detect_renamed_psexec.md index f14b652ac3..72d98ce82b 100644 --- a/docs/_posts/2021-09-16-detect_renamed_psexec.md +++ b/docs/_posts/2021-09-16-detect_renamed_psexec.md @@ -1,6 +1,6 @@ --- title: "Detect Renamed PSExec" -excerpt: "Service Execution" +excerpt: "System Services, Service Execution" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1569 + - System Services + - Execution - T1569.002 - Service Execution - Execution @@ -40,6 +43,7 @@ The following analytic identifies renamed instances of `PsExec.exe` being utiliz | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | | [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | diff --git a/docs/_posts/2021-09-16-detect_renamed_winrar.md b/docs/_posts/2021-09-16-detect_renamed_winrar.md index 35ca37e570..6d743e36b2 100644 --- a/docs/_posts/2021-09-16-detect_renamed_winrar.md +++ b/docs/_posts/2021-09-16-detect_renamed_winrar.md @@ -1,6 +1,6 @@ --- title: "Detect Renamed WinRAR" -excerpt: "Archive via Utility" +excerpt: "Archive via Utility, Archive Collected Data" categories: - Endpoint last_modified_at: 2021-09-16 @@ -11,6 +11,9 @@ tags: - T1560.001 - Archive via Utility - Collection + - T1560 + - Archive Collected Data + - Collection - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +42,8 @@ The following analtyic identifies renamed instances of `WinRAR.exe`. In most cas | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | +| [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection || [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | + #### Search diff --git a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md b/docs/_posts/2021-09-16-dump_lsass_via_procdump.md index 3ef511b647..3d5008317a 100644 --- a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md +++ b/docs/_posts/2021-09-16-dump_lsass_via_procdump.md @@ -1,6 +1,6 @@ --- title: "Dump LSASS via procdump" -excerpt: "LSASS Memory" +excerpt: "LSASS Memory, OS Credential Dumping" categories: - Endpoint last_modified_at: 2021-09-16 @@ -11,6 +11,9 @@ tags: - T1003.001 - LSASS Memory - Credential Access + - T1003 + - OS Credential Dumping + - Credential Access - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +42,8 @@ During triage, confirm this is procdump.exe executing. If it is the first time a | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | +| [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access || [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + #### Search diff --git a/docs/_posts/2021-09-16-local_account_discovery_with_net.md b/docs/_posts/2021-09-16-local_account_discovery_with_net.md index 534dfb389e..1c26775f0d 100644 --- a/docs/_posts/2021-09-16-local_account_discovery_with_net.md +++ b/docs/_posts/2021-09-16-local_account_discovery_with_net.md @@ -1,6 +1,6 @@ --- title: "Local Account Discovery with Net" -excerpt: "Local Account" +excerpt: "Account Discovery, Local Account" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1087 + - Account Discovery + - Discovery - T1087.001 - Local Account - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command-li | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | diff --git a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md b/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md index e52353e196..34ca85fdea 100644 --- a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md +++ b/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md @@ -1,6 +1,6 @@ --- title: "Local Account Discovery With Wmic" -excerpt: "Local Account" +excerpt: "Account Discovery, Local Account" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1087 + - Account Discovery + - Discovery - T1087.001 - Local Account - Discovery @@ -38,6 +41,7 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | diff --git a/docs/_posts/2021-09-16-office_product_spawning_wmic.md b/docs/_posts/2021-09-16-office_product_spawning_wmic.md index 5ce30328ff..3df9c7a6e1 100644 --- a/docs/_posts/2021-09-16-office_product_spawning_wmic.md +++ b/docs/_posts/2021-09-16-office_product_spawning_wmic.md @@ -1,6 +1,6 @@ --- title: "Office Product Spawning Wmic" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-09-16 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ The following detection identifies the latest behavior utilized by Ursnif malwar | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-09-16-processes_launching_netsh.md b/docs/_posts/2021-09-16-processes_launching_netsh.md index 400a19493f..8052c1e8a2 100644 --- a/docs/_posts/2021-09-16-processes_launching_netsh.md +++ b/docs/_posts/2021-09-16-processes_launching_netsh.md @@ -1,6 +1,6 @@ --- title: "Processes launching netsh" -excerpt: "Disable or Modify System Firewall" +excerpt: "Disable or Modify System Firewall, Impair Defenses" categories: - Endpoint last_modified_at: 2021-09-16 @@ -11,6 +11,9 @@ tags: - T1562.004 - Disable or Modify System Firewall - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search looks for processes launching netsh.exe. Netsh is a command-line scr | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1562.004](https://attack.mitre.org/techniques/T1562/004/) | Disable or Modify System Firewall | Defense Evasion | +| [T1562.004](https://attack.mitre.org/techniques/T1562/004/) | Disable or Modify System Firewall | Defense Evasion || [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + #### Search diff --git a/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md b/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md index 29daeb29d8..cb19b7e50e 100644 --- a/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md @@ -1,6 +1,6 @@ --- title: "Detect Regasm with no Command Line Arguments" -excerpt: "Regsvcs/Regasm" +excerpt: "Signed Binary Proxy Execution, Regsvcs/Regasm" categories: - Endpoint last_modified_at: 2021-09-20 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.009 - Regsvcs/Regasm - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies regasm.exe with no command line arguments. Thi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | diff --git a/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md b/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md index 869f008695..fcff6a0137 100644 --- a/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md @@ -1,6 +1,6 @@ --- title: "Detect Regsvcs with No Command Line Arguments" -excerpt: "Regsvcs/Regasm" +excerpt: "Signed Binary Proxy Execution, Regsvcs/Regasm" categories: - Endpoint last_modified_at: 2021-09-20 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.009 - Regsvcs/Regasm - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies regsvcs.exe with no command line arguments. Th | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | diff --git a/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md b/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md index 3aeb112778..7422ed9c11 100644 --- a/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md +++ b/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md @@ -1,6 +1,6 @@ --- title: "Office Document Spawned Child Process To Download" -excerpt: "Spearphishing Attachment" +excerpt: "Phishing, Spearphishing Attachment" categories: - Endpoint last_modified_at: 2021-09-20 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1566 + - Phishing + - Initial Access - T1566.001 - Spearphishing Attachment - Initial Access @@ -38,6 +41,7 @@ This search is to detect potential malicious office document executing lolbin ch | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | diff --git a/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md b/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md index b43daedddf..c4f2b17a68 100644 --- a/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md +++ b/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md @@ -1,6 +1,6 @@ --- title: "Suspicious microsoft workflow compiler rename" -excerpt: "Trusted Developer Utilities Proxy Execution, Rename System Utilities" +excerpt: "Masquerading, Trusted Developer Utilities Proxy Execution, Rename System Utilities" categories: - Endpoint last_modified_at: 2021-09-20 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - Hunting + - T1036 + - Masquerading + - Defense Evasion - T1127 - Trusted Developer Utilities Proxy Execution - Defense Evasion @@ -41,6 +44,7 @@ The following analytic identifies a renamed instance of microsoft.workflow.compi | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | | [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | | [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | diff --git a/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md index db121561bc..181a492d2c 100644 --- a/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md @@ -1,6 +1,6 @@ --- title: "Suspicious Rundll32 no Command Line Arguments" -excerpt: "Rundll32" +excerpt: "Signed Binary Proxy Execution, Rundll32" categories: - Endpoint last_modified_at: 2021-09-20 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion - T1218.011 - Rundll32 - Defense Evasion @@ -38,6 +41,7 @@ The following analytic identifies rundll32.exe with no command line arguments. I | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | diff --git a/docs/_posts/2021-09-27-change_default_file_association.md b/docs/_posts/2021-09-27-change_default_file_association.md new file mode 100644 index 0000000000..6da4d82dc3 --- /dev/null +++ b/docs/_posts/2021-09-27-change_default_file_association.md @@ -0,0 +1,109 @@ +--- +title: "Change Default File Association" +excerpt: "Change Default File Association, Event Triggered Execution" +categories: + - Endpoint +last_modified_at: 2021-09-27 +toc: true +toc_label: "" +tags: + - TTP + - T1546.001 + - Change Default File Association + - Privilege Escalation + - Persistence + - T1546 + - Event Triggered Execution + - Privilege Escalation + - Persistence + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is developed to detect suspicious registry modification to change the default file association of windows to malicious payload. This techninique was seen in some APT where it modify the default process to run file association, like .txt to notepad.exe. Instead notepad.exe it will point to a Script or other payload that will load malicious command to the compromised host. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-09-27 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 462d17d8-1f71-11ec-ad07-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1546.001](https://attack.mitre.org/techniques/T1546/001/) | Change Default File Association | Privilege Escalation, Persistence || [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\shell\\open\\command\\*" Registry.registry_path = "*HKCR\\*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `change_default_file_association_filter` +``` + +#### Associated Analytic Story +* [Windows Persistence Techniques](/stories/windows_persistence_techniques) +* [Windows Privilege Escalation](/stories/windows_privilege_escalation) + + +#### How To Implement +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +#### Required field +* _time +* Registry.dest +* Registry.user +* Registry.registry_path +* Registry.registry_key_name +* Registry.registry_value_name + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +unknown + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | + + + +#### Reference + +* [https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/change_default_file_association.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md b/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md new file mode 100644 index 0000000000..090cf88106 --- /dev/null +++ b/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md @@ -0,0 +1,109 @@ +--- +title: "Logon Script Event Trigger Execution" +excerpt: "Boot or Logon Initialization Scripts, Logon Script (Windows)" +categories: + - Endpoint +last_modified_at: 2021-09-27 +toc: true +toc_label: "" +tags: + - TTP + - T1037 + - Boot or Logon Initialization Scripts + - Persistence + - Privilege Escalation + - T1037.001 + - Logon Script (Windows) + - Persistence + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This search is to detect a suspicious modification of registry entry to persist and gain privilege escalation upon booting up of compromised host. This technique was seen in several APT and malware where it modify UserInitMprLogonScript registry entry to its malicious payload to be executed upon boot up of the machine. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-09-27 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 4c38c264-1f74-11ec-b5fa-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1037](https://attack.mitre.org/techniques/T1037/) | Boot or Logon Initialization Scripts | Persistence, Privilege Escalation | +| [T1037.001](https://attack.mitre.org/techniques/T1037/001/) | Logon Script (Windows) | Persistence, Privilege Escalation | + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path IN ("*\\Environment\\UserInitMprLogonScript") by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `logon_script_event_trigger_execution_filter` +``` + +#### Associated Analytic Story +* [Windows Persistence Techniques](/stories/windows_persistence_techniques) +* [Windows Privilege Escalation](/stories/windows_privilege_escalation) + + +#### How To Implement +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +#### Required field +* _time +* Registry.dest +* Registry.user +* Registry.registry_path +* Registry.registry_key_name +* Registry.registry_value_name + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +unknown + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1037/001](https://attack.mitre.org/techniques/T1037/001) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1037.001/logonscript_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1037.001/logonscript_reg/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/logon_script_event_trigger_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md b/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md new file mode 100644 index 0000000000..db3540bc09 --- /dev/null +++ b/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md @@ -0,0 +1,110 @@ +--- +title: "Screensaver Event Trigger Execution" +excerpt: "Event Triggered Execution, Screensaver" +categories: + - Endpoint +last_modified_at: 2021-09-27 +toc: true +toc_label: "" +tags: + - TTP + - T1546 + - Event Triggered Execution + - Privilege Escalation + - Persistence + - T1546.002 + - Screensaver + - Privilege Escalation + - Persistence + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is developed to detect possible event trigger execution through screensaver registry entry modification for persistence or privilege escalation. This technique was seen in several APT and malware where they put the malicious payload path to the SCRNSAVE.EXE registry key to redirect the execution to their malicious payload path. This TTP is a good indicator that some attacker may modify this entry for their persistence and privilege escalation. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-09-27 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 58cea3ec-1f6d-11ec-8560-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | +| [T1546.002](https://attack.mitre.org/techniques/T1546/002/) | Screensaver | Privilege Escalation, Persistence | + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\Control Panel\\Desktop\\SCRNSAVE.EXE*") by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `screensaver_event_trigger_execution_filter` +``` + +#### Associated Analytic Story +* [Windows Persistence Techniques](/stories/windows_persistence_techniques) +* [Windows Privilege Escalation](/stories/windows_privilege_escalation) + + +#### How To Implement +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +#### Required field +* _time +* Registry.dest +* Registry.user +* Registry.registry_path +* Registry.registry_key_name +* Registry.registry_value_name + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +unknown + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 72.0 | 80 | 90 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1546/002/](https://attack.mitre.org/techniques/T1546/002/) +* [https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.002/scrnsave_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.002/scrnsave_reg/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/screensaver_event_trigger_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-28-active_setup_registry_autostart.md b/docs/_posts/2021-09-28-active_setup_registry_autostart.md new file mode 100644 index 0000000000..fbdf4a6604 --- /dev/null +++ b/docs/_posts/2021-09-28-active_setup_registry_autostart.md @@ -0,0 +1,110 @@ +--- +title: "Active Setup Registry Autostart" +excerpt: "Active Setup, Boot or Logon Autostart Execution" +categories: + - Endpoint +last_modified_at: 2021-09-28 +toc: true +toc_label: "" +tags: + - TTP + - T1547.014 + - Active Setup + - Persistence + - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a suspicious modification of the active setup registry for persistence and privilege escalation. This technique was seen in several malware (poisonIvy), adware and APT to gain persistence to the compromised machine upon boot up. This TTP is a good indicator to further check the process id that do the modification since modification of this registry is not commonly done. check the legitimacy of the file and process involve in this rules to check if it is a valid setup installer that creating or modifying this registry. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-09-28 +- **Author**: Teoderick Contreras, Splunk +- **ID**: f64579c0-203f-11ec-abcc-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1547.014](https://attack.mitre.org/techniques/T1547/014/) | Active Setup | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_value_name = "StubPath" Registry.registry_key_name = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `active_setup_registry_autostart_filter` +``` + +#### Associated Analytic Story +* [Windows Persistence Techniques](/stories/windows_persistence_techniques) +* [Windows Privilege Escalation](/stories/windows_privilege_escalation) + + +#### How To Implement +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +#### Required field +* _time +* Registry.dest +* Registry.user +* Registry.registry_path +* Registry.registry_key_name +* Registry.registry_value_name + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +Active setup installer may add or modify this registry. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 64.0 | 80 | 80 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | + + + +#### Reference + +* [https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor%3aWin32%2fPoisonivy.E](https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor%3aWin32%2fPoisonivy.E) +* [https://attack.mitre.org/techniques/T1547/014/](https://attack.mitre.org/techniques/T1547/014/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1547.014/active_setup_stubpath/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1547.014/active_setup_stubpath/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/active_setup_registry_autostart.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-28-print_processor_registry_autostart.md b/docs/_posts/2021-09-28-print_processor_registry_autostart.md new file mode 100644 index 0000000000..f688e971ee --- /dev/null +++ b/docs/_posts/2021-09-28-print_processor_registry_autostart.md @@ -0,0 +1,112 @@ +--- +title: "Print Processor Registry Autostart" +excerpt: "Print Processors, Boot or Logon Autostart Execution" +categories: + - Endpoint +last_modified_at: 2021-09-28 +toc: true +toc_label: "" +tags: + - TTP + - T1547.012 + - Print Processors + - Persistence + - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + +### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION +We have not been able to test, simulate or build datasets for it, use at your own risk! + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a suspicious modification or new registry entry regarding print processor. This registry is known to be abuse by turla or other APT to gain persistence and privilege escalation to the compromised machine. This is done by adding the malicious dll payload on the new created key in this registry that will be executed as it restarted the spoolsv.exe process and services. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-09-28 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 1f5b68aa-2037-11ec-898e-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\Control\\Print\\Environments\\Windows x64\\Print Processors*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `print_processor_registry_autostart_filter` +``` + +#### Associated Analytic Story +* [Windows Persistence Techniques](/stories/windows_persistence_techniques) +* [Windows Privilege Escalation](/stories/windows_privilege_escalation) + + +#### How To Implement +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +#### Required field +* _time +* Registry.dest +* Registry.user +* Registry.registry_path +* Registry.registry_key_name +* Registry.registry_value_name + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +possible new printer installation may add driver component on this registry. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1547/012/](https://attack.mitre.org/techniques/T1547/012/) +* [https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/](https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/print_reg/sysmon_print.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/print_reg/sysmon_print.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/print_processor_registry_autostart.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-29-disable_uac_remote_restriction.md b/docs/_posts/2021-09-29-disable_uac_remote_restriction.md new file mode 100644 index 0000000000..29b7c916b3 --- /dev/null +++ b/docs/_posts/2021-09-29-disable_uac_remote_restriction.md @@ -0,0 +1,110 @@ +--- +title: "Disable UAC Remote Restriction" +excerpt: "Bypass User Account Control, Abuse Elevation Control Mechanism" +categories: + - Endpoint +last_modified_at: 2021-09-29 +toc: true +toc_label: "" +tags: + - TTP + - T1548.002 + - Bypass User Account Control + - Privilege Escalation + - Defense Evasion + - T1548 + - Abuse Elevation Control Mechanism + - Privilege Escalation + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a suspicious modification of registry to disable UAC remote restriction. This technique was well documented in Microsoft page where attacker may modify this registry value to bypassed UAC feature of windows host. This is a good indicator that some tries to bypassed UAC to suspicious process or gain privilege escalation. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-09-29 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 9928b732-210e-11ec-b65e-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion || [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy" Registry.registry_value_data="0x00000001" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `disable_uac_remote_restriction_filter` +``` + +#### Associated Analytic Story +* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) +* [Suspicious Windows Registry Activities](/stories/suspicious_windows_registry_activities) + + +#### How To Implement +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +#### Required field +* _time +* Registry.dest +* Registry.user +* Registry.registry_path +* Registry.registry_key_name +* Registry.registry_value_name +* Registry.registry_value_data + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +admin may set this policy for non-critical machine. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | + + + +#### Reference + +* [https://docs.microsoft.com/en-us/troubleshoot/windows-server/windows-security/user-account-control-and-remote-restriction](https://docs.microsoft.com/en-us/troubleshoot/windows-server/windows-security/user-account-control-and-remote-restriction) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/LocalAccountTokenFilterPolicy/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/LocalAccountTokenFilterPolicy/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_uac_remote_restriction.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-29-time_provider_persistence_registry.md b/docs/_posts/2021-09-29-time_provider_persistence_registry.md new file mode 100644 index 0000000000..950c8714c4 --- /dev/null +++ b/docs/_posts/2021-09-29-time_provider_persistence_registry.md @@ -0,0 +1,110 @@ +--- +title: "Time Provider Persistence Registry" +excerpt: "Time Providers, Boot or Logon Autostart Execution" +categories: + - Endpoint +last_modified_at: 2021-09-29 +toc: true +toc_label: "" +tags: + - TTP + - T1547.003 + - Time Providers + - Persistence + - Privilege Escalation + - T1547 + - Boot or Logon Autostart Execution + - Persistence + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a suspiciouos modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-09-29 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 5ba382c4-2105-11ec-8d8f-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1547.003](https://attack.mitre.org/techniques/T1547/003/) | Time Providers | Persistence, Privilege Escalation || [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `time_provider_persistence_registry_filter` +``` + +#### Associated Analytic Story +* [Windows Persistence Techniques](/stories/windows_persistence_techniques) +* [Windows Privilege Escalation](/stories/windows_privilege_escalation) + + +#### How To Implement +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +#### Required field +* _time +* Registry.dest +* Registry.user +* Registry.registry_path +* Registry.registry_key_name +* Registry.registry_value_name + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +unknown + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | + + + +#### Reference + +* [https://pentestlab.blog/2019/10/22/persistence-time-providers/](https://pentestlab.blog/2019/10/22/persistence-time-providers/) +* [https://attack.mitre.org/techniques/T1547/003/](https://attack.mitre.org/techniques/T1547/003/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.003/timeprovider_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.003/timeprovider_reg/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/time_provider_persistence_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-09-29-verclsid_clsid_execution.md b/docs/_posts/2021-09-29-verclsid_clsid_execution.md new file mode 100644 index 0000000000..1021b33af6 --- /dev/null +++ b/docs/_posts/2021-09-29-verclsid_clsid_execution.md @@ -0,0 +1,113 @@ +--- +title: "Verclsid CLSID Execution" +excerpt: "Verclsid, Signed Binary Proxy Execution" +categories: + - Endpoint +last_modified_at: 2021-09-29 +toc: true +toc_label: "" +tags: + - Hunting + - T1218.012 + - Verclsid + - Defense Evasion + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a possible abuse of verclsid to execute malicious file through generate CLSID. This process is a normal application of windows to verify the CLSID COM object before it is instantiated by Windows Explorer. This hunting query can be a good pivot point to analyze what is he CLSID or COM object pointing too to check if it is a valid application or not. + +- **Type**: Hunting +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-09-29 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 61e9a56a-20fa-11ec-8ba3-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1218.012](https://attack.mitre.org/techniques/T1218/012/) | Verclsid | Defense Evasion || [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_verclsid` AND Processes.process="*/S*" Processes.process="*/C*" AND Processes.process="*{*" AND Processes.process="*}*" by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name Processes.parent_process +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `verclsid_clsid_execution_filter` +``` + +#### Associated Analytic Story +* [Unusual Processes](/stories/unusual_processes) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +windows can used this application for its normal COM object validation. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 25.0 | 50 | 50 | process $process_name$ to execute possible clsid commandline $process$ in $dest$ | + + + +#### Reference + +* [https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5](https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5) +* [https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/](https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.012/verclsid_exec/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.012/verclsid_exec/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/verclsid_clsid_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md b/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md new file mode 100644 index 0000000000..fde7b099d0 --- /dev/null +++ b/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md @@ -0,0 +1,113 @@ +--- +title: "Vbscript Execution Using Wscript App" +excerpt: "Visual Basic, Command and Scripting Interpreter" +categories: + - Endpoint +last_modified_at: 2021-10-01 +toc: true +toc_label: "" +tags: + - TTP + - T1059.005 + - Visual Basic + - Execution + - T1059 + - Command and Scripting Interpreter + - Execution + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a suspicious wscript commandline to execute vbscript. This technique was seen in several malware to execute malicious vbs file using wscript application. commonly vbs script is associated to cscript process and this can be a technique to evade process parent child detections or even some av script emulation system. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-01 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 35159940-228f-11ec-8a49-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1059.005](https://attack.mitre.org/techniques/T1059/005/) | Visual Basic | Execution || [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "wscript.exe" AND Processes.parent_process = "*//e:vbscript*") OR (Processes.process_name = "wscript.exe" AND Processes.process = "*//e:vbscript*") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `vbscript_execution_using_wscript_app_filter` +``` + +#### Associated Analytic Story +* [FIN7](/stories/fin7) +* [Remcos](/stories/remcos) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +unknown + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 49.0 | 70 | 70 | Process name $process_name$ with commandline $process$ to execute vbsscript | + + + +#### Reference + +* [https://www.joesandbox.com/analysis/369332/0/html](https://www.joesandbox.com/analysis/369332/0/html) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md b/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md new file mode 100644 index 0000000000..e38636db91 --- /dev/null +++ b/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md @@ -0,0 +1,107 @@ +--- +title: "MSBuild Suspicious Spawned By Script Process" +excerpt: "MSBuild, Trusted Developer Utilities Proxy Execution" +categories: + - Endpoint +last_modified_at: 2021-10-04 +toc: true +toc_label: "" +tags: + - TTP + - T1127.001 + - MSBuild + - Defense Evasion + - T1127 + - Trusted Developer Utilities Proxy Execution + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a suspicious child process of MSBuild spawned by Windows Script Host - cscript or wscript. This behavior or event are commonly seen and used by malware or adversaries to execute malicious msbuild process using malicious script in the compromised host. During triage, review parallel processes and identify any file modifications. MSBuild may load a script from the same path without having command-line arguments. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-04 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 213b3148-24ea-11ec-93a2-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion || [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("wscript.exe", "cscript.exe") AND `process_msbuild` by Processes.dest Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `msbuild_suspicious_spawned_by_script_process_filter` +``` + +#### Associated Analytic Story +* [Trusted Developer Utilities Proxy Execution MSBuild](/stories/trusted_developer_utilities_proxy_execution_msbuild) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Required field +* _time +* Processes.dest +* Processes.parent_process +* Processes.parent_process_name +* Processes.process_name +* Processes.original_file_name +* Processes.user + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +False positives should be limited as developers do not spawn MSBuild via a WSH. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 49.0 | 70 | 70 | Msbuild.exe process spawned by $parent_process_name$ on $dest$ executed by $user$ | + + + +#### Reference + +* [https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/#](https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/#) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/regsvr32_silent/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/regsvr32_silent/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-04-regsvr32_silent_param_dll_loading.md b/docs/_posts/2021-10-04-regsvr32_silent_param_dll_loading.md new file mode 100644 index 0000000000..220c6b0c85 --- /dev/null +++ b/docs/_posts/2021-10-04-regsvr32_silent_param_dll_loading.md @@ -0,0 +1,113 @@ +--- +title: "Regsvr32 Silent Param Dll Loading" +excerpt: "Signed Binary Proxy Execution, Regsvr32" +categories: + - Endpoint +last_modified_at: 2021-10-04 +toc: true +toc_label: "" +tags: + - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion + - T1218.010 + - Regsvr32 + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a loading of dll using regsvr32 application with silent parameter and dllinstall execution. This technique was seen in several RAT malware like remcos, njrat and APT's to load their malicious dll in the compromised machine. This TTP may executed by normal 3rd party application so it is better to pivot the parent process, parent commandline and commandline of the file that execute this regsvr32. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-04 +- **Author**: Teoderick Contreras, Splunk +- **ID**: f421c250-24e7-11ec-bc43-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | +| [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = regsvr32.exe Processes.process="*/i*" Processes.process="*/s*" by Processes.dest Processes.parent_process Processes.process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `regsvr32_silent_param_dll_loading_filter` +``` + +#### Associated Analytic Story +* [Suspicious Regsvr32 Activity](/stories/suspicious_regsvr32_activity) + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +Other third part application may used this parameter but not so common in base windows environment. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 36.0 | 60 | 60 | regsvr32 process with $process$ commandline in $dest$ | + + + +#### Reference + +* [https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/#](https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/#) +* [https://attack.mitre.org/techniques/T1218/010/](https://attack.mitre.org/techniques/T1218/010/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/regsvr32_silent_param_dll_loading.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-detect_exchange_web_shell.md b/docs/_posts/2021-10-05-detect_exchange_web_shell.md index 98d1959118..bd8524ab9c 100644 --- a/docs/_posts/2021-10-05-detect_exchange_web_shell.md +++ b/docs/_posts/2021-10-05-detect_exchange_web_shell.md @@ -1,6 +1,6 @@ --- title: "Detect Exchange Web Shell" -excerpt: "Web Shell" +excerpt: "Server Software Component, Web Shell" categories: - Endpoint last_modified_at: 2021-10-05 @@ -8,6 +8,9 @@ toc: true toc_label: "" tags: - TTP + - T1505 + - Server Software Component + - Persistence - T1505.003 - Web Shell - Persistence @@ -38,6 +41,7 @@ The following query identifies suspicious .aspx created in 3 paths identified by | ID | Technique | Tactic | | ----------- | ----------- | -------------- | +| [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | | [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | diff --git a/docs/_posts/2021-10-05-disable_security_logs_using_minint_registry.md b/docs/_posts/2021-10-05-disable_security_logs_using_minint_registry.md new file mode 100644 index 0000000000..476edcd635 --- /dev/null +++ b/docs/_posts/2021-10-05-disable_security_logs_using_minint_registry.md @@ -0,0 +1,103 @@ +--- +title: "Disable Security Logs Using MiniNt Registry" +excerpt: "Modify Registry" +categories: + - Endpoint +last_modified_at: 2021-10-05 +toc: true +toc_label: "" +tags: + - TTP + - T1112 + - Modify Registry + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a suspicious registry modification to disable security audit logs. This technique was shared by a researcher to disable Security logs of windows by adding this registry. The Windows will think it is WinPE and will not log any event to the Security Log + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-05 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 39ebdc68-25b9-11ec-aec7-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Control\\MiniNt\\*" by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name Registry.registry_path Registry.registry_value_data +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `disable_security_logs_using_minint_registry_filter` +``` + +#### Associated Analytic Story +* [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics) + + +#### How To Implement +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +#### Required field +* _time +* Registry.dest +* Registry.user +* Registry.registry_value_name +* Registry.registry_key_name +* Registry.registry_path +* Registry.registry_value_data + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +Unknown. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | + + + +#### Reference + +* [https://twitter.com/0gtweet/status/1182516740955226112](https://twitter.com/0gtweet/status/1182516740955226112) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/minint_reg/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/minint_reg/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/disable_security_logs_using_minint_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-enable_wdigest_uselogoncredential_registry.md b/docs/_posts/2021-10-05-enable_wdigest_uselogoncredential_registry.md new file mode 100644 index 0000000000..ea16458ec7 --- /dev/null +++ b/docs/_posts/2021-10-05-enable_wdigest_uselogoncredential_registry.md @@ -0,0 +1,107 @@ +--- +title: "Enable WDigest UseLogonCredential Registry" +excerpt: "Modify Registry, OS Credential Dumping" +categories: + - Endpoint +last_modified_at: 2021-10-05 +toc: true +toc_label: "" +tags: + - TTP + - T1112 + - Modify Registry + - Defense Evasion + - T1003 + - OS Credential Dumping + - Credential Access + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a suspicious registry modification to enable plain text credential feature of windows. This technique was used by several malware and also by mimikatz to be able to dumpe the a plain text credential to the compromised or target host. This TTP is really a good indicator that someone wants to dump the crendential of the host so it must be a good pivot for credential dumping techniques. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-05 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 0c7d8ffe-25b1-11ec-9f39-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | +| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name Registry.registry_path Registry.registry_value_data +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `enable_wdigest_uselogoncredential_registry_filter` +``` + +#### Associated Analytic Story +* [Credential Dumping](/stories/credential_dumping) + + +#### How To Implement +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +#### Required field +* _time +* Registry.dest +* Registry.user +* Registry.registry_value_name +* Registry.registry_key_name +* Registry.registry_path +* Registry.registry_value_data + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +unknown + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | wdigest registry $registry_path$ was modified in $dest$ | + + + +#### Reference + +* [https://www.csoonline.com/article/3438824/how-to-detect-and-halt-credential-theft-via-windows-wdigest.html](https://www.csoonline.com/article/3438824/how-to-detect-and-halt-credential-theft-via-windows-wdigest.html) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/wdigest_enable/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/wdigest_enable/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md b/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md new file mode 100644 index 0000000000..018424fc3c --- /dev/null +++ b/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md @@ -0,0 +1,115 @@ +--- +title: "Malicious InProcServer32 Modification" +excerpt: "Regsvr32, Modify Registry" +categories: + - Endpoint +last_modified_at: 2021-10-05 +toc: true +toc_label: "" +tags: + - TTP + - T1218.010 + - Regsvr32 + - Defense Evasion + - T1112 + - Modify Registry + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies a process modifying the registry with a known malicious CLSID under InProcServer32. Most COM classes are registered with the operating system and are identified by a GUID that represents the Class Identifier (CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind the implementation of a COM class is the server (some binary) that is referenced within registry keys under the CLSID. The LocalServer32 key represents a path to an executable (exe) implementation, and the InprocServer32 key represents a path to a dynamic link library (DLL) implementation (Bohops). During triage, review parallel processes for suspicious activity. Pivot on the process GUID to see the full timeline of events. Analyze the value and look for file modifications. Being this is looking for inprocserver32, a DLL found in the value will most likely be loaded by a parallel process. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-05 +- **Author**: Michael Haag, Splunk +- **ID**: 127c8d08-25ff-11ec-9223-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion || [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid Processes.user +| `drop_dm_object_name(Processes)` +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest Registry.process_guid Registry.user +| `drop_dm_object_name(Registry)` +| fields _time dest registry_path registry_key_name registry_value_name process_name process_path process process_guid user] +| stats count min(_time) as firstTime max(_time) as lastTime by dest, process_name registry_path registry_key_name registry_value_name user +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `malicious_inprocserver32_modification_filter` +``` + +#### Associated Analytic Story +* [Suspicious Regsvr32 Activity](/stories/suspicious_regsvr32_activity) +* [Remcos](/stories/remcos) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Required field +* _time +* dest +* process_name +* registry_path +* registry_key_name +* registry_value_name +* user + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +False positives should be limited, filter as needed. In our test case, Remcos used regsvr32.exe to modify the registry. It may be required, dependent upon the EDR tool producing registry events, to remove (Default) from the command-line. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | The $process_name$ was identified on endpoint $dest$ modifying the registry with a known malicious clsid under InProcServer32. | + + + +#### Reference + +* [https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/](https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/) +* [https://tria.ge/210929-ap75vsddan](https://tria.ge/210929-ap75vsddan) +* [https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89](https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/malicious_inprocserver32_modification.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md b/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md index 1077b13f7f..ac46606682 100644 --- a/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md +++ b/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md @@ -1,6 +1,6 @@ --- title: "Malicious PowerShell Process - Connect To Internet With Hidden Window" -excerpt: "PowerShell" +excerpt: "PowerShell, Command and Scripting Interpreter" categories: - Endpoint last_modified_at: 2021-10-05 @@ -11,6 +11,9 @@ tags: - T1059.001 - PowerShell - Execution + - T1059 + - Command and Scripting Interpreter + - Execution - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -39,7 +42,8 @@ The following hunting analytic identifies PowerShell commands utilizing the Wind | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | +| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution || [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | + #### Search diff --git a/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md b/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md new file mode 100644 index 0000000000..23491a99a1 --- /dev/null +++ b/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md @@ -0,0 +1,116 @@ +--- +title: "Process Writing DynamicWrapperX" +excerpt: "Command and Scripting Interpreter, Component Object Model" +categories: + - Endpoint +last_modified_at: 2021-10-05 +toc: true +toc_label: "" +tags: + - Hunting + - T1059 + - Command and Scripting Interpreter + - Execution + - T1559.001 + - Component Object Model + - Execution + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +DynamicWrapperX is an ActiveX component that can be used in a script to call Windows API functions, but it requires the dynwrapx.dll to be installed and registered. With that, a binary writing dynwrapx.dll to disk and registering it into the registry is highly suspect. Why is it needed? In most malicious instances, it will be written to disk at a non-standard location. During triage, review parallel processes and pivot on the process_guid. Review the registry for any suspicious modifications meant to load dynwrapx.dll. Identify any suspicious module loads of dynwrapx.dll. This will identify the process that will invoke vbs/wscript/cscript. + +- **Type**: Hunting +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-05 +- **Author**: Michael Haag, Splunk +- **ID**: b0a078e4-2601-11ec-9aec-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | +| [T1559.001](https://attack.mitre.org/techniques/T1559/001/) | Component Object Model | Execution | + + +#### Search + +``` + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid Processes.user +| `drop_dm_object_name(Processes)` +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="dynwrapx.dll" by _time Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid Filesystem.user +| `drop_dm_object_name(Filesystem)` +| fields _time process_guid file_path file_name file_create_time user dest process_name] +| stats count min(_time) as firstTime max(_time) as lastTime by dest process_name process_guid file_name file_path file_create_time user +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `process_writing_dynamicwrapperx_filter` +``` + +#### Associated Analytic Story +* [Remcos](/stories/remcos) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Required field +* _time +* dest +* process_name +* process_guid +* file_name +* file_path +* file_create_time user + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +False positives should be limited, however it is possible to filter by Processes.process_name and specific processes (ex. wscript.exe). Filter as needed. This may need modification based on EDR telemetry and how it brings in registry data. For example, removal of (Default). + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | An instance of $process_name$ was identified on endpoint $dest$ downloading the DynamicWrapperX dll. | + + + +#### Reference + +* [https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/](https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/) +* [https://www.script-coding.com/dynwrapx_eng.html](https://www.script-coding.com/dynwrapx_eng.html) +* [https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/](https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/) +* [https://tria.ge/210929-ap75vsddan](https://tria.ge/210929-ap75vsddan) +* [https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89](https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/process_writing_dynamicwrapperx.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-rundll32_shimcache_flush.md b/docs/_posts/2021-10-05-rundll32_shimcache_flush.md new file mode 100644 index 0000000000..8ddd052cb4 --- /dev/null +++ b/docs/_posts/2021-10-05-rundll32_shimcache_flush.md @@ -0,0 +1,109 @@ +--- +title: "Rundll32 Shimcache Flush" +excerpt: "Modify Registry" +categories: + - Endpoint +last_modified_at: 2021-10-05 +toc: true +toc_label: "" +tags: + - TTP + - T1112 + - Modify Registry + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a suspicious rundll32 commandline to clear shim cache. This technique is a anti-forensic technique to clear the cache taht are one important artifacts in terms of digital forensic during attacks or incident. This TTP is a good indicator that someone tries to evade some tools and clear foothold on the machine. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-05 +- **Author**: Teoderick Contreras, Splunk +- **ID**: a913718a-25b6-11ec-96d3-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` AND Processes.process = "*apphelp.dll,ShimFlushCache*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `rundll32_shimcache_flush_filter` +``` + +#### Associated Analytic Story +* [Unusual Processes](/stories/unusual_processes) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +unknown + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | rundll32 process execute $process$ to clear shim cache in $dest$ | + + + +#### Reference + +* [https://blueteamops.medium.com/shimcache-flush-89daff28d15e](https://blueteamops.medium.com/shimcache-flush-89daff28d15e) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/shimcache_flush/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/shimcache_flush/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_shimcache_flush.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-suspicious_copy_on_system32.md b/docs/_posts/2021-10-05-suspicious_copy_on_system32.md new file mode 100644 index 0000000000..fa1eeb399f --- /dev/null +++ b/docs/_posts/2021-10-05-suspicious_copy_on_system32.md @@ -0,0 +1,112 @@ +--- +title: "Suspicious Copy on System32" +excerpt: "Rename System Utilities, Masquerading" +categories: + - Endpoint +last_modified_at: 2021-10-05 +toc: true +toc_label: "" +tags: + - TTP + - T1036.003 + - Rename System Utilities + - Defense Evasion + - T1036 + - Masquerading + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a suspicious copy of file from systemroot folder of the windows OS. This technique is commonly used by APT or other malware as part of execution (LOLBIN) to run its malicious code using the available legitimate tool in OS. this type of event may seen or may execute of normal user in some instance but this is really a anomaly that needs to be check within the network. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-05 +- **Author**: Teoderick Contreras, Splunk +- **ID**: ce633e56-25b2-11ec-9e76-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion || [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN("cmd.exe", "powershell*","pwsh.exe", "sqlps.exe", "sqltoolsps.exe", "powershell_ise.exe") AND `process_copy` AND Processes.process IN("*\\Windows\\System32\*", "*\\Windows\\SysWow64\\*") AND Processes.process = "*copy*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_copy_on_system32_filter` +``` + +#### Associated Analytic Story +* [Unusual Processes](/stories/unusual_processes) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +every user may do this event but very un-ussual. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 63.0 | 70 | 90 | execution of copy exe to copy file from $process$ in $dest$ | + + + +#### Reference + +* [https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120](https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/copy_sysmon/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/copy_sysmon/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_copy_on_system32.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md b/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md new file mode 100644 index 0000000000..206529fb3c --- /dev/null +++ b/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md @@ -0,0 +1,112 @@ +--- +title: "Winhlp32 Spawning a Process" +excerpt: "Process Injection" +categories: + - Endpoint +last_modified_at: 2021-10-05 +toc: true +toc_label: "" +tags: + - TTP + - T1055 + - Process Injection + - Defense Evasion + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies winhlp32.exe, found natively in `c:\windows\`, spawning a child process that loads a file out of appdata, programdata, or temp. Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the ".hlp" file name extension. This particular instance is related to a Remcos sample where dynwrapx.dll is added to the registry under inprocserver32, and later module loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk. During triage, review parallel processes to identify further suspicious behavior. Review module loads for unsuspecting unsigned modules. Capture any file modifications and analyze. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-05 +- **Author**: Michael Haag, Splunk +- **ID**: d17dae9e-2618-11ec-b9f5-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `winhlp32_spawning_a_process_filter` +``` + +#### Associated Analytic Story +* [Remcos](/stories/remcos) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +False positives should be limited as winhlp32.exe is typically not used with the latest flavors of Windows OS. However, filter as needed. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$, and is not typical activity for this process. | + + + +#### Reference + +* [https://www.exploit-db.com/exploits/16541](https://www.exploit-db.com/exploits/16541) +* [https://tria.ge/210929-ap75vsddan](https://tria.ge/210929-ap75vsddan) +* [https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89](https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/winhlp32_spawning_a_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md b/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md index ac00e595e8..81cbd06898 100644 --- a/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md +++ b/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md @@ -1,6 +1,6 @@ --- title: "DNS Query Length With High Standard Deviation" -excerpt: "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol" +excerpt: "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, Exfiltration Over Alternative Protocol" categories: - Network last_modified_at: 2021-10-06 @@ -11,6 +11,9 @@ tags: - T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol - Exfiltration + - T1048 + - Exfiltration Over Alternative Protocol + - Exfiltration - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud @@ -38,7 +41,8 @@ This search allows you to identify DNS requests and compute the standard deviati | ID | Technique | Tactic | | ----------- | ----------- | -------------- | -| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | +| [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration || [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | + #### Search diff --git a/docs/_posts/2021-10-06-sdelete_application_execution.md b/docs/_posts/2021-10-06-sdelete_application_execution.md new file mode 100644 index 0000000000..074401d517 --- /dev/null +++ b/docs/_posts/2021-10-06-sdelete_application_execution.md @@ -0,0 +1,116 @@ +--- +title: "Sdelete Application Execution" +excerpt: "Data Destruction, File Deletion, Indicator Removal on Host" +categories: + - Endpoint +last_modified_at: 2021-10-06 +toc: true +toc_label: "" +tags: + - TTP + - T1485 + - Data Destruction + - Impact + - T1070.004 + - File Deletion + - Defense Evasion + - T1070 + - Indicator Removal on Host + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect the execution of sdelete.exe application sysinternal tools. This tool is one of the most use tool of malware and adversaries to remove or clear their tracks and artifact in the targetted host. This tool is designed to delete securely a file in file system that remove the forensic evidence on the machine. A good TTP query to check why user execute this application which is not a common practice. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-06 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 31702fc0-2682-11ec-85c3-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | +| [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion || [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_sdelete` by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name Processes.parent_process +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `sdelete_application_execution_filter` +``` + +#### Associated Analytic Story +* [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +user may execute and use this application + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 49.0 | 70 | 70 | sdelete process $process_name$ executed in $dest$ | + + + +#### Reference + +* [https://app.any.run/tasks/956f50be-2c13-465a-ac00-6224c14c5f89/](https://app.any.run/tasks/956f50be-2c13-465a-ac00-6224c14c5f89/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/sdelete_application_execution.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md b/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md new file mode 100644 index 0000000000..ae3f268830 --- /dev/null +++ b/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md @@ -0,0 +1,126 @@ +--- +title: "Wscript Or Cscript Suspicious Child Process" +excerpt: "Process Injection, Create or Modify System Process, Parent PID Spoofing, Access Token Manipulation" +categories: + - Endpoint +last_modified_at: 2021-10-06 +toc: true +toc_label: "" +tags: + - TTP + - T1055 + - Process Injection + - Defense Evasion + - Privilege Escalation + - T1543 + - Create or Modify System Process + - Persistence + - Privilege Escalation + - T1134.004 + - Parent PID Spoofing + - Defense Evasion + - Privilege Escalation + - T1134 + - Access Token Manipulation + - Defense Evasion + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a suspicious spawned process by wscript or cscript process. This technique was a common technique used by adversaries and malware to execute different LOLBIN, other script like powershell or create a suspended process to inject its code as a defense evasion. This TTP may detect some normal script that using several application tool that are in the list of the child process it detects but a good pivot and indicator that a script is may execute suspicious code. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-06 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 1f35e1da-267b-11ec-90a9-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | +| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | +| [T1134.004](https://attack.mitre.org/techniques/T1134/004/) | Parent PID Spoofing | Defense Evasion, Privilege Escalation || [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("cscript.exe", "wscript.exe") Processes.process_name IN ("regsvr32.exe", "rundll32.exe","winhlp32.exe","certutil.exe","msbuild.exe","cmd.exe","powershell*","wmic.exe","mshta.exe") by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `wscript_or_cscript_suspicious_child_process_filter` +``` + +#### Associated Analytic Story +* [FIN7](/stories/fin7) +* [Remcos](/stories/remcos) +* [Unusual Processes](/stories/unusual_processes) + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +user may create vbs or js script that use several tool as part of its execution. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 49.0 | 70 | 70 | wscript or cscript parent process spawned $process_name$ in $dest$ | + + + +#### Reference + +* [https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120](https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-07-etw_registry_disabled.md b/docs/_posts/2021-10-07-etw_registry_disabled.md new file mode 100644 index 0000000000..732cc23dca --- /dev/null +++ b/docs/_posts/2021-10-07-etw_registry_disabled.md @@ -0,0 +1,111 @@ +--- +title: "ETW Registry Disabled" +excerpt: "Indicator Blocking, Trusted Developer Utilities Proxy Execution, Impair Defenses" +categories: + - Endpoint +last_modified_at: 2021-10-07 +toc: true +toc_label: "" +tags: + - TTP + - T1562.006 + - Indicator Blocking + - Defense Evasion + - T1127 + - Trusted Developer Utilities Proxy Execution + - Defense Evasion + - T1562 + - Impair Defenses + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic is to detect a registry modification to disable ETW feature of windows. This technique is to evade EDR appliance to evade detections and hide its execution from audit logs. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-07 +- **Author**: Teoderick Contreras, Splunk +- **ID**: 8ed523ac-276b-11ec-ac39-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1562.006](https://attack.mitre.org/techniques/T1562/006/) | Indicator Blocking | Defense Evasion || [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | +| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*") Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000 by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `etw_registry_disabled_filter` +``` + +#### Associated Analytic Story +* [Windows Persistence Techniques](/stories/windows_persistence_techniques) +* [Windows Privilege Escalation](/stories/windows_privilege_escalation) + + +#### How To Implement +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +#### Required field +* _time +* Registry.dest +* Registry.user +* Registry.registry_path +* Registry.registry_key_name +* Registry.registry_value_name +* Registry.registry_value_data + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +unknown + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 90.0 | 90 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | + + + +#### Reference + +* [https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3](https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/etw_disable/sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/etw_disable/sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/etw_registry_disabled.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md b/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md new file mode 100644 index 0000000000..a48ee64fe1 --- /dev/null +++ b/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md @@ -0,0 +1,108 @@ +--- +title: "Suspicious wevtutil Usage" +excerpt: "Clear Windows Event Logs, Indicator Removal on Host" +categories: + - Endpoint +last_modified_at: 2021-10-11 +toc: true +toc_label: "" +tags: + - TTP + - T1070.001 + - Clear Windows Event Logs + - Defense Evasion + - T1070 + - Indicator Removal on Host + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Actions on Objectives +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The wevtutil.exe application is the windows event log utility. This searches for wevtutil.exe with parameters for clearing the application, security, setup, trace or system event logs. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-11 +- **Author**: David Dorsey, Michael Haag, Splunk +- **ID**: 2827c0fd-e1be-4868-ae25-59d28e0f9d4f + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion || [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wevtutil.exe Processes.process IN ("* cl *", "*clear-log*") (Processes.process="*System*" OR Processes.process="*Security*" OR Processes.process="*Setup*" OR Processes.process="*Application*" OR Processes.process="*trace*") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` +| `suspicious_wevtutil_usage_filter` +``` + +#### Associated Analytic Story +* [Windows Log Manipulation](/stories/windows_log_manipulation) +* [Ransomware](/stories/ransomware) +* [Clop Ransomware](/stories/clop_ransomware) + + +#### How To Implement +You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. + +#### Required field +* _time +* Processes.process +* Processes.process_name +* Processes.parent_process_name +* Processes.dest +* Processes.user + + +#### Kill Chain Phase +* Actions on Objectives + + +#### Known False Positives +The wevtutil.exe application is a legitimate Windows event log utility. Administrators may use it to manage Windows event logs. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 28.0 | 40 | 70 | Wevtutil.exe being used to clear Event Logs on $dest$ by $user$ | + + + +#### Reference + +* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_wevtutil_usage.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md new file mode 100644 index 0000000000..5f22de4084 --- /dev/null +++ b/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md @@ -0,0 +1,112 @@ +--- +title: "DLLHost with no Command Line Arguments with Network" +excerpt: "Process Injection" +categories: + - Endpoint +last_modified_at: 2021-10-13 +toc: true +toc_label: "" +tags: + - TTP + - T1055 + - Process Injection + - Defense Evasion + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies DLLHost.exe with no command line arguments with a network connection. It is unusual for DLLHost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. DLLHost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-13 +- **Author**: Michael Haag, Splunk +- **ID**: f1c07594-a141-11eb-8407-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=dllhost.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| regex process="(dllhost\.exe.{0,4}$)" +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port +| `drop_dm_object_name(Ports)` +| rename dest as connection_to_CNC] +| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port +| `dllhost_with_no_command_line_arguments_with_network_filter` +``` + +#### Associated Analytic Story +* [Cobalt Strike](/stories/cobalt_strike) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `port` node. + +#### Required field +* _time +* EventID +* process_name +* process_id +* parent_process_name +* dest_port +* process_path + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +Although unlikely, some legitimate third party applications may use a moved copy of dllhost, triggering a false positive. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 49.0 | 70 | 70 | The process $process_name$ was spawned by $parent_image$ without any command-line arguments on $dest$ by $user$. | + + + +#### Reference + +* [https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile](https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile) +* [https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/](https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_dllhost.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_dllhost.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md new file mode 100644 index 0000000000..8accda0bdb --- /dev/null +++ b/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md @@ -0,0 +1,123 @@ +--- +title: "Rundll32 with no Command Line Arguments with Network" +excerpt: "Signed Binary Proxy Execution, Rundll32" +categories: + - Endpoint +last_modified_at: 2021-10-13 +toc: true +toc_label: "" +tags: + - TTP + - T1218 + - Signed Binary Proxy Execution + - Defense Evasion + - T1218.011 + - Rundll32 + - Defense Evasion + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies rundll32.exe with no command line arguments and performing a network connection. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-13 +- **Author**: Michael Haag, Splunk +- **ID**: 35307032-a12d-11eb-835f-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | +| [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | + + +#### Search + +``` + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_rundll32` by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name Processes.original_file_name +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| regex process="(rundll32\.exe.{0,4}$)" +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port +| `drop_dm_object_name(Ports)` +| rename dest as connection_to_CNC] +| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port +| `rundll32_with_no_command_line_arguments_with_network_filter` +``` + +#### Associated Analytic Story +* [Suspicious Rundll32 Activity](/stories/suspicious_rundll32_activity) +* [Cobalt Strike](/stories/cobalt_strike) +* [PrintNightmare CVE-2021-34527](/stories/printnightmare_cve-2021-34527) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `port` node. To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +Although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 70.0 | 70 | 100 | A rundll32 process $process_name$ with no commandline argument like this process commandline $process$ in host $dest$ | + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1218/011/](https://attack.mitre.org/techniques/T1218/011/) +* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md) +* [https://lolbas-project.github.io/lolbas/Binaries/Rundll32](https://lolbas-project.github.io/lolbas/Binaries/Rundll32) +* [https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/](https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md b/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md new file mode 100644 index 0000000000..1476bcd20e --- /dev/null +++ b/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md @@ -0,0 +1,110 @@ +--- +title: "SearchProtocolHost with no Command Line with Network" +excerpt: "Process Injection" +categories: + - Endpoint +last_modified_at: 2021-10-13 +toc: true +toc_label: "" +tags: + - TTP + - T1055 + - Process Injection + - Defense Evasion + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint + - Exploitation +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies searchprotocolhost.exe with no command line arguments and with a network connection. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-10-13 +- **Author**: Michael Haag, Splunk +- **ID**: b690df8c-a145-11eb-a38b-acde48001122 + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- | -------------- | +| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | + + + +#### Search + +``` + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| regex process="(searchprotocolhost\.exe.{0,4}$)" +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port +| `drop_dm_object_name(Ports)` +| rename dest as connection_to_CNC] +| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port +| `searchprotocolhost_with_no_command_line_with_network_filter` +``` + +#### Associated Analytic Story +* [Cobalt Strike](/stories/cobalt_strike) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `ports` node. + +#### Required field +* _time +* process_name +* process_id +* parent_process_name +* dest_port +* process_path + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +Limited false positives may be present in small environments. Tuning may be required based on parent process. + + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 70.0 | 70 | 100 | A searchprotocolhost.exe process $process_name$ with no commandline in host $dest$ | + + + +#### Reference + +* [https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc](https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_searchprotocolhost.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_searchprotocolhost.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_stories/active_directory_discovery.md b/docs/_stories/active_directory_discovery.md index ca8a94e001..7dc8283b01 100644 --- a/docs/_stories/active_directory_discovery.md +++ b/docs/_stories/active_directory_discovery.md @@ -31,70 +31,70 @@ Once an attacker obtains an initial foothold in an Active Directory environment, | Name | Technique | Type | | ----------- | ----------- |--------------| -| [AdsiSearcher Account Discovery](/endpoint/adsisearcher_account_discovery/) | [Domain Account](/tags/#domain-account) | TTP | +| [AdsiSearcher Account Discovery](/endpoint/adsisearcher_account_discovery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | | [DSQuery Domain Discovery](/endpoint/dsquery_domain_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | -| [Domain Account Discovery With Net App](/endpoint/domain_account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account) | TTP | -| [Domain Account Discovery with Dsquery](/endpoint/domain_account_discovery_with_dsquery/) | [Domain Account](/tags/#domain-account) | Hunting | -| [Domain Account Discovery with Wmic](/endpoint/domain_account_discovery_with_wmic/) | [Domain Account](/tags/#domain-account) | TTP | +| [Domain Account Discovery With Net App](/endpoint/domain_account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | +| [Domain Account Discovery with Dsquery](/endpoint/domain_account_discovery_with_dsquery/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | Hunting | +| [Domain Account Discovery with Wmic](/endpoint/domain_account_discovery_with_wmic/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | | [Domain Controller Discovery with Nltest](/endpoint/domain_controller_discovery_with_nltest/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | | [Domain Controller Discovery with Wmic](/endpoint/domain_controller_discovery_with_wmic/) | [Remote System Discovery](/tags/#remote-system-discovery) | Hunting | -| [Domain Group Discovery With Dsquery](/endpoint/domain_group_discovery_with_dsquery/) | [Domain Groups](/tags/#domain-groups) | Hunting | -| [Domain Group Discovery With Net](/endpoint/domain_group_discovery_with_net/) | [Domain Groups](/tags/#domain-groups) | Hunting | -| [Domain Group Discovery With Wmic](/endpoint/domain_group_discovery_with_wmic/) | [Domain Groups](/tags/#domain-groups) | Hunting | -| [Domain Group Discovery with Adsisearcher](/endpoint/domain_group_discovery_with_adsisearcher/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [Elevated Group Discovery With Net](/endpoint/elevated_group_discovery_with_net/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [Elevated Group Discovery With Wmic](/endpoint/elevated_group_discovery_with_wmic/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [Elevated Group Discovery with PowerView](/endpoint/elevated_group_discovery_with_powerview/) | [Domain Groups](/tags/#domain-groups) | Hunting | +| [Domain Group Discovery With Dsquery](/endpoint/domain_group_discovery_with_dsquery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | +| [Domain Group Discovery With Net](/endpoint/domain_group_discovery_with_net/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | +| [Domain Group Discovery With Wmic](/endpoint/domain_group_discovery_with_wmic/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | +| [Domain Group Discovery with Adsisearcher](/endpoint/domain_group_discovery_with_adsisearcher/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [Elevated Group Discovery With Net](/endpoint/elevated_group_discovery_with_net/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [Elevated Group Discovery With Wmic](/endpoint/elevated_group_discovery_with_wmic/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [Elevated Group Discovery with PowerView](/endpoint/elevated_group_discovery_with_powerview/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | | [Get ADDefaultDomainPasswordPolicy with Powershell](/endpoint/get_addefaultdomainpasswordpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery) | Hunting | | [Get ADDefaultDomainPasswordPolicy with Powershell Script Block](/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery) | Hunting | -| [Get ADUser with PowerShell](/endpoint/get_aduser_with_powershell/) | [Domain Account](/tags/#domain-account) | Hunting | -| [Get ADUser with PowerShell Script Block](/endpoint/get_aduser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account) | Hunting | +| [Get ADUser with PowerShell](/endpoint/get_aduser_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | Hunting | +| [Get ADUser with PowerShell Script Block](/endpoint/get_aduser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | Hunting | | [Get ADUserResultantPasswordPolicy with Powershell](/endpoint/get_aduserresultantpasswordpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery) | TTP | | [Get ADUserResultantPasswordPolicy with Powershell Script Block](/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery) | TTP | | [Get DomainPolicy with Powershell](/endpoint/get_domainpolicy_with_powershell/) | [Password Policy Discovery](/tags/#password-policy-discovery) | TTP | | [Get DomainPolicy with Powershell Script Block](/endpoint/get_domainpolicy_with_powershell_script_block/) | [Password Policy Discovery](/tags/#password-policy-discovery) | TTP | -| [Get DomainUser with PowerShell](/endpoint/get_domainuser_with_powershell/) | [Domain Account](/tags/#domain-account) | TTP | -| [Get DomainUser with PowerShell Script Block](/endpoint/get_domainuser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account) | TTP | -| [Get WMIObject Group Discovery](/endpoint/get_wmiobject_group_discovery/) | [Local Groups](/tags/#local-groups) | Hunting | -| [Get WMIObject Group Discovery with Script Block Logging](/endpoint/get_wmiobject_group_discovery_with_script_block_logging/) | [Local Groups](/tags/#local-groups) | Hunting | +| [Get DomainUser with PowerShell](/endpoint/get_domainuser_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | +| [Get DomainUser with PowerShell Script Block](/endpoint/get_domainuser_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | +| [Get WMIObject Group Discovery](/endpoint/get_wmiobject_group_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | +| [Get WMIObject Group Discovery with Script Block Logging](/endpoint/get_wmiobject_group_discovery_with_script_block_logging/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | | [Get-DomainTrust with PowerShell](/endpoint/get-domaintrust_with_powershell/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | | [Get-DomainTrust with PowerShell Script Block](/endpoint/get-domaintrust_with_powershell_script_block/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | | [Get-ForestTrust with PowerShell](/endpoint/get-foresttrust_with_powershell/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | | [Get-ForestTrust with PowerShell Script Block](/endpoint/get-foresttrust_with_powershell_script_block/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | | [GetAdComputer with PowerShell](/endpoint/getadcomputer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | Hunting | | [GetAdComputer with PowerShell Script Block](/endpoint/getadcomputer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | Hunting | -| [GetAdGroup with PowerShell](/endpoint/getadgroup_with_powershell/) | [Domain Groups](/tags/#domain-groups) | Hunting | -| [GetAdGroup with PowerShell Script Block](/endpoint/getadgroup_with_powershell_script_block/) | [Domain Groups](/tags/#domain-groups) | Hunting | +| [GetAdGroup with PowerShell](/endpoint/getadgroup_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | +| [GetAdGroup with PowerShell Script Block](/endpoint/getadgroup_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | Hunting | | [GetCurrent User with PowerShell](/endpoint/getcurrent_user_with_powershell/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Hunting | | [GetCurrent User with PowerShell Script Block](/endpoint/getcurrent_user_with_powershell_script_block/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Hunting | | [GetDomainComputer with PowerShell](/endpoint/getdomaincomputer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | | [GetDomainComputer with PowerShell Script Block](/endpoint/getdomaincomputer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | | [GetDomainController with PowerShell](/endpoint/getdomaincontroller_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | Hunting | | [GetDomainController with PowerShell Script Block](/endpoint/getdomaincontroller_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | -| [GetDomainGroup with PowerShell](/endpoint/getdomaingroup_with_powershell/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [GetDomainGroup with PowerShell Script Block](/endpoint/getdomaingroup_with_powershell_script_block/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [GetLocalUser with PowerShell](/endpoint/getlocaluser_with_powershell/) | [Local Account](/tags/#local-account) | Hunting | -| [GetLocalUser with PowerShell Script Block](/endpoint/getlocaluser_with_powershell_script_block/) | [Local Account](/tags/#local-account) | Hunting | +| [GetDomainGroup with PowerShell](/endpoint/getdomaingroup_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [GetDomainGroup with PowerShell Script Block](/endpoint/getdomaingroup_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [GetLocalUser with PowerShell](/endpoint/getlocaluser_with_powershell/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | +| [GetLocalUser with PowerShell Script Block](/endpoint/getlocaluser_with_powershell_script_block/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | | [GetNetTcpconnection with PowerShell](/endpoint/getnettcpconnection_with_powershell/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | Hunting | | [GetNetTcpconnection with PowerShell Script Block](/endpoint/getnettcpconnection_with_powershell_script_block/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | Hunting | -| [GetWmiObject DS User with PowerShell](/endpoint/getwmiobject_ds_user_with_powershell/) | [Domain Account](/tags/#domain-account) | TTP | -| [GetWmiObject DS User with PowerShell Script Block](/endpoint/getwmiobject_ds_user_with_powershell_script_block/) | [Domain Account](/tags/#domain-account) | TTP | +| [GetWmiObject DS User with PowerShell](/endpoint/getwmiobject_ds_user_with_powershell/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | +| [GetWmiObject DS User with PowerShell Script Block](/endpoint/getwmiobject_ds_user_with_powershell_script_block/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | | [GetWmiObject Ds Computer with PowerShell](/endpoint/getwmiobject_ds_computer_with_powershell/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | | [GetWmiObject Ds Computer with PowerShell Script Block](/endpoint/getwmiobject_ds_computer_with_powershell_script_block/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | -| [GetWmiObject Ds Group with PowerShell](/endpoint/getwmiobject_ds_group_with_powershell/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [GetWmiObject Ds Group with PowerShell Script Block](/endpoint/getwmiobject_ds_group_with_powershell_script_block/) | [Domain Groups](/tags/#domain-groups) | TTP | -| [GetWmiObject User Account with PowerShell](/endpoint/getwmiobject_user_account_with_powershell/) | [Local Account](/tags/#local-account) | Hunting | -| [GetWmiObject User Account with PowerShell Script Block](/endpoint/getwmiobject_user_account_with_powershell_script_block/) | [Local Account](/tags/#local-account) | Hunting | -| [Local Account Discovery With Wmic](/endpoint/local_account_discovery_with_wmic/) | [Local Account](/tags/#local-account) | Hunting | -| [Local Account Discovery with Net](/endpoint/local_account_discovery_with_net/) | [Local Account](/tags/#local-account) | Hunting | +| [GetWmiObject Ds Group with PowerShell](/endpoint/getwmiobject_ds_group_with_powershell/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [GetWmiObject Ds Group with PowerShell Script Block](/endpoint/getwmiobject_ds_group_with_powershell_script_block/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Domain Groups](/tags/#domain-groups) | TTP | +| [GetWmiObject User Account with PowerShell](/endpoint/getwmiobject_user_account_with_powershell/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | +| [GetWmiObject User Account with PowerShell Script Block](/endpoint/getwmiobject_user_account_with_powershell_script_block/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | +| [Local Account Discovery With Wmic](/endpoint/local_account_discovery_with_wmic/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | +| [Local Account Discovery with Net](/endpoint/local_account_discovery_with_net/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | Hunting | | [NLTest Domain Trust Discovery](/endpoint/nltest_domain_trust_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | -| [Net Localgroup Discovery](/endpoint/net_localgroup_discovery/) | [Local Groups](/tags/#local-groups) | Hunting | +| [Net Localgroup Discovery](/endpoint/net_localgroup_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | | [Network Connection Discovery With Arp](/endpoint/network_connection_discovery_with_arp/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | Hunting | | [Network Connection Discovery With Net](/endpoint/network_connection_discovery_with_net/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | Hunting | | [Network Connection Discovery With Netstat](/endpoint/network_connection_discovery_with_netstat/) | [System Network Connections Discovery](/tags/#system-network-connections-discovery) | Hunting | | [Password Policy Discovery with Net](/endpoint/password_policy_discovery_with_net/) | [Password Policy Discovery](/tags/#password-policy-discovery) | Hunting | -| [PowerShell Get LocalGroup Discovery](/endpoint/powershell_get_localgroup_discovery/) | [Local Groups](/tags/#local-groups) | Hunting | -| [Powershell Get LocalGroup Discovery with Script Block Logging](/endpoint/powershell_get_localgroup_discovery_with_script_block_logging/) | [Local Groups](/tags/#local-groups) | Hunting | +| [PowerShell Get LocalGroup Discovery](/endpoint/powershell_get_localgroup_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | +| [Powershell Get LocalGroup Discovery with Script Block Logging](/endpoint/powershell_get_localgroup_discovery_with_script_block_logging/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | | [Remote System Discovery with Adsisearcher](/endpoint/remote_system_discovery_with_adsisearcher/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | | [Remote System Discovery with Dsquery](/endpoint/remote_system_discovery_with_dsquery/) | [Remote System Discovery](/tags/#remote-system-discovery) | Hunting | | [Remote System Discovery with Net](/endpoint/remote_system_discovery_with_net/) | [Remote System Discovery](/tags/#remote-system-discovery) | Hunting | @@ -103,7 +103,7 @@ Once an attacker obtains an initial foothold in an Active Directory environment, | [System User Discovery With Whoami](/endpoint/system_user_discovery_with_whoami/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Hunting | | [User Discovery With Env Vars PowerShell](/endpoint/user_discovery_with_env_vars_powershell/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Hunting | | [User Discovery With Env Vars PowerShell Script Block](/endpoint/user_discovery_with_env_vars_powershell_script_block/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | Hunting | -| [Wmic Group Discovery](/endpoint/wmic_group_discovery/) | [Local Groups](/tags/#local-groups) | Hunting | +| [Wmic Group Discovery](/endpoint/wmic_group_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | #### Reference diff --git a/docs/_stories/active_directory_password_spraying.md b/docs/_stories/active_directory_password_spraying.md index ba1d5d7643..a4be2498cf 100644 --- a/docs/_stories/active_directory_password_spraying.md +++ b/docs/_stories/active_directory_password_spraying.md @@ -32,14 +32,14 @@ Specifically, this Analytic Story is focused on detecting possible Password Spra | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Multiple Disabled Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Invalid Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Invalid Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Users Attempting To Authenticate Using Explicit Credentials](/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Users Failing To Authenticate From Process](/endpoint/multiple_users_failing_to_authenticate_from_process/) | [Password Spraying](/tags/#password-spraying) | Anomaly | -| [Multiple Users Remotely Failing To Authenticate From Host](/endpoint/multiple_users_remotely_failing_to_authenticate_from_host/) | [Password Spraying](/tags/#password-spraying) | Anomaly | +| [Multiple Disabled Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Invalid Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Invalid Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Users Attempting To Authenticate Using Explicit Credentials](/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Users Failing To Authenticate From Host Using Kerberos](/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Users Failing To Authenticate From Host Using NTLM](/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Users Failing To Authenticate From Process](/endpoint/multiple_users_failing_to_authenticate_from_process/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | +| [Multiple Users Remotely Failing To Authenticate From Host](/endpoint/multiple_users_remotely_failing_to_authenticate_from_host/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | Anomaly | #### Reference diff --git a/docs/_stories/aws_iam_privilege_escalation.md b/docs/_stories/aws_iam_privilege_escalation.md index 8fb7923022..941fa18846 100644 --- a/docs/_stories/aws_iam_privilege_escalation.md +++ b/docs/_stories/aws_iam_privilege_escalation.md @@ -31,15 +31,15 @@ However, if these IAM policies are misconfigured and have specific combinations | Name | Technique | Type | | ----------- | ----------- |--------------| -| [AWS Create Policy Version to allow all resources](/cloud/aws_create_policy_version_to_allow_all_resources/) | [Cloud Accounts](/tags/#cloud-accounts) | TTP | -| [AWS CreateAccessKey](/cloud/aws_createaccesskey/) | [Cloud Account](/tags/#cloud-account) | Hunting | -| [AWS CreateLoginProfile](/cloud/aws_createloginprofile/) | [Cloud Account](/tags/#cloud-account) | TTP | +| [AWS Create Policy Version to allow all resources](/cloud/aws_create_policy_version_to_allow_all_resources/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | TTP | +| [AWS CreateAccessKey](/cloud/aws_createaccesskey/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | Hunting | +| [AWS CreateLoginProfile](/cloud/aws_createloginprofile/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | | [AWS IAM Assume Role Policy Brute Force](/cloud/aws_iam_assume_role_policy_brute_force/) | [Cloud Infrastructure Discovery](/tags/#cloud-infrastructure-discovery), [Brute Force](/tags/#brute-force) | TTP | | [AWS IAM Delete Policy](/cloud/aws_iam_delete_policy/) | [Account Manipulation](/tags/#account-manipulation) | Hunting | | [AWS IAM Failure Group Deletion](/cloud/aws_iam_failure_group_deletion/) | [Account Manipulation](/tags/#account-manipulation) | Anomaly | -| [AWS IAM Successful Group Deletion](/cloud/aws_iam_successful_group_deletion/) | [Cloud Groups](/tags/#cloud-groups), [Account Manipulation](/tags/#account-manipulation) | Hunting | -| [AWS SetDefaultPolicyVersion](/cloud/aws_setdefaultpolicyversion/) | [Cloud Accounts](/tags/#cloud-accounts) | TTP | -| [AWS UpdateLoginProfile](/cloud/aws_updateloginprofile/) | [Cloud Account](/tags/#cloud-account) | TTP | +| [AWS IAM Successful Group Deletion](/cloud/aws_iam_successful_group_deletion/) | [Cloud Groups](/tags/#cloud-groups), [Account Manipulation](/tags/#account-manipulation), [Permission Groups Discovery](/tags/#permission-groups-discovery) | Hunting | +| [AWS SetDefaultPolicyVersion](/cloud/aws_setdefaultpolicyversion/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | TTP | +| [AWS UpdateLoginProfile](/cloud/aws_updateloginprofile/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | #### Reference diff --git a/docs/_stories/aws_network_acl_activity.md b/docs/_stories/aws_network_acl_activity.md index ccbfb85386..359fbc3f4e 100644 --- a/docs/_stories/aws_network_acl_activity.md +++ b/docs/_stories/aws_network_acl_activity.md @@ -30,8 +30,8 @@ AWS CloudTrail is an AWS service that helps you enable governance, compliance, a | Name | Technique | Type | | ----------- | ----------- |--------------| -| [AWS Network Access Control List Created with All Open Ports](/cloud/aws_network_access_control_list_created_with_all_open_ports/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | TTP | -| [AWS Network Access Control List Deleted](/cloud/aws_network_access_control_list_deleted/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | Anomaly | +| [AWS Network Access Control List Created with All Open Ports](/cloud/aws_network_access_control_list_created_with_all_open_ports/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [AWS Network Access Control List Deleted](/cloud/aws_network_access_control_list_deleted/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | Anomaly | | [Detect Spike in blocked Outbound Traffic from your AWS](/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws/) | | Anomaly | #### Reference diff --git a/docs/_stories/blackmatter_ransomware.md b/docs/_stories/blackmatter_ransomware.md index ad3881edd0..c6dc072cdb 100644 --- a/docs/_stories/blackmatter_ransomware.md +++ b/docs/_stories/blackmatter_ransomware.md @@ -30,8 +30,8 @@ BlackMatter ransomware campaigns targeting healthcare and other vertical sectors | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Add DefaultUser And Password In Registry](/endpoint/add_defaultuser_and_password_in_registry/) | [Credentials in Registry](/tags/#credentials-in-registry) | Anomaly | -| [Auto Admin Logon Registry Entry](/endpoint/auto_admin_logon_registry_entry/) | [Credentials in Registry](/tags/#credentials-in-registry) | TTP | +| [Add DefaultUser And Password In Registry](/endpoint/add_defaultuser_and_password_in_registry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials) | Anomaly | +| [Auto Admin Logon Registry Entry](/endpoint/auto_admin_logon_registry_entry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials) | TTP | | [Bcdedit Command Back To Normal Mode Boot](/endpoint/bcdedit_command_back_to_normal_mode_boot/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Change To Safe Mode With Network Config](/endpoint/change_to_safe_mode_with_network_config/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Known Services Killed by Ransomware](/endpoint/known_services_killed_by_ransomware/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | diff --git a/docs/_stories/clop_ransomware.md b/docs/_stories/clop_ransomware.md index dafc23a2a3..4cfe02190d 100644 --- a/docs/_stories/clop_ransomware.md +++ b/docs/_stories/clop_ransomware.md @@ -34,7 +34,7 @@ Clop ransomware campaigns targeting healthcare and other vertical sectors, invol | [Clop Ransomware Known Service Name](/endpoint/clop_ransomware_known_service_name/) | [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction) | Hunting | -| [Create Service In Suspicious File Path](/endpoint/create_service_in_suspicious_file_path/) | [Service Execution](/tags/#service-execution) | TTP | +| [Create Service In Suspicious File Path](/endpoint/create_service_in_suspicious_file_path/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | TTP | | [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [High File Deletion Frequency](/endpoint/high_file_deletion_frequency/) | [Data Destruction](/tags/#data-destruction) | Anomaly | | [High Process Termination Frequency](/endpoint/high_process_termination_frequency/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | Anomaly | @@ -42,10 +42,10 @@ Clop ransomware campaigns targeting healthcare and other vertical sectors, invol | [Ransomware Notes bulk creation](/endpoint/ransomware_notes_bulk_creation/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | Anomaly | | [Resize ShadowStorage volume](/endpoint/resize_shadowstorage_volume/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Resize Shadowstorage Volume](/endpoint/resize_shadowstorage_volume/) | [Service Stop](/tags/#service-stop) | TTP | -| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [WevtUtil Usage To Clear Logs](/endpoint/wevtutil_usage_to_clear_logs/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | +| [WevtUtil Usage To Clear Logs](/endpoint/wevtutil_usage_to_clear_logs/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | #### Reference diff --git a/docs/_stories/cloud_cryptomining.md b/docs/_stories/cloud_cryptomining.md index 07394ba9a3..5b3567ce17 100644 --- a/docs/_stories/cloud_cryptomining.md +++ b/docs/_stories/cloud_cryptomining.md @@ -34,8 +34,8 @@ This Analytic Story is focused on detecting suspicious new instances in your clo | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Abnormally High Number Of Cloud Instances Launched](/cloud/abnormally_high_number_of_cloud_instances_launched/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | -| [Cloud Compute Instance Created By Previously Unseen User](/cloud/cloud_compute_instance_created_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | +| [Abnormally High Number Of Cloud Instances Launched](/cloud/abnormally_high_number_of_cloud_instances_launched/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | +| [Cloud Compute Instance Created By Previously Unseen User](/cloud/cloud_compute_instance_created_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | | [Cloud Compute Instance Created In Previously Unused Region](/cloud/cloud_compute_instance_created_in_previously_unused_region/) | [Unused/Unsupported Cloud Regions](/tags/#unused/unsupported-cloud-regions) | Anomaly | | [Cloud Compute Instance Created With Previously Unseen Image](/cloud/cloud_compute_instance_created_with_previously_unseen_image/) | | Anomaly | | [Cloud Compute Instance Created With Previously Unseen Instance Type](/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type/) | | Anomaly | diff --git a/docs/_stories/cloud_federated_credential_abuse.md b/docs/_stories/cloud_federated_credential_abuse.md index a9011cd822..f9f7b133cd 100644 --- a/docs/_stories/cloud_federated_credential_abuse.md +++ b/docs/_stories/cloud_federated_credential_abuse.md @@ -34,13 +34,13 @@ This story is composed of detection searches based on endpoint that addresses th | [AWS SAML Access by Provider User and Principal](/cloud/aws_saml_access_by_provider_user_and_principal/) | [Valid Accounts](/tags/#valid-accounts) | Anomaly | | [AWS SAML Update identity provider](/cloud/aws_saml_update_identity_provider/) | [Valid Accounts](/tags/#valid-accounts) | TTP | | [Certutil exe certificate extraction](/endpoint/certutil_exe_certificate_extraction/) | | TTP | -| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory) | TTP | +| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Detect Rare Executables](/endpoint/detect_rare_executables/) | | Anomaly | -| [O365 Add App Role Assignment Grant User](/cloud/o365_add_app_role_assignment_grant_user/) | [Cloud Account](/tags/#cloud-account) | TTP | -| [O365 Added Service Principal](/cloud/o365_added_service_principal/) | [Cloud Account](/tags/#cloud-account) | TTP | +| [O365 Add App Role Assignment Grant User](/cloud/o365_add_app_role_assignment_grant_user/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | +| [O365 Added Service Principal](/cloud/o365_added_service_principal/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | | [O365 Excessive SSO logon errors](/cloud/o365_excessive_sso_logon_errors/) | [Modify Authentication Process](/tags/#modify-authentication-process) | Anomaly | -| [O365 New Federated Domain Added](/cloud/o365_new_federated_domain_added/) | [Cloud Account](/tags/#cloud-account) | TTP | -| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection) | TTP | +| [O365 New Federated Domain Added](/cloud/o365_new_federated_domain_added/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | +| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | #### Reference diff --git a/docs/_stories/cobalt_strike.md b/docs/_stories/cobalt_strike.md index cd97df804b..d3fb679f4f 100644 --- a/docs/_stories/cobalt_strike.md +++ b/docs/_stories/cobalt_strike.md @@ -39,23 +39,23 @@ While investigating a detection related to this Analytic Story, keep in mind the | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Anomalous usage of 7zip](/endpoint/anomalous_usage_of_7zip/) | [Archive via Utility](/tags/#archive-via-utility) | Anomaly | -| [CMD Echo Pipe - Escalation](/endpoint/cmd_echo_pipe_-_escalation/) | [Windows Command Shell](/tags/#windows-command-shell), [Windows Service](/tags/#windows-service) | TTP | +| [Anomalous usage of 7zip](/endpoint/anomalous_usage_of_7zip/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Anomaly | +| [CMD Echo Pipe - Escalation](/endpoint/cmd_echo_pipe_-_escalation/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [Cobalt Strike Named Pipes](/endpoint/cobalt_strike_named_pipes/) | [Process Injection](/tags/#process-injection) | TTP | | [DLLHost with no Command Line Arguments with Network](/endpoint/dllhost_with_no_command_line_arguments_with_network/) | [Process Injection](/tags/#process-injection) | TTP | -| [Detect Regsvr32 Application Control Bypass](/endpoint/detect_regsvr32_application_control_bypass/) | [Regsvr32](/tags/#regsvr32) | TTP | +| [Detect Regsvr32 Application Control Bypass](/endpoint/detect_regsvr32_application_control_bypass/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | TTP | | [GPUpdate with no Command Line Arguments with Network](/endpoint/gpupdate_with_no_command_line_arguments_with_network/) | [Process Injection](/tags/#process-injection) | TTP | -| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [Rundll32](/tags/#rundll32) | TTP | +| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | | [SearchProtocolHost with no Command Line with Network](/endpoint/searchprotocolhost_with_no_command_line_with_network/) | [Process Injection](/tags/#process-injection) | TTP | | [Services Escalate Exe](/endpoint/services_escalate_exe/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Suspicious DLLHost no Command Line Arguments](/endpoint/suspicious_dllhost_no_command_line_arguments/) | [Process Injection](/tags/#process-injection) | TTP | | [Suspicious GPUpdate no Command Line Arguments](/endpoint/suspicious_gpupdate_no_command_line_arguments/) | [Process Injection](/tags/#process-injection) | TTP | -| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | -| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [Rundll32](/tags/#rundll32) | TTP | -| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | TTP | +| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | | [Suspicious SearchProtocolHost no Command Line Arguments](/endpoint/suspicious_searchprotocolhost_no_command_line_arguments/) | [Process Injection](/tags/#process-injection) | TTP | -| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | -| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | +| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | +| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | TTP | #### Reference diff --git a/docs/_stories/collection_and_staging.md b/docs/_stories/collection_and_staging.md index 0f2a54e40c..21dfeff9ce 100644 --- a/docs/_stories/collection_and_staging.md +++ b/docs/_stories/collection_and_staging.md @@ -33,11 +33,11 @@ Use the searches to detect and monitor suspicious behavior related to these acti | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect Renamed 7-Zip](/endpoint/detect_renamed_7-zip/) | [Archive via Utility](/tags/#archive-via-utility) | Hunting | -| [Detect Renamed WinRAR](/endpoint/detect_renamed_winrar/) | [Archive via Utility](/tags/#archive-via-utility) | Hunting | -| [Email files written outside of the Outlook directory](/application/email_files_written_outside_of_the_outlook_directory/) | [Local Email Collection](/tags/#local-email-collection) | TTP | -| [Email servers sending high volume traffic to hosts](/application/email_servers_sending_high_volume_traffic_to_hosts/) | [Remote Email Collection](/tags/#remote-email-collection) | Anomaly | -| [Hosts receiving high volume of network traffic from email server](/network/hosts_receiving_high_volume_of_network_traffic_from_email_server/) | [Remote Email Collection](/tags/#remote-email-collection) | Anomaly | +| [Detect Renamed 7-Zip](/endpoint/detect_renamed_7-zip/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Hunting | +| [Detect Renamed WinRAR](/endpoint/detect_renamed_winrar/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Hunting | +| [Email files written outside of the Outlook directory](/application/email_files_written_outside_of_the_outlook_directory/) | [Email Collection](/tags/#email-collection), [Local Email Collection](/tags/#local-email-collection) | TTP | +| [Email servers sending high volume traffic to hosts](/application/email_servers_sending_high_volume_traffic_to_hosts/) | [Email Collection](/tags/#email-collection), [Remote Email Collection](/tags/#remote-email-collection) | Anomaly | +| [Hosts receiving high volume of network traffic from email server](/network/hosts_receiving_high_volume_of_network_traffic_from_email_server/) | [Remote Email Collection](/tags/#remote-email-collection), [Email Collection](/tags/#email-collection) | Anomaly | | [Suspicious writes to windows Recycle Bin](/endpoint/suspicious_writes_to_windows_recycle_bin/) | [Masquerading](/tags/#masquerading) | TTP | #### Reference diff --git a/docs/_stories/command_and_control.md b/docs/_stories/command_and_control.md index a4eaa25b5b..1a8da8e6b8 100644 --- a/docs/_stories/command_and_control.md +++ b/docs/_stories/command_and_control.md @@ -34,18 +34,18 @@ Because this communication is so critical for an adversary, they often use techn | Name | Technique | Type | | ----------- | ----------- |--------------| | [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | -| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns) | Anomaly | -| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | Anomaly | +| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | Anomaly | +| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | | [Detect Large Outbound ICMP Packets](/network/detect_large_outbound_icmp_packets/) | [Non-Application Layer Protocol](/tags/#non-application-layer-protocol) | TTP | | [Detect Spike in blocked Outbound Traffic from your AWS](/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws/) | | Anomaly | | [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise) | TTP | -| [Excessive DNS Failures](/network/excessive_dns_failures/) | [DNS](/tags/#dns) | Anomaly | +| [Excessive DNS Failures](/network/excessive_dns_failures/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | Anomaly | | [Excessive Usage of NSLOOKUP App](/endpoint/excessive_usage_of_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | -| [Multiple Archive Files Http Post Traffic](/network/multiple_archive_files_http_post_traffic/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | TTP | -| [Plain HTTP POST Exfiltrated Data](/network/plain_http_post_exfiltrated_data/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | TTP | +| [Multiple Archive Files Http Post Traffic](/network/multiple_archive_files_http_post_traffic/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | +| [Plain HTTP POST Exfiltrated Data](/network/plain_http_post_exfiltrated_data/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | | [Prohibited Network Traffic Allowed](/network/prohibited_network_traffic_allowed/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | -| [Protocol or Port Mismatch](/network/protocol_or_port_mismatch/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | Anomaly | -| [TOR Traffic](/network/tor_traffic/) | [Web Protocols](/tags/#web-protocols) | TTP | +| [Protocol or Port Mismatch](/network/protocol_or_port_mismatch/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | +| [TOR Traffic](/network/tor_traffic/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols) | TTP | #### Reference diff --git a/docs/_stories/credential_dumping.md b/docs/_stories/credential_dumping.md index 7fcfc99376..56ce77ddd8 100644 --- a/docs/_stories/credential_dumping.md +++ b/docs/_stories/credential_dumping.md @@ -32,18 +32,18 @@ The detection searches in this Analytic Story monitor access to the Local Securi | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Access LSASS Memory for Dump Creation](/endpoint/access_lsass_memory_for_dump_creation/) | [LSASS Memory](/tags/#lsass-memory) | TTP | +| [Access LSASS Memory for Dump Creation](/endpoint/access_lsass_memory_for_dump_creation/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Applying Stolen Credentials via Mimikatz modules](/endpoint/applying_stolen_credentials_via_mimikatz_modules/) | [Process Injection](/tags/#process-injection), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Access Token Manipulation](/tags/#access-token-manipulation), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Compromise Client Software Binary](/tags/#compromise-client-software-binary), [Modify Authentication Process](/tags/#modify-authentication-process), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | | [Applying Stolen Credentials via PowerSploit modules](/endpoint/applying_stolen_credentials_via_powersploit_modules/) | [Process Injection](/tags/#process-injection), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Access Token Manipulation](/tags/#access-token-manipulation), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Compromise Client Software Binary](/tags/#compromise-client-software-binary), [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | | [Assessment of Credential Strength via DSInternals modules](/endpoint/assessment_of_credential_strength_via_dsinternals_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Account Discovery](/tags/#account-discovery), [Password Policy Discovery](/tags/#password-policy-discovery), [Unsecured Credentials](/tags/#unsecured-credentials), [Credentials from Password Stores](/tags/#credentials-from-password-stores) | TTP | | [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager) | TTP | -| [Create Remote Thread into LSASS](/endpoint/create_remote_thread_into_lsass/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Creation of Shadow Copy](/endpoint/creation_of_shadow_copy/) | [NTDS](/tags/#ntds) | TTP | -| [Creation of Shadow Copy with wmic and powershell](/endpoint/creation_of_shadow_copy_with_wmic_and_powershell/) | [NTDS](/tags/#ntds) | TTP | -| [Creation of lsass Dump with Taskmgr](/endpoint/creation_of_lsass_dump_with_taskmgr/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Credential Dumping via Copy Command from Shadow Copy](/endpoint/credential_dumping_via_copy_command_from_shadow_copy/) | [NTDS](/tags/#ntds) | TTP | -| [Credential Dumping via Symlink to Shadow Copy](/endpoint/credential_dumping_via_symlink_to_shadow_copy/) | [NTDS](/tags/#ntds) | TTP | +| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Create Remote Thread into LSASS](/endpoint/create_remote_thread_into_lsass/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Creation of Shadow Copy](/endpoint/creation_of_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Creation of Shadow Copy with wmic and powershell](/endpoint/creation_of_shadow_copy_with_wmic_and_powershell/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Creation of lsass Dump with Taskmgr](/endpoint/creation_of_lsass_dump_with_taskmgr/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Credential Dumping via Copy Command from Shadow Copy](/endpoint/credential_dumping_via_copy_command_from_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Credential Dumping via Symlink to Shadow Copy](/endpoint/credential_dumping_via_symlink_to_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction indicative of FGDump and CacheDump with s option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction indicative of FGDump and CacheDump with v option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction indicative of Lazagne command line options](/endpoint/credential_extraction_indicative_of_lazagne_command_line_options/) | [OS Credential Dumping](/tags/#os-credential-dumping), [Credentials from Password Stores](/tags/#credentials-from-password-stores) | TTP | @@ -54,19 +54,20 @@ The detection searches in this Analytic Story monitor access to the Local Securi | [Credential Extraction native Microsoft debuggers peek into the kernel](/endpoint/credential_extraction_native_microsoft_debuggers_peek_into_the_kernel/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction native Microsoft debuggers via z command line option](/endpoint/credential_extraction_native_microsoft_debuggers_via_z_command_line_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals](/endpoint/credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Detect Copy of ShadowCopy with Script Block Logging](/endpoint/detect_copy_of_shadowcopy_with_script_block_logging/) | [Security Account Manager](/tags/#security-account-manager) | TTP | -| [Detect Credential Dumping through LSASS access](/endpoint/detect_credential_dumping_through_lsass_access/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Detect Dump LSASS Memory using comsvcs](/endpoint/detect_dump_lsass_memory_using_comsvcs/) | [NTDS](/tags/#ntds) | TTP | -| [Detect Kerberoasting](/endpoint/detect_kerberoasting/) | [Kerberoasting](/tags/#kerberoasting) | TTP | -| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Dump LSASS via procdump](/endpoint/dump_lsass_via_procdump/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Esentutl SAM Copy](/endpoint/esentutl_sam_copy/) | [Security Account Manager](/tags/#security-account-manager) | Hunting | -| [Extraction of Registry Hives](/endpoint/extraction_of_registry_hives/) | [Security Account Manager](/tags/#security-account-manager) | TTP | -| [Ntdsutil Export NTDS](/endpoint/ntdsutil_export_ntds/) | [NTDS](/tags/#ntds) | TTP | -| [SAM Database File Access Attempt](/endpoint/sam_database_file_access_attempt/) | [Security Account Manager](/tags/#security-account-manager) | Hunting | -| [SecretDumps Offline NTDS Dumping Tool](/endpoint/secretdumps_offline_ntds_dumping_tool/) | [NTDS](/tags/#ntds) | TTP | -| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [PowerShell](/tags/#powershell) | TTP | +| [Detect Copy of ShadowCopy with Script Block Logging](/endpoint/detect_copy_of_shadowcopy_with_script_block_logging/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Detect Credential Dumping through LSASS access](/endpoint/detect_credential_dumping_through_lsass_access/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Detect Dump LSASS Memory using comsvcs](/endpoint/detect_dump_lsass_memory_using_comsvcs/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Detect Kerberoasting](/endpoint/detect_kerberoasting/) | [Kerberoasting](/tags/#kerberoasting), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | +| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Dump LSASS via procdump](/endpoint/dump_lsass_via_procdump/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Enable WDigest UseLogonCredential Registry](/endpoint/enable_wdigest_uselogoncredential_registry/) | [Modify Registry](/tags/#modify-registry), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Esentutl SAM Copy](/endpoint/esentutl_sam_copy/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | Hunting | +| [Extraction of Registry Hives](/endpoint/extraction_of_registry_hives/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Ntdsutil Export NTDS](/endpoint/ntdsutil_export_ntds/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [SAM Database File Access Attempt](/endpoint/sam_database_file_access_attempt/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | Hunting | +| [SecretDumps Offline NTDS Dumping Tool](/endpoint/secretdumps_offline_ntds_dumping_tool/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | #### Reference diff --git a/docs/_stories/darkside_ransomware.md b/docs/_stories/darkside_ransomware.md index 230791d807..95ab2cb837 100644 --- a/docs/_stories/darkside_ransomware.md +++ b/docs/_stories/darkside_ransomware.md @@ -30,22 +30,22 @@ This story addresses Darkside ransomware. This ransomware payload has many simil | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager) | TTP | +| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [BITSAdmin Download File](/endpoint/bitsadmin_download_file/) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | -| [CMLUA Or CMSTPLUA UAC Bypass](/endpoint/cmlua_or_cmstplua_uac_bypass/) | [CMSTP](/tags/#cmstp) | TTP | +| [CMLUA Or CMSTPLUA UAC Bypass](/endpoint/cmlua_or_cmstplua_uac_bypass/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | TTP | | [CertUtil Download With URLCache and Split Arguments](/endpoint/certutil_download_with_urlcache_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [CertUtil Download With VerifyCtl and Split Arguments](/endpoint/certutil_download_with_verifyctl_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [Cobalt Strike Named Pipes](/endpoint/cobalt_strike_named_pipes/) | [Process Injection](/tags/#process-injection) | TTP | | [Delete ShadowCopy With PowerShell](/endpoint/delete_shadowcopy_with_powershell/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | -| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | | [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration) | TTP | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [Service Execution](/tags/#service-execution) | Hunting | +| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Hunting | | [Detect Renamed RClone](/endpoint/detect_renamed_rclone/) | [Automated Exfiltration](/tags/#automated-exfiltration) | Hunting | -| [Extraction of Registry Hives](/endpoint/extraction_of_registry_hives/) | [Security Account Manager](/tags/#security-account-manager) | TTP | +| [Extraction of Registry Hives](/endpoint/extraction_of_registry_hives/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Ransomware Notes bulk creation](/endpoint/ransomware_notes_bulk_creation/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | Anomaly | -| [SLUI RunAs Elevated](/endpoint/slui_runas_elevated/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [SLUI Spawning a Process](/endpoint/slui_spawning_a_process/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | +| [SLUI RunAs Elevated](/endpoint/slui_runas_elevated/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [SLUI Spawning a Process](/endpoint/slui_spawning_a_process/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | #### Reference diff --git a/docs/_stories/data_exfiltration.md b/docs/_stories/data_exfiltration.md index 3a55d9d6e4..501a0b2c96 100644 --- a/docs/_stories/data_exfiltration.md +++ b/docs/_stories/data_exfiltration.md @@ -35,12 +35,12 @@ Exfiltration comes in many flavors. Adversaries can collect data over encrypted | [Detect SNICat SNI Exfiltration](/network/detect_snicat_sni_exfiltration/) | [Exfiltration Over C2 Channel](/tags/#exfiltration-over-c2-channel) | TTP | | [Detect shared ec2 snapshot](/cloud/detect_shared_ec2_snapshot/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | TTP | | [Excessive Usage of NSLOOKUP App](/endpoint/excessive_usage_of_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | -| [Mailsniper Invoke functions](/endpoint/mailsniper_invoke_functions/) | [Local Email Collection](/tags/#local-email-collection) | TTP | -| [Multiple Archive Files Http Post Traffic](/network/multiple_archive_files_http_post_traffic/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | TTP | +| [Mailsniper Invoke functions](/endpoint/mailsniper_invoke_functions/) | [Email Collection](/tags/#email-collection), [Local Email Collection](/tags/#local-email-collection) | TTP | +| [Multiple Archive Files Http Post Traffic](/network/multiple_archive_files_http_post_traffic/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | | [O365 PST export alert](/cloud/o365_pst_export_alert/) | [Email Collection](/tags/#email-collection) | TTP | -| [O365 Suspicious Admin Email Forwarding](/cloud/o365_suspicious_admin_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule) | Anomaly | -| [O365 Suspicious User Email Forwarding](/cloud/o365_suspicious_user_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule) | Anomaly | -| [Plain HTTP POST Exfiltrated Data](/network/plain_http_post_exfiltrated_data/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | TTP | +| [O365 Suspicious Admin Email Forwarding](/cloud/o365_suspicious_admin_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection) | Anomaly | +| [O365 Suspicious User Email Forwarding](/cloud/o365_suspicious_user_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection) | Anomaly | +| [Plain HTTP POST Exfiltrated Data](/network/plain_http_post_exfiltrated_data/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | #### Reference diff --git a/docs/_stories/detect_zerologon_attack.md b/docs/_stories/detect_zerologon_attack.md index 82dfa2f05f..e62dfd6a5b 100644 --- a/docs/_stories/detect_zerologon_attack.md +++ b/docs/_stories/detect_zerologon_attack.md @@ -30,8 +30,8 @@ This attack is a privilege escalation technique, where attacker targets a Netlog | Name | Technique | Type | | ----------- | ----------- |--------------| | [Detect Computer Changed with Anonymous Account](/endpoint/detect_computer_changed_with_anonymous_account/) | [Exploitation of Remote Services](/tags/#exploitation-of-remote-services) | Hunting | -| [Detect Credential Dumping through LSASS access](/endpoint/detect_credential_dumping_through_lsass_access/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory) | TTP | +| [Detect Credential Dumping through LSASS access](/endpoint/detect_credential_dumping_through_lsass_access/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Detect Zerologon via Zeek](/network/detect_zerologon_via_zeek/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | TTP | #### Reference diff --git a/docs/_stories/dev_sec_ops.md b/docs/_stories/dev_sec_ops.md index dd55092a7b..591480ea30 100644 --- a/docs/_stories/dev_sec_ops.md +++ b/docs/_stories/dev_sec_ops.md @@ -30,17 +30,25 @@ DevSecOps is a collaborative framework, which thinks about application and infra | Name | Technique | Type | | ----------- | ----------- |--------------| -| [AWS ECR Container Scanning Findings High](/cloud/aws_ecr_container_scanning_findings_high/) | [Malicious Image](/tags/#malicious-image) | TTP | -| [AWS ECR Container Scanning Findings Low Informational Unknown](/cloud/aws_ecr_container_scanning_findings_low_informational_unknown/) | [Malicious Image](/tags/#malicious-image) | Hunting | -| [AWS ECR Container Scanning Findings Medium](/cloud/aws_ecr_container_scanning_findings_medium/) | [Malicious Image](/tags/#malicious-image) | Anomaly | -| [AWS ECR Container Upload Outside Business Hours](/cloud/aws_ecr_container_upload_outside_business_hours/) | [Malicious Image](/tags/#malicious-image) | Anomaly | -| [AWS ECR Container Upload Unknown User](/cloud/aws_ecr_container_upload_unknown_user/) | [Malicious Image](/tags/#malicious-image) | Anomaly | +| [AWS ECR Container Scanning Findings High](/cloud/aws_ecr_container_scanning_findings_high/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | TTP | +| [AWS ECR Container Scanning Findings Low Informational Unknown](/cloud/aws_ecr_container_scanning_findings_low_informational_unknown/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Hunting | +| [AWS ECR Container Scanning Findings Medium](/cloud/aws_ecr_container_scanning_findings_medium/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Anomaly | +| [AWS ECR Container Upload Outside Business Hours](/cloud/aws_ecr_container_upload_outside_business_hours/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Anomaly | +| [AWS ECR Container Upload Unknown User](/cloud/aws_ecr_container_upload_unknown_user/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Anomaly | | [Circle CI Disable Security Job](/cloud/circle_ci_disable_security_job/) | [Compromise Client Software Binary](/tags/#compromise-client-software-binary) | Anomaly | | [Circle CI Disable Security Step](/cloud/circle_ci_disable_security_step/) | [Compromise Client Software Binary](/tags/#compromise-client-software-binary) | Anomaly | -| [Correlation by Repository and Risk](/cloud/correlation_by_repository_and_risk/) | [Malicious Image](/tags/#malicious-image) | Correlation | -| [Correlation by User and Risk](/cloud/correlation_by_user_and_risk/) | [Malicious Image](/tags/#malicious-image) | Correlation | -| [GitHub Dependabot Alert](/cloud/github_dependabot_alert/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools) | Anomaly | -| [GitHub Pull Request from Unknown User](/cloud/github_pull_request_from_unknown_user/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools) | Anomaly | +| [Correlation by Repository and Risk](/cloud/correlation_by_repository_and_risk/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Correlation | +| [Correlation by User and Risk](/cloud/correlation_by_user_and_risk/) | [Malicious Image](/tags/#malicious-image), [User Execution](/tags/#user-execution) | Correlation | +| [GSuite Email Suspicious Attachment](/cloud/gsuite_email_suspicious_attachment/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | +| [GitHub Dependabot Alert](/cloud/github_dependabot_alert/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools), [Supply Chain Compromise](/tags/#supply-chain-compromise) | Anomaly | +| [GitHub Pull Request from Unknown User](/cloud/github_pull_request_from_unknown_user/) | [Compromise Software Dependencies and Development Tools](/tags/#compromise-software-dependencies-and-development-tools), [Supply Chain Compromise](/tags/#supply-chain-compromise) | Anomaly | +| [Github Commit Changes In Master](/cloud/github_commit_changes_in_master/) | [Trusted Relationship](/tags/#trusted-relationship) | Anomaly | +| [Github Commit In Develop](/cloud/github_commit_in_develop/) | [Trusted Relationship](/tags/#trusted-relationship) | Anomaly | +| [Gsuite Drive Share In External Email](/cloud/gsuite_drive_share_in_external_email/) | [Exfiltration to Cloud Storage](/tags/#exfiltration-to-cloud-storage), [Exfiltration Over Web Service](/tags/#exfiltration-over-web-service) | Anomaly | +| [Gsuite Email Suspicious Subject With Attachment](/cloud/gsuite_email_suspicious_subject_with_attachment/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | +| [Gsuite Email With Known Abuse Web Service Link](/cloud/gsuite_email_with_known_abuse_web_service_link/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | +| [Gsuite Outbound Email With Attachment To External Domain](/cloud/gsuite_outbound_email_with_attachment_to_external_domain/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | +| [Gsuite Suspicious Shared File Name](/cloud/gsuite_suspicious_shared_file_name/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | | [Kubernetes Nginx Ingress LFI](/cloud/kubernetes_nginx_ingress_lfi/) | [Exploitation for Credential Access](/tags/#exploitation-for-credential-access) | TTP | | [Kubernetes Nginx Ingress RFI](/cloud/kubernetes_nginx_ingress_rfi/) | [Exploitation for Credential Access](/tags/#exploitation-for-credential-access) | TTP | | [Kubernetes Scanner Image Pulling](/cloud/kubernetes_scanner_image_pulling/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | TTP | diff --git a/docs/_stories/dhs_report_ta18-074a.md b/docs/_stories/dhs_report_ta18-074a.md index be50653f90..44c93c2e37 100644 --- a/docs/_stories/dhs_report_ta18-074a.md +++ b/docs/_stories/dhs_report_ta18-074a.md @@ -34,19 +34,19 @@ Suspicious activities--spikes in SMB traffic, processes that launch netsh (to mo | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Create local admin accounts using net exe](/endpoint/create_local_admin_accounts_using_net_exe/) | [Local Account](/tags/#local-account) | TTP | -| [Detect New Local Admin account](/endpoint/detect_new_local_admin_account/) | [Local Account](/tags/#local-account) | TTP | -| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols) | TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [Service Execution](/tags/#service-execution) | Hunting | -| [Malicious PowerShell Process - Execution Policy Bypass](/endpoint/malicious_powershell_process_-_execution_policy_bypass/) | [PowerShell](/tags/#powershell) | TTP | -| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall) | TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | -| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | Anomaly | -| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | Anomaly | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service) | TTP | -| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task) | TTP | -| [Single Letter Process On Endpoint](/endpoint/single_letter_process_on_endpoint/) | [Malicious File](/tags/#malicious-file) | TTP | +| [Create local admin accounts using net exe](/endpoint/create_local_admin_accounts_using_net_exe/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account) | TTP | +| [Detect New Local Admin account](/endpoint/detect_new_local_admin_account/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account) | TTP | +| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol) | TTP | +| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Hunting | +| [Malicious PowerShell Process - Execution Policy Bypass](/endpoint/malicious_powershell_process_-_execution_policy_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | Anomaly | +| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | Anomaly | +| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | +| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [Single Letter Process On Endpoint](/endpoint/single_letter_process_on_endpoint/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file) | TTP | | [Suspicious Reg exe Process](/endpoint/suspicious_reg_exe_process/) | [Modify Registry](/tags/#modify-registry) | TTP | #### Reference diff --git a/docs/_stories/disabling_security_tools.md b/docs/_stories/disabling_security_tools.md index 5bb9d0a846..f0069a852f 100644 --- a/docs/_stories/disabling_security_tools.md +++ b/docs/_stories/disabling_security_tools.md @@ -30,12 +30,12 @@ Attackers employ a variety of tactics in order to avoid detection and operate wi | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Attempt To Add Certificate To Untrusted Store](/endpoint/attempt_to_add_certificate_to_untrusted_store/) | [Install Root Certificate](/tags/#install-root-certificate) | TTP | -| [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall) | TTP | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service) | TTP | +| [Attempt To Add Certificate To Untrusted Store](/endpoint/attempt_to_add_certificate_to_untrusted_store/) | [Install Root Certificate](/tags/#install-root-certificate), [Subvert Trust Controls](/tags/#subvert-trust-controls) | TTP | +| [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [Suspicious Reg exe Process](/endpoint/suspicious_reg_exe_process/) | [Modify Registry](/tags/#modify-registry) | TTP | -| [Unload Sysmon Filter Driver](/endpoint/unload_sysmon_filter_driver/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Unload Sysmon Filter Driver](/endpoint/unload_sysmon_filter_driver/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | #### Reference diff --git a/docs/_stories/dns_amplification_attacks.md b/docs/_stories/dns_amplification_attacks.md index 81bfca4696..20cbc0f0fa 100644 --- a/docs/_stories/dns_amplification_attacks.md +++ b/docs/_stories/dns_amplification_attacks.md @@ -31,7 +31,7 @@ The search in this story can help you to detect if attackers are abusing your co | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Large Volume of DNS ANY Queries](/network/large_volume_of_dns_any_queries/) | [Reflection Amplification](/tags/#reflection-amplification) | Anomaly | +| [Large Volume of DNS ANY Queries](/network/large_volume_of_dns_any_queries/) | [Network Denial of Service](/tags/#network-denial-of-service), [Reflection Amplification](/tags/#reflection-amplification) | Anomaly | #### Reference diff --git a/docs/_stories/emotet_malware__dhs_report_ta18-201a_.md b/docs/_stories/emotet_malware__dhs_report_ta18-201a_.md index f6a61bd541..6558b3ffe4 100644 --- a/docs/_stories/emotet_malware__dhs_report_ta18-201a_.md +++ b/docs/_stories/emotet_malware__dhs_report_ta18-201a_.md @@ -35,13 +35,13 @@ The searches in this Analytic Story will help you find executables that are rare | Name | Technique | Type | | ----------- | ----------- |--------------| | [Detect Rare Executables](/endpoint/detect_rare_executables/) | | Anomaly | -| [Detect Use of cmd exe to Launch Script Interpreters](/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters/) | [Windows Command Shell](/tags/#windows-command-shell) | TTP | +| [Detect Use of cmd exe to Launch Script Interpreters](/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | TTP | | [Detection of tools built by NirSoft](/endpoint/detection_of_tools_built_by_nirsoft/) | [Software Deployment Tools](/tags/#software-deployment-tools) | TTP | | [Email Attachments With Lots Of Spaces](/application/email_attachments_with_lots_of_spaces/) | | Anomaly | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | -| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | Anomaly | -| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | Anomaly | -| [Suspicious Email Attachment Extensions](/application/suspicious_email_attachment_extensions/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | Anomaly | +| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | Anomaly | +| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | Anomaly | +| [Suspicious Email Attachment Extensions](/application/suspicious_email_attachment_extensions/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | #### Reference diff --git a/docs/_stories/fin7.md b/docs/_stories/fin7.md index d73fff95c4..8169adafd2 100644 --- a/docs/_stories/fin7.md +++ b/docs/_stories/fin7.md @@ -31,14 +31,16 @@ FIN7 is a Russian criminal advanced persistent threat group that has primarily t | Name | Technique | Type | | ----------- | ----------- |--------------| | [Check Elevated CMD using whoami](/endpoint/check_elevated_cmd_using_whoami/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | TTP | -| [Cmdline Tool Not Executed In CMD Shell](/endpoint/cmdline_tool_not_executed_in_cmd_shell/) | [JavaScript](/tags/#javascript) | TTP | -| [Jscript Execution Using Cscript App](/endpoint/jscript_execution_using_cscript_app/) | [JavaScript](/tags/#javascript) | TTP | -| [MS Scripting Process Loading Ldap Module](/endpoint/ms_scripting_process_loading_ldap_module/) | [JavaScript](/tags/#javascript) | Anomaly | -| [MS Scripting Process Loading WMI Module](/endpoint/ms_scripting_process_loading_wmi_module/) | [JavaScript](/tags/#javascript) | Anomaly | -| [Non Chrome Process Accessing Chrome Default Dir](/endpoint/non_chrome_process_accessing_chrome_default_dir/) | [Credentials from Web Browsers](/tags/#credentials-from-web-browsers) | Anomaly | -| [Non Firefox Process Access Firefox Profile Dir](/endpoint/non_firefox_process_access_firefox_profile_dir/) | [Credentials from Web Browsers](/tags/#credentials-from-web-browsers) | Anomaly | -| [Office Application Drop Executable](/endpoint/office_application_drop_executable/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawning Wmic](/endpoint/office_product_spawning_wmic/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Cmdline Tool Not Executed In CMD Shell](/endpoint/cmdline_tool_not_executed_in_cmd_shell/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | TTP | +| [Jscript Execution Using Cscript App](/endpoint/jscript_execution_using_cscript_app/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | TTP | +| [MS Scripting Process Loading Ldap Module](/endpoint/ms_scripting_process_loading_ldap_module/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | Anomaly | +| [MS Scripting Process Loading WMI Module](/endpoint/ms_scripting_process_loading_wmi_module/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | Anomaly | +| [Non Chrome Process Accessing Chrome Default Dir](/endpoint/non_chrome_process_accessing_chrome_default_dir/) | [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers) | Anomaly | +| [Non Firefox Process Access Firefox Profile Dir](/endpoint/non_firefox_process_access_firefox_profile_dir/) | [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers) | Anomaly | +| [Office Application Drop Executable](/endpoint/office_application_drop_executable/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawning Wmic](/endpoint/office_product_spawning_wmic/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Vbscript Execution Using Wscript App](/endpoint/vbscript_execution_using_wscript_app/) | [Visual Basic](/tags/#visual-basic), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | TTP | +| [Wscript Or Cscript Suspicious Child Process](/endpoint/wscript_or_cscript_suspicious_child_process/) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation) | TTP | | [XSL Script Execution With WMIC](/endpoint/xsl_script_execution_with_wmic/) | [XSL Script Processing](/tags/#xsl-script-processing) | TTP | #### Reference diff --git a/docs/_stories/hafnium_group.md b/docs/_stories/hafnium_group.md index cf3bc9c9da..6d3a1a8b13 100644 --- a/docs/_stories/hafnium_group.md +++ b/docs/_stories/hafnium_group.md @@ -33,21 +33,21 @@ The following Splunk detections assist with identifying the HAFNIUM groups trade | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [PowerShell](/tags/#powershell) | TTP | -| [Detect Exchange Web Shell](/endpoint/detect_exchange_web_shell/) | [Web Shell](/tags/#web-shell) | TTP | -| [Detect New Local Admin account](/endpoint/detect_new_local_admin_account/) | [Local Account](/tags/#local-account) | TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [Service Execution](/tags/#service-execution) | Hunting | -| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Dump LSASS via procdump](/endpoint/dump_lsass_via_procdump/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Email servers sending high volume traffic to hosts](/application/email_servers_sending_high_volume_traffic_to_hosts/) | [Remote Email Collection](/tags/#remote-email-collection) | Anomaly | -| [Malicious PowerShell Process - Connect To Internet With Hidden Window](/endpoint/malicious_powershell_process_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell) | Hunting | -| [Malicious PowerShell Process - Execution Policy Bypass](/endpoint/malicious_powershell_process_-_execution_policy_bypass/) | [PowerShell](/tags/#powershell) | TTP | -| [Nishang PowershellTCPOneLine](/endpoint/nishang_powershelltcponeline/) | [PowerShell](/tags/#powershell) | TTP | -| [Ntdsutil Export NTDS](/endpoint/ntdsutil_export_ntds/) | [NTDS](/tags/#ntds) | TTP | -| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [PowerShell](/tags/#powershell) | TTP | +| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Detect Exchange Web Shell](/endpoint/detect_exchange_web_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | TTP | +| [Detect New Local Admin account](/endpoint/detect_new_local_admin_account/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account) | TTP | +| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Hunting | +| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Dump LSASS via procdump](/endpoint/dump_lsass_via_procdump/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Email servers sending high volume traffic to hosts](/application/email_servers_sending_high_volume_traffic_to_hosts/) | [Email Collection](/tags/#email-collection), [Remote Email Collection](/tags/#remote-email-collection) | Anomaly | +| [Malicious PowerShell Process - Connect To Internet With Hidden Window](/endpoint/malicious_powershell_process_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | Hunting | +| [Malicious PowerShell Process - Execution Policy Bypass](/endpoint/malicious_powershell_process_-_execution_policy_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Nishang PowershellTCPOneLine](/endpoint/nishang_powershelltcponeline/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Ntdsutil Export NTDS](/endpoint/ntdsutil_export_ntds/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Unified Messaging Service Spawning a Process](/endpoint/unified_messaging_service_spawning_a_process/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | TTP | -| [W3WP Spawning Shell](/endpoint/w3wp_spawning_shell/) | [Web Shell](/tags/#web-shell) | TTP | +| [W3WP Spawning Shell](/endpoint/w3wp_spawning_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | TTP | #### Reference diff --git a/docs/_stories/hidden_cobra_malware.md b/docs/_stories/hidden_cobra_malware.md index 1a7f8130ab..309ad02f0c 100644 --- a/docs/_stories/hidden_cobra_malware.md +++ b/docs/_stories/hidden_cobra_malware.md @@ -35,14 +35,14 @@ Among other searches in this Analytic Story is a detection search that looks for | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Create or delete windows shares using net exe](/endpoint/create_or_delete_windows_shares_using_net_exe/) | [Network Share Connection Removal](/tags/#network-share-connection-removal) | TTP | -| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns) | Anomaly | -| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | Anomaly | -| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols) | TTP | -| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | Anomaly | -| [Remote Desktop Process Running On System](/endpoint/remote_desktop_process_running_on_system/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | Hunting | -| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | Anomaly | -| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | Anomaly | +| [Create or delete windows shares using net exe](/endpoint/create_or_delete_windows_shares_using_net_exe/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Network Share Connection Removal](/tags/#network-share-connection-removal) | TTP | +| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | Anomaly | +| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | +| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol) | TTP | +| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Anomaly | +| [Remote Desktop Process Running On System](/endpoint/remote_desktop_process_running_on_system/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Hunting | +| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | Anomaly | +| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | Anomaly | #### Reference diff --git a/docs/_stories/icedid.md b/docs/_stories/icedid.md index 6fb742cf7b..c85e6a9f66 100644 --- a/docs/_stories/icedid.md +++ b/docs/_stories/icedid.md @@ -30,30 +30,30 @@ IcedId banking trojan campaigns targeting banks and other vertical sectors.This | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Account Discovery With Net App](/endpoint/account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account) | TTP | +| [Account Discovery With Net App](/endpoint/account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | | [CHCP Command Execution](/endpoint/chcp_command_execution/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | TTP | | [Create Remote Thread In Shell Application](/endpoint/create_remote_thread_in_shell_application/) | [Process Injection](/tags/#process-injection) | TTP | -| [Drop IcedID License dat](/endpoint/drop_icedid_license_dat/) | [Malicious File](/tags/#malicious-file) | Hunting | -| [Eventvwr UAC Bypass](/endpoint/eventvwr_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [IcedID Exfiltrated Archived File Creation](/endpoint/icedid_exfiltrated_archived_file_creation/) | [Archive via Utility](/tags/#archive-via-utility) | Hunting | -| [Mshta spawning Rundll32 OR Regsvr32 Process](/endpoint/mshta_spawning_rundll32_or_regsvr32_process/) | [Mshta](/tags/#mshta) | TTP | +| [Drop IcedID License dat](/endpoint/drop_icedid_license_dat/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file) | Hunting | +| [Eventvwr UAC Bypass](/endpoint/eventvwr_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [IcedID Exfiltrated Archived File Creation](/endpoint/icedid_exfiltrated_archived_file_creation/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Hunting | +| [Mshta spawning Rundll32 OR Regsvr32 Process](/endpoint/mshta_spawning_rundll32_or_regsvr32_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | | [NLTest Domain Trust Discovery](/endpoint/nltest_domain_trust_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | -| [Office Application Spawn Regsvr32 process](/endpoint/office_application_spawn_regsvr32_process/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawning MSHTA](/endpoint/office_product_spawning_mshta/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | +| [Office Application Spawn Regsvr32 process](/endpoint/office_application_spawn_regsvr32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawning MSHTA](/endpoint/office_product_spawning_mshta/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Rundll32 Create Remote Thread To A Process](/endpoint/rundll32_create_remote_thread_to_a_process/) | [Process Injection](/tags/#process-injection) | TTP | | [Rundll32 CreateRemoteThread In Browser](/endpoint/rundll32_createremotethread_in_browser/) | [Process Injection](/tags/#process-injection) | TTP | -| [Rundll32 DNSQuery](/endpoint/rundll32_dnsquery/) | [Rundll32](/tags/#rundll32) | TTP | -| [Rundll32 Process Creating Exe Dll Files](/endpoint/rundll32_process_creating_exe_dll_files/) | [Rundll32](/tags/#rundll32) | TTP | +| [Rundll32 DNSQuery](/endpoint/rundll32_dnsquery/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Rundll32 Process Creating Exe Dll Files](/endpoint/rundll32_process_creating_exe_dll_files/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | | [Schedule Task with Rundll32 Command Trigger](/endpoint/schedule_task_with_rundll32_command_trigger/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | | [Sqlite Module In Temp Folder](/endpoint/sqlite_module_in_temp_folder/) | [Data from Local System](/tags/#data-from-local-system) | TTP | -| [Suspicious IcedID Regsvr32 Cmdline](/endpoint/suspicious_icedid_regsvr32_cmdline/) | [Regsvr32](/tags/#regsvr32) | TTP | -| [Suspicious IcedID Rundll32 Cmdline](/endpoint/suspicious_icedid_rundll32_cmdline/) | [Rundll32](/tags/#rundll32) | TTP | -| [Suspicious Rundll32 PluginInit](/endpoint/suspicious_rundll32_plugininit/) | [Rundll32](/tags/#rundll32) | TTP | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task) | TTP | +| [Suspicious IcedID Regsvr32 Cmdline](/endpoint/suspicious_icedid_regsvr32_cmdline/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | TTP | +| [Suspicious IcedID Rundll32 Cmdline](/endpoint/suspicious_icedid_rundll32_cmdline/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious Rundll32 PluginInit](/endpoint/suspicious_rundll32_plugininit/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | #### Reference diff --git a/docs/_stories/ingress_tool_transfer.md b/docs/_stories/ingress_tool_transfer.md index 2f10eee4b7..5db1b3f1de 100644 --- a/docs/_stories/ingress_tool_transfer.md +++ b/docs/_stories/ingress_tool_transfer.md @@ -30,8 +30,8 @@ Ingress tool transfer is a Technique under tactic Command and Control. Behaviors | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [PowerShell](/tags/#powershell) | TTP | -| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [PowerShell](/tags/#powershell) | TTP | +| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [BITSAdmin Download File](/endpoint/bitsadmin_download_file/) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [CertUtil Download With URLCache and Split Arguments](/endpoint/certutil_download_with_urlcache_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [CertUtil Download With VerifyCtl and Split Arguments](/endpoint/certutil_download_with_verifyctl_and_split_arguments/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | diff --git a/docs/_stories/lateral_movement.md b/docs/_stories/lateral_movement.md index f38f1ba842..0b4c8f3fc8 100644 --- a/docs/_stories/lateral_movement.md +++ b/docs/_stories/lateral_movement.md @@ -35,16 +35,16 @@ If there is evidence of lateral movement, it is imperative for analysts to colle | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect Activity Related to Pass the Hash Attacks](/endpoint/detect_activity_related_to_pass_the_hash_attacks/) | [Pass the Hash](/tags/#pass-the-hash) | TTP | -| [Detect Pass the Hash](/endpoint/detect_pass_the_hash/) | [Pass the Hash](/tags/#pass-the-hash) | TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [Service Execution](/tags/#service-execution) | Hunting | -| [Kerberoasting spn request with RC4 encryption](/endpoint/kerberoasting_spn_request_with_rc4_encryption/) | [Kerberoasting](/tags/#kerberoasting) | TTP | -| [Potential Pass the Token or Hash Observed at the Destination Device](/endpoint/potential_pass_the_token_or_hash_observed_at_the_destination_device/) | [Pass the Hash](/tags/#pass-the-hash) | TTP | -| [Potential Pass the Token or Hash Observed by an Event Collecting Device](/endpoint/potential_pass_the_token_or_hash_observed_by_an_event_collecting_device/) | [Pass the Hash](/tags/#pass-the-hash) | TTP | -| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | Anomaly | -| [Remote Desktop Process Running On System](/endpoint/remote_desktop_process_running_on_system/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | Hunting | -| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task) | TTP | +| [Detect Activity Related to Pass the Hash Attacks](/endpoint/detect_activity_related_to_pass_the_hash_attacks/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [Detect Pass the Hash](/endpoint/detect_pass_the_hash/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Hunting | +| [Kerberoasting spn request with RC4 encryption](/endpoint/kerberoasting_spn_request_with_rc4_encryption/) | [Kerberoasting](/tags/#kerberoasting), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | +| [Potential Pass the Token or Hash Observed at the Destination Device](/endpoint/potential_pass_the_token_or_hash_observed_at_the_destination_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [Potential Pass the Token or Hash Observed by an Event Collecting Device](/endpoint/potential_pass_the_token_or_hash_observed_by_an_event_collecting_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Anomaly | +| [Remote Desktop Process Running On System](/endpoint/remote_desktop_process_running_on_system/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Hunting | +| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | #### Reference diff --git a/docs/_stories/malicious_powershell.md b/docs/_stories/malicious_powershell.md index be85b9e892..8a20104c07 100644 --- a/docs/_stories/malicious_powershell.md +++ b/docs/_stories/malicious_powershell.md @@ -41,33 +41,33 @@ Most recently we have added new content related to PowerShell Script Block loggi | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [PowerShell](/tags/#powershell) | TTP | -| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [PowerShell](/tags/#powershell) | TTP | +| [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Credential Extraction indicative of use of DSInternals credential conversion modules](/endpoint/credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction indicative of use of DSInternals modules](/endpoint/credential_extraction_indicative_of_use_of_dsinternals_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction indicative of use of PowerSploit modules](/endpoint/credential_extraction_indicative_of_use_of_powersploit_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals](/endpoint/credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Detect Empire with PowerShell Script Block Logging](/endpoint/detect_empire_with_powershell_script_block_logging/) | [PowerShell](/tags/#powershell) | TTP | +| [Detect Empire with PowerShell Script Block Logging](/endpoint/detect_empire_with_powershell_script_block_logging/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Detect Mimikatz With PowerShell Script Block Logging](/endpoint/detect_mimikatz_with_powershell_script_block_logging/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Illegal Access To User Content via PowerSploit modules](/endpoint/illegal_access_to_user_content_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Screen Capture](/tags/#screen-capture), [Audio Capture](/tags/#audio-capture), [Remote Service Session Hijacking](/tags/#remote-service-session-hijacking) | TTP | | [Illegal Privilege Elevation and Persistence via PowerSploit modules](/endpoint/illegal_privilege_elevation_and_persistence_via_powersploit_modules/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Access Token Manipulation](/tags/#access-token-manipulation), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Illegal Service and Process Control via PowerSploit modules](/endpoint/illegal_service_and_process_control_via_powersploit_modules/) | [Process Injection](/tags/#process-injection), [Native API](/tags/#native-api), [System Services](/tags/#system-services) | TTP | -| [Malicious PowerShell Process - Connect To Internet With Hidden Window](/endpoint/malicious_powershell_process_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell) | Hunting | +| [Malicious PowerShell Process - Connect To Internet With Hidden Window](/endpoint/malicious_powershell_process_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | Hunting | | [Malicious PowerShell Process - Encoded Command](/endpoint/malicious_powershell_process_-_encoded_command/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information) | Hunting | -| [Malicious PowerShell Process With Obfuscation Techniques](/endpoint/malicious_powershell_process_with_obfuscation_techniques/) | [PowerShell](/tags/#powershell) | TTP | -| [PowerShell 4104 Hunting](/endpoint/powershell_4104_hunting/) | [PowerShell](/tags/#powershell) | Hunting | -| [PowerShell Domain Enumeration](/endpoint/powershell_domain_enumeration/) | [PowerShell](/tags/#powershell) | TTP | -| [PowerShell Loading DotNET into Memory via System Reflection Assembly](/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly/) | [PowerShell](/tags/#powershell) | TTP | -| [Powershell Creating Thread Mutex](/endpoint/powershell_creating_thread_mutex/) | [Indicator Removal from Tools](/tags/#indicator-removal-from-tools) | TTP | -| [Powershell Enable SMB1Protocol Feature](/endpoint/powershell_enable_smb1protocol_feature/) | [Indicator Removal from Tools](/tags/#indicator-removal-from-tools) | TTP | -| [Powershell Execute COM Object](/endpoint/powershell_execute_com_object/) | [Component Object Model Hijacking](/tags/#component-object-model-hijacking) | TTP | -| [Powershell Fileless Process Injection via GetProcAddress](/endpoint/powershell_fileless_process_injection_via_getprocaddress/) | [Process Injection](/tags/#process-injection), [PowerShell](/tags/#powershell) | TTP | -| [Powershell Fileless Script Contains Base64 Encoded Content](/endpoint/powershell_fileless_script_contains_base64_encoded_content/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [PowerShell](/tags/#powershell) | TTP | -| [Powershell Processing Stream Of Data](/endpoint/powershell_processing_stream_of_data/) | [PowerShell](/tags/#powershell) | TTP | +| [Malicious PowerShell Process With Obfuscation Techniques](/endpoint/malicious_powershell_process_with_obfuscation_techniques/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [PowerShell 4104 Hunting](/endpoint/powershell_4104_hunting/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | Hunting | +| [PowerShell Domain Enumeration](/endpoint/powershell_domain_enumeration/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [PowerShell Loading DotNET into Memory via System Reflection Assembly](/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Powershell Creating Thread Mutex](/endpoint/powershell_creating_thread_mutex/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools) | TTP | +| [Powershell Enable SMB1Protocol Feature](/endpoint/powershell_enable_smb1protocol_feature/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools) | TTP | +| [Powershell Execute COM Object](/endpoint/powershell_execute_com_object/) | [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Powershell Fileless Process Injection via GetProcAddress](/endpoint/powershell_fileless_process_injection_via_getprocaddress/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Process Injection](/tags/#process-injection), [PowerShell](/tags/#powershell) | TTP | +| [Powershell Fileless Script Contains Base64 Encoded Content](/endpoint/powershell_fileless_script_contains_base64_encoded_content/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [PowerShell](/tags/#powershell) | TTP | +| [Powershell Processing Stream Of Data](/endpoint/powershell_processing_stream_of_data/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Powershell Using memory As Backing Store](/endpoint/powershell_using_memory_as_backing_store/) | [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information) | TTP | | [Recon AVProduct Through Pwh or WMI](/endpoint/recon_avproduct_through_pwh_or_wmi/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | | [Recon Using WMI Class](/endpoint/recon_using_wmi_class/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | -| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [PowerShell](/tags/#powershell) | TTP | +| [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Unloading AMSI via Reflection](/endpoint/unloading_amsi_via_reflection/) | [Impair Defenses](/tags/#impair-defenses) | TTP | | [WMI Recon Running Process Or Services](/endpoint/wmi_recon_running_process_or_services/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | diff --git a/docs/_stories/masquerading_-_rename_system_utilities.md b/docs/_stories/masquerading_-_rename_system_utilities.md index e0c606ef45..9353929e34 100644 --- a/docs/_stories/masquerading_-_rename_system_utilities.md +++ b/docs/_stories/masquerading_-_rename_system_utilities.md @@ -32,13 +32,14 @@ There will be false positives as some native Windows processes are moved or ran | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Execution of File with Multiple Extensions](/endpoint/execution_of_file_with_multiple_extensions/) | [Rename System Utilities](/tags/#rename-system-utilities) | TTP | -| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | -| [Suspicious Rundll32 Rename](/endpoint/suspicious_rundll32_rename/) | [Rundll32](/tags/#rundll32), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | -| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | -| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | +| [Execution of File with Multiple Extensions](/endpoint/execution_of_file_with_multiple_extensions/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | +| [Sdelete Application Execution](/endpoint/sdelete_application_execution/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | +| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | TTP | +| [Suspicious Rundll32 Rename](/endpoint/suspicious_rundll32_rename/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Masquerading](/tags/#masquerading), [Rundll32](/tags/#rundll32), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | +| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | +| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | TTP | | [System Process Running from Unexpected Location](/endpoint/system_process_running_from_unexpected_location/) | [Masquerading](/tags/#masquerading) | Anomaly | -| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Rename System Utilities](/tags/#rename-system-utilities) | TTP | +| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | #### Reference diff --git a/docs/_stories/microsoft_mshtml_remote_code_execution_cve-2021-40444.md b/docs/_stories/microsoft_mshtml_remote_code_execution_cve-2021-40444.md index 690f586cf2..3ef88c84bf 100644 --- a/docs/_stories/microsoft_mshtml_remote_code_execution_cve-2021-40444.md +++ b/docs/_stories/microsoft_mshtml_remote_code_execution_cve-2021-40444.md @@ -32,12 +32,12 @@ Microsoft is aware of targeted attacks that attempt to exploit this vulnerabilit | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Control Loading from World Writable Directory](/endpoint/control_loading_from_world_writable_directory/) | [Control Panel](/tags/#control-panel) | TTP | -| [MSHTML Module Load in Office Product](/endpoint/mshtml_module_load_in_office_product/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Writing cab or inf](/endpoint/office_product_writing_cab_or_inf/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Spawning Control](/endpoint/office_spawning_control/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Rundll32 Control RunDLL Hunt](/endpoint/rundll32_control_rundll_hunt/) | [Rundll32](/tags/#rundll32) | Hunting | -| [Rundll32 Control RunDLL World Writable Directory](/endpoint/rundll32_control_rundll_world_writable_directory/) | [Rundll32](/tags/#rundll32) | TTP | +| [Control Loading from World Writable Directory](/endpoint/control_loading_from_world_writable_directory/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Control Panel](/tags/#control-panel) | TTP | +| [MSHTML Module Load in Office Product](/endpoint/mshtml_module_load_in_office_product/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Writing cab or inf](/endpoint/office_product_writing_cab_or_inf/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Spawning Control](/endpoint/office_spawning_control/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Rundll32 Control RunDLL Hunt](/endpoint/rundll32_control_rundll_hunt/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | Hunting | +| [Rundll32 Control RunDLL World Writable Directory](/endpoint/rundll32_control_rundll_world_writable_directory/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | #### Reference diff --git a/docs/_stories/netsh_abuse.md b/docs/_stories/netsh_abuse.md index fc4228b9c5..761f9dbde9 100644 --- a/docs/_stories/netsh_abuse.md +++ b/docs/_stories/netsh_abuse.md @@ -31,7 +31,7 @@ To get started, run the detection search to identify parent processes of `netsh. | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall) | TTP | +| [Processes launching netsh](/endpoint/processes_launching_netsh/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | #### Reference diff --git a/docs/_stories/nobelium_group.md b/docs/_stories/nobelium_group.md index bce9583086..85137ca19b 100644 --- a/docs/_stories/nobelium_group.md +++ b/docs/_stories/nobelium_group.md @@ -32,18 +32,18 @@ This Analytic Story supports you to detect Tactics, Techniques and Procedures (T | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Anomalous usage of 7zip](/endpoint/anomalous_usage_of_7zip/) | [Archive via Utility](/tags/#archive-via-utility) | Anomaly | -| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols) | TTP | -| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Windows Command Shell](/tags/#windows-command-shell) | Hunting | -| [Detect Rundll32 Inline HTA Execution](/endpoint/detect_rundll32_inline_hta_execution/) | [Mshta](/tags/#mshta) | TTP | -| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [Service Execution](/tags/#service-execution) | Anomaly | +| [Anomalous usage of 7zip](/endpoint/anomalous_usage_of_7zip/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Anomaly | +| [Detect Outbound SMB Traffic](/network/detect_outbound_smb_traffic/) | [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol) | TTP | +| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | Hunting | +| [Detect Rundll32 Inline HTA Execution](/endpoint/detect_rundll32_inline_hta_execution/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Anomaly | | [Malicious PowerShell Process - Encoded Command](/endpoint/malicious_powershell_process_-_encoded_command/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information) | Hunting | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service) | TTP | -| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task) | TTP | -| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task) | TTP | +| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | +| [Scheduled Task Deleted Or Created via CMD](/endpoint/scheduled_task_deleted_or_created_via_cmd/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | | [Sunburst Correlation DLL and Network Event](/endpoint/sunburst_correlation_dll_and_network_event/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | TTP | | [Supernova Webshell](/web/supernova_webshell/) | [Web Shell](/tags/#web-shell) | TTP | -| [TOR Traffic](/network/tor_traffic/) | [Web Protocols](/tags/#web-protocols) | TTP | +| [TOR Traffic](/network/tor_traffic/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols) | TTP | | [Windows AdFind Exe](/endpoint/windows_adfind_exe/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | #### Reference diff --git a/docs/_stories/office_365_detections.md b/docs/_stories/office_365_detections.md index ffbbb892c1..759d539258 100644 --- a/docs/_stories/office_365_detections.md +++ b/docs/_stories/office_365_detections.md @@ -30,18 +30,18 @@ More and more companies are using Microsofts Office 365 cloud offering. Therefor | Name | Technique | Type | | ----------- | ----------- |--------------| -| [High Number of Login Failures from a single source](/cloud/high_number_of_login_failures_from_a_single_source/) | [Password Guessing](/tags/#password-guessing) | Anomaly | -| [O365 Add App Role Assignment Grant User](/cloud/o365_add_app_role_assignment_grant_user/) | [Cloud Account](/tags/#cloud-account) | TTP | -| [O365 Added Service Principal](/cloud/o365_added_service_principal/) | [Cloud Account](/tags/#cloud-account) | TTP | -| [O365 Bypass MFA via Trusted IP](/cloud/o365_bypass_mfa_via_trusted_ip/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | TTP | +| [High Number of Login Failures from a single source](/cloud/high_number_of_login_failures_from_a_single_source/) | [Password Guessing](/tags/#password-guessing), [Brute Force](/tags/#brute-force) | Anomaly | +| [O365 Add App Role Assignment Grant User](/cloud/o365_add_app_role_assignment_grant_user/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | +| [O365 Added Service Principal](/cloud/o365_added_service_principal/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | +| [O365 Bypass MFA via Trusted IP](/cloud/o365_bypass_mfa_via_trusted_ip/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | | [O365 Disable MFA](/cloud/o365_disable_mfa/) | [Modify Authentication Process](/tags/#modify-authentication-process) | TTP | | [O365 Excessive Authentication Failures Alert](/cloud/o365_excessive_authentication_failures_alert/) | [Brute Force](/tags/#brute-force) | Anomaly | | [O365 Excessive SSO logon errors](/cloud/o365_excessive_sso_logon_errors/) | [Modify Authentication Process](/tags/#modify-authentication-process) | Anomaly | -| [O365 New Federated Domain Added](/cloud/o365_new_federated_domain_added/) | [Cloud Account](/tags/#cloud-account) | TTP | +| [O365 New Federated Domain Added](/cloud/o365_new_federated_domain_added/) | [Cloud Account](/tags/#cloud-account), [Create Account](/tags/#create-account) | TTP | | [O365 PST export alert](/cloud/o365_pst_export_alert/) | [Email Collection](/tags/#email-collection) | TTP | -| [O365 Suspicious Admin Email Forwarding](/cloud/o365_suspicious_admin_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule) | Anomaly | -| [O365 Suspicious Rights Delegation](/cloud/o365_suspicious_rights_delegation/) | [Remote Email Collection](/tags/#remote-email-collection) | TTP | -| [O365 Suspicious User Email Forwarding](/cloud/o365_suspicious_user_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule) | Anomaly | +| [O365 Suspicious Admin Email Forwarding](/cloud/o365_suspicious_admin_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection) | Anomaly | +| [O365 Suspicious Rights Delegation](/cloud/o365_suspicious_rights_delegation/) | [Remote Email Collection](/tags/#remote-email-collection), [Email Collection](/tags/#email-collection) | TTP | +| [O365 Suspicious User Email Forwarding](/cloud/o365_suspicious_user_email_forwarding/) | [Email Forwarding Rule](/tags/#email-forwarding-rule), [Email Collection](/tags/#email-collection) | Anomaly | #### Reference diff --git a/docs/_stories/orangeworm_attack_group.md b/docs/_stories/orangeworm_attack_group.md index e231aa5f2d..9d73c2bd2d 100644 --- a/docs/_stories/orangeworm_attack_group.md +++ b/docs/_stories/orangeworm_attack_group.md @@ -33,8 +33,8 @@ This Analytic Story is designed to help you detect and investigate suspicious ac | Name | Technique | Type | | ----------- | ----------- |--------------| -| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [Service Execution](/tags/#service-execution) | Anomaly | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service) | TTP | +| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Anomaly | +| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | #### Reference diff --git a/docs/_stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns.md b/docs/_stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns.md index aa1c32cb06..720316b7bf 100644 --- a/docs/_stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns.md +++ b/docs/_stories/possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns.md @@ -57,8 +57,8 @@ If behavioral searches included in this story yield positive hits, iDefense reco | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Malicious PowerShell Process - Connect To Internet With Hidden Window](/endpoint/malicious_powershell_process_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell) | Hunting | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | +| [Malicious PowerShell Process - Connect To Internet With Hidden Window](/endpoint/malicious_powershell_process_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | Hunting | +| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | | Anomaly | | [Unusually Long Command Line - MLTK](/endpoint/unusually_long_command_line_-_mltk/) | | Anomaly | diff --git a/docs/_stories/printnightmare_cve-2021-34527.md b/docs/_stories/printnightmare_cve-2021-34527.md index bf16400e8c..84139f4aed 100644 --- a/docs/_stories/printnightmare_cve-2021-34527.md +++ b/docs/_stories/printnightmare_cve-2021-34527.md @@ -35,15 +35,15 @@ In the most impactful scenario, an attacker would be able to leverage this vulne | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Print Spooler Adding A Printer Driver](/endpoint/print_spooler_adding_a_printer_driver/) | [Print Processors](/tags/#print-processors) | TTP | -| [Print Spooler Failed to Load a Plug-in](/endpoint/print_spooler_failed_to_load_a_plug-in/) | [Print Processors](/tags/#print-processors) | TTP | -| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [Rundll32](/tags/#rundll32) | TTP | -| [Spoolsv Spawning Rundll32](/endpoint/spoolsv_spawning_rundll32/) | [Print Processors](/tags/#print-processors) | TTP | -| [Spoolsv Suspicious Loaded Modules](/endpoint/spoolsv_suspicious_loaded_modules/) | [Print Processors](/tags/#print-processors) | TTP | +| [Print Spooler Adding A Printer Driver](/endpoint/print_spooler_adding_a_printer_driver/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Print Spooler Failed to Load a Plug-in](/endpoint/print_spooler_failed_to_load_a_plug-in/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Spoolsv Spawning Rundll32](/endpoint/spoolsv_spawning_rundll32/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Spoolsv Suspicious Loaded Modules](/endpoint/spoolsv_suspicious_loaded_modules/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Spoolsv Suspicious Process Access](/endpoint/spoolsv_suspicious_process_access/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | TTP | -| [Spoolsv Writing a DLL](/endpoint/spoolsv_writing_a_dll/) | [Print Processors](/tags/#print-processors) | TTP | -| [Spoolsv Writing a DLL - Sysmon](/endpoint/spoolsv_writing_a_dll_-_sysmon/) | [Print Processors](/tags/#print-processors) | TTP | -| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [Rundll32](/tags/#rundll32) | TTP | +| [Spoolsv Writing a DLL](/endpoint/spoolsv_writing_a_dll/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Spoolsv Writing a DLL - Sysmon](/endpoint/spoolsv_writing_a_dll_-_sysmon/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | #### Reference diff --git a/docs/_stories/prohibited_traffic_allowed_or_protocol_mismatch.md b/docs/_stories/prohibited_traffic_allowed_or_protocol_mismatch.md index 661f68cdf9..9e7df70211 100644 --- a/docs/_stories/prohibited_traffic_allowed_or_protocol_mismatch.md +++ b/docs/_stories/prohibited_traffic_allowed_or_protocol_mismatch.md @@ -32,13 +32,13 @@ A traditional security best practice is to control the ports, protocols, and ser | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Allow Inbound Traffic By Firewall Rule Registry](/endpoint/allow_inbound_traffic_by_firewall_rule_registry/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | TTP | -| [Allow Inbound Traffic In Firewall Rule](/endpoint/allow_inbound_traffic_in_firewall_rule/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | TTP | +| [Allow Inbound Traffic By Firewall Rule Registry](/endpoint/allow_inbound_traffic_by_firewall_rule_registry/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | TTP | +| [Allow Inbound Traffic In Firewall Rule](/endpoint/allow_inbound_traffic_in_firewall_rule/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | TTP | | [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise) | TTP | | [Enable RDP In Other Port Number](/endpoint/enable_rdp_in_other_port_number/) | [Remote Services](/tags/#remote-services) | TTP | | [Prohibited Network Traffic Allowed](/network/prohibited_network_traffic_allowed/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | -| [Protocol or Port Mismatch](/network/protocol_or_port_mismatch/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | Anomaly | -| [TOR Traffic](/network/tor_traffic/) | [Web Protocols](/tags/#web-protocols) | TTP | +| [Protocol or Port Mismatch](/network/protocol_or_port_mismatch/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | +| [TOR Traffic](/network/tor_traffic/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols) | TTP | #### Reference diff --git a/docs/_stories/proxyshell.md b/docs/_stories/proxyshell.md index d6e0914329..ecfffcc430 100644 --- a/docs/_stories/proxyshell.md +++ b/docs/_stories/proxyshell.md @@ -34,10 +34,10 @@ Upon successful exploitation, the remote attacker will have `SYSTEM` privileges | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect Exchange Web Shell](/endpoint/detect_exchange_web_shell/) | [Web Shell](/tags/#web-shell) | TTP | +| [Detect Exchange Web Shell](/endpoint/detect_exchange_web_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | TTP | | [Exchange PowerShell Abuse via SSRF](/endpoint/exchange_powershell_abuse_via_ssrf/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | TTP | -| [Exchange PowerShell Module Usage](/endpoint/exchange_powershell_module_usage/) | [PowerShell](/tags/#powershell) | TTP | -| [W3WP Spawning Shell](/endpoint/w3wp_spawning_shell/) | [Web Shell](/tags/#web-shell) | TTP | +| [Exchange PowerShell Module Usage](/endpoint/exchange_powershell_module_usage/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [W3WP Spawning Shell](/endpoint/w3wp_spawning_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | TTP | #### Reference diff --git a/docs/_stories/ransomware.md b/docs/_stories/ransomware.md index e5f56c6f11..d1048a1d45 100644 --- a/docs/_stories/ransomware.md +++ b/docs/_stories/ransomware.md @@ -31,15 +31,15 @@ Ransomware is an ever-present risk to the enterprise, wherein an infected host e | Name | Technique | Type | | ----------- | ----------- |--------------| -| [7zip CommandLine To SMB Share Path](/endpoint/7zip_commandline_to_smb_share_path/) | [Archive via Utility](/tags/#archive-via-utility) | Hunting | -| [Allow File And Printing Sharing In Firewall](/endpoint/allow_file_and_printing_sharing_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | TTP | -| [Allow Network Discovery In Firewall](/endpoint/allow_network_discovery_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | TTP | +| [7zip CommandLine To SMB Share Path](/endpoint/7zip_commandline_to_smb_share_path/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Hunting | +| [Allow File And Printing Sharing In Firewall](/endpoint/allow_file_and_printing_sharing_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Allow Network Discovery In Firewall](/endpoint/allow_network_discovery_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Allow Operation with Consent Admin](/endpoint/allow_operation_with_consent_admin/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Attempt To Disable Services](/endpoint/attempt_to_disable_services/) | [Service Stop](/tags/#service-stop) | TTP | | [Attempt To delete Services](/endpoint/attempt_to_delete_services/) | [Service Stop](/tags/#service-stop) | TTP | | [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | -| [CMLUA Or CMSTPLUA UAC Bypass](/endpoint/cmlua_or_cmstplua_uac_bypass/) | [CMSTP](/tags/#cmstp) | TTP | -| [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion) | TTP | +| [CMLUA Or CMSTPLUA UAC Bypass](/endpoint/cmlua_or_cmstplua_uac_bypass/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | TTP | +| [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [Conti Common Exec parameter](/endpoint/conti_common_exec_parameter/) | [User Execution](/tags/#user-execution) | TTP | @@ -48,58 +48,58 @@ Ransomware is an ever-present risk to the enterprise, wherein an infected host e | [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration) | TTP | | [Detect Renamed RClone](/endpoint/detect_renamed_rclone/) | [Automated Exfiltration](/tags/#automated-exfiltration) | Hunting | -| [Detect SharpHound Command-Line Arguments](/endpoint/detect_sharphound_command-line_arguments/) | [Domain Account](/tags/#domain-account), [Local Account](/tags/#local-account), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Domain Groups](/tags/#domain-groups), [Local Groups](/tags/#local-groups) | TTP | -| [Detect SharpHound File Modifications](/endpoint/detect_sharphound_file_modifications/) | [Domain Account](/tags/#domain-account), [Local Account](/tags/#local-account), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Domain Groups](/tags/#domain-groups), [Local Groups](/tags/#local-groups) | TTP | -| [Detect SharpHound Usage](/endpoint/detect_sharphound_usage/) | [Domain Account](/tags/#domain-account), [Local Account](/tags/#local-account), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Domain Groups](/tags/#domain-groups), [Local Groups](/tags/#local-groups) | TTP | -| [Disable AMSI Through Registry](/endpoint/disable_amsi_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disable ETW Through Registry](/endpoint/disable_etw_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disable Logs Using WevtUtil](/endpoint/disable_logs_using_wevtutil/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Detect SharpHound Command-Line Arguments](/endpoint/detect_sharphound_command-line_arguments/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | TTP | +| [Detect SharpHound File Modifications](/endpoint/detect_sharphound_file_modifications/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | TTP | +| [Detect SharpHound Usage](/endpoint/detect_sharphound_usage/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | TTP | +| [Disable AMSI Through Registry](/endpoint/disable_amsi_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable ETW Through Registry](/endpoint/disable_etw_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable Logs Using WevtUtil](/endpoint/disable_logs_using_wevtutil/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | | [Disable Net User Account](/endpoint/disable_net_user_account/) | [Service Stop](/tags/#service-stop) | TTP | -| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Excessive Service Stop Attempt](/endpoint/excessive_service_stop_attempt/) | [Service Stop](/tags/#service-stop) | Anomaly | | [Excessive Usage Of Net App](/endpoint/excessive_usage_of_net_app/) | [Account Access Removal](/tags/#account-access-removal) | Anomaly | -| [Excessive Usage Of SC Service Utility](/endpoint/excessive_usage_of_sc_service_utility/) | [Service Execution](/tags/#service-execution) | Anomaly | -| [Execute Javascript With Jscript COM CLSID](/endpoint/execute_javascript_with_jscript_com_clsid/) | [Visual Basic](/tags/#visual-basic) | TTP | +| [Excessive Usage Of SC Service Utility](/endpoint/excessive_usage_of_sc_service_utility/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Anomaly | +| [Execute Javascript With Jscript COM CLSID](/endpoint/execute_javascript_with_jscript_com_clsid/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Visual Basic](/tags/#visual-basic) | TTP | | [Fsutil Zeroing File](/endpoint/fsutil_zeroing_file/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [ICACLS Grant Command](/endpoint/icacls_grant_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [Known Services Killed by Ransomware](/endpoint/known_services_killed_by_ransomware/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Modification Of Wallpaper](/endpoint/modification_of_wallpaper/) | [Defacement](/tags/#defacement) | TTP | -| [Msmpeng Application DLL Side Loading](/endpoint/msmpeng_application_dll_side_loading/) | [DLL Side-Loading](/tags/#dll-side-loading) | TTP | +| [Msmpeng Application DLL Side Loading](/endpoint/msmpeng_application_dll_side_loading/) | [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | | [Permission Modification using Takeown App](/endpoint/permission_modification_using_takeown_app/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | -| [Powershell Disable Security Monitoring](/endpoint/powershell_disable_security_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Powershell Enable SMB1Protocol Feature](/endpoint/powershell_enable_smb1protocol_feature/) | [Indicator Removal from Tools](/tags/#indicator-removal-from-tools) | TTP | -| [Powershell Execute COM Object](/endpoint/powershell_execute_com_object/) | [Component Object Model Hijacking](/tags/#component-object-model-hijacking) | TTP | +| [Powershell Disable Security Monitoring](/endpoint/powershell_disable_security_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Powershell Enable SMB1Protocol Feature](/endpoint/powershell_enable_smb1protocol_feature/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools) | TTP | +| [Powershell Execute COM Object](/endpoint/powershell_execute_com_object/) | [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [Prevent Automatic Repair Mode using Bcdedit](/endpoint/prevent_automatic_repair_mode_using_bcdedit/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Prohibited Network Traffic Allowed](/network/prohibited_network_traffic_allowed/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | | [Recon AVProduct Through Pwh or WMI](/endpoint/recon_avproduct_through_pwh_or_wmi/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | -| [Recursive Delete of Directory In Batch CMD](/endpoint/recursive_delete_of_directory_in_batch_cmd/) | [File Deletion](/tags/#file-deletion) | TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | +| [Recursive Delete of Directory In Batch CMD](/endpoint/recursive_delete_of_directory_in_batch_cmd/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | +| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Remote Process Instantiation via WMI](/endpoint/remote_process_instantiation_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | | [Resize Shadowstorage Volume](/endpoint/resize_shadowstorage_volume/) | [Service Stop](/tags/#service-stop) | TTP | | [Revil Common Exec Parameter](/endpoint/revil_common_exec_parameter/) | [User Execution](/tags/#user-execution) | TTP | | [Revil Registry Entry](/endpoint/revil_registry_entry/) | [Modify Registry](/tags/#modify-registry) | TTP | -| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | Anomaly | -| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | Anomaly | -| [Schtasks used for forcing a reboot](/endpoint/schtasks_used_for_forcing_a_reboot/) | [Scheduled Task](/tags/#scheduled-task) | TTP | +| [SMB Traffic Spike](/network/smb_traffic_spike/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | Anomaly | +| [SMB Traffic Spike - MLTK](/network/smb_traffic_spike_-_mltk/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | Anomaly | +| [Schtasks used for forcing a reboot](/endpoint/schtasks_used_for_forcing_a_reboot/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | | [Spike in File Writes](/endpoint/spike_in_file_writes/) | | Anomaly | -| [Start Up During Safe Mode Boot](/endpoint/start_up_during_safe_mode_boot/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | -| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task) | Anomaly | -| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Rename System Utilities](/tags/#rename-system-utilities) | TTP | -| [TOR Traffic](/network/tor_traffic/) | [Web Protocols](/tags/#web-protocols) | TTP | -| [UAC Bypass With Colorui COM Object](/endpoint/uac_bypass_with_colorui_com_object/) | [CMSTP](/tags/#cmstp) | TTP | +| [Start Up During Safe Mode Boot](/endpoint/start_up_during_safe_mode_boot/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | Anomaly | +| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | +| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | +| [TOR Traffic](/network/tor_traffic/) | [Application Layer Protocol](/tags/#application-layer-protocol), [Web Protocols](/tags/#web-protocols) | TTP | +| [UAC Bypass With Colorui COM Object](/endpoint/uac_bypass_with_colorui_com_object/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | TTP | | [USN Journal Deletion](/endpoint/usn_journal_deletion/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | -| [Uninstall App Using MsiExec](/endpoint/uninstall_app_using_msiexec/) | [Msiexec](/tags/#msiexec) | TTP | +| [Uninstall App Using MsiExec](/endpoint/uninstall_app_using_msiexec/) | [Msiexec](/tags/#msiexec), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution) | TTP | | [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | | Anomaly | | [Unusually Long Command Line - MLTK](/endpoint/unusually_long_command_line_-_mltk/) | | Anomaly | | [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | -| [Wbemprox COM Object Execution](/endpoint/wbemprox_com_object_execution/) | [CMSTP](/tags/#cmstp) | TTP | -| [WevtUtil Usage To Clear Logs](/endpoint/wevtutil_usage_to_clear_logs/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [Wevtutil Usage To Disable Logs](/endpoint/wevtutil_usage_to_disable_logs/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task) | TTP | -| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task) | TTP | -| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Wbemprox COM Object Execution](/endpoint/wbemprox_com_object_execution/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | TTP | +| [WevtUtil Usage To Clear Logs](/endpoint/wevtutil_usage_to_clear_logs/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Wevtutil Usage To Disable Logs](/endpoint/wevtutil_usage_to_disable_logs/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | #### Reference diff --git a/docs/_stories/remcos.md b/docs/_stories/remcos.md index 508bfb87f9..f111d8417c 100644 --- a/docs/_stories/remcos.md +++ b/docs/_stories/remcos.md @@ -30,15 +30,20 @@ Remcos or Remote Control and Surveillance, marketed as a legitimate software for | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | +| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading) | TTP | +| [Malicious InProcServer32 Modification](/endpoint/malicious_inprocserver32_modification/) | [Regsvr32](/tags/#regsvr32), [Modify Registry](/tags/#modify-registry) | TTP | | [Process Deleting Its Process File Path](/endpoint/process_deleting_its_process_file_path/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | +| [Process Writing DynamicWrapperX](/endpoint/process_writing_dynamicwrapperx/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Component Object Model](/tags/#component-object-model) | Hunting | +| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Remcos RAT File Creation in Remcos Folder](/endpoint/remcos_rat_file_creation_in_remcos_folder/) | [Screen Capture](/tags/#screen-capture) | TTP | | [Remcos client registry install entry](/endpoint/remcos_client_registry_install_entry/) | [Modify Registry](/tags/#modify-registry) | TTP | | [Suspicious Image Creation In Appdata Folder](/endpoint/suspicious_image_creation_in_appdata_folder/) | [Screen Capture](/tags/#screen-capture) | TTP | | [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [Suspicious WAV file in Appdata Folder](/endpoint/suspicious_wav_file_in_appdata_folder/) | [Screen Capture](/tags/#screen-capture) | TTP | +| [Vbscript Execution Using Wscript App](/endpoint/vbscript_execution_using_wscript_app/) | [Visual Basic](/tags/#visual-basic), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | TTP | +| [Winhlp32 Spawning a Process](/endpoint/winhlp32_spawning_a_process/) | [Process Injection](/tags/#process-injection) | TTP | +| [Wscript Or Cscript Suspicious Child Process](/endpoint/wscript_or_cscript_suspicious_child_process/) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation) | TTP | #### Reference diff --git a/docs/_stories/revil_ransomware.md b/docs/_stories/revil_ransomware.md index 04684d21d3..1d8a5867fe 100644 --- a/docs/_stories/revil_ransomware.md +++ b/docs/_stories/revil_ransomware.md @@ -30,15 +30,15 @@ Revil ransomware is a RaaS,that a single group may operates and manges the devel | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Allow Network Discovery In Firewall](/endpoint/allow_network_discovery_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall) | TTP | +| [Allow Network Discovery In Firewall](/endpoint/allow_network_discovery_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Delete ShadowCopy With PowerShell](/endpoint/delete_shadowcopy_with_powershell/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | -| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Modification Of Wallpaper](/endpoint/modification_of_wallpaper/) | [Defacement](/tags/#defacement) | TTP | -| [Msmpeng Application DLL Side Loading](/endpoint/msmpeng_application_dll_side_loading/) | [DLL Side-Loading](/tags/#dll-side-loading) | TTP | -| [Powershell Disable Security Monitoring](/endpoint/powershell_disable_security_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Msmpeng Application DLL Side Loading](/endpoint/msmpeng_application_dll_side_loading/) | [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | +| [Powershell Disable Security Monitoring](/endpoint/powershell_disable_security_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Revil Common Exec Parameter](/endpoint/revil_common_exec_parameter/) | [User Execution](/tags/#user-execution) | TTP | | [Revil Registry Entry](/endpoint/revil_registry_entry/) | [Modify Registry](/tags/#modify-registry) | TTP | -| [Wbemprox COM Object Execution](/endpoint/wbemprox_com_object_execution/) | [CMSTP](/tags/#cmstp) | TTP | +| [Wbemprox COM Object Execution](/endpoint/wbemprox_com_object_execution/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | TTP | #### Reference diff --git a/docs/_stories/router_and_infrastructure_security.md b/docs/_stories/router_and_infrastructure_security.md index d31565bc42..712d88188f 100644 --- a/docs/_stories/router_and_infrastructure_security.md +++ b/docs/_stories/router_and_infrastructure_security.md @@ -32,13 +32,13 @@ This Analytic Story helps you gain a better understanding of how your network de | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect ARP Poisoning](/network/detect_arp_poisoning/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | -| [Detect IPv6 Network Infrastructure Threats](/network/detect_ipv6_network_infrastructure_threats/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | +| [Detect ARP Poisoning](/network/detect_arp_poisoning/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Man-in-the-Middle](/tags/#man-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | +| [Detect IPv6 Network Infrastructure Threats](/network/detect_ipv6_network_infrastructure_threats/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Man-in-the-Middle](/tags/#man-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | | [Detect New Login Attempts to Routers](/application/detect_new_login_attempts_to_routers/) | | TTP | -| [Detect Port Security Violation](/network/detect_port_security_violation/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | +| [Detect Port Security Violation](/network/detect_port_security_violation/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Man-in-the-Middle](/tags/#man-in-the-middle), [ARP Cache Poisoning](/tags/#arp-cache-poisoning) | TTP | | [Detect Rogue DHCP Server](/network/detect_rogue_dhcp_server/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Man-in-the-Middle](/tags/#man-in-the-middle) | TTP | -| [Detect Software Download To Network Device](/network/detect_software_download_to_network_device/) | [TFTP Boot](/tags/#tftp-boot) | TTP | -| [Detect Traffic Mirroring](/network/detect_traffic_mirroring/) | [Hardware Additions](/tags/#hardware-additions), [Network Denial of Service](/tags/#network-denial-of-service), [Traffic Duplication](/tags/#traffic-duplication) | TTP | +| [Detect Software Download To Network Device](/network/detect_software_download_to_network_device/) | [TFTP Boot](/tags/#tftp-boot), [Pre-OS Boot](/tags/#pre-os-boot) | TTP | +| [Detect Traffic Mirroring](/network/detect_traffic_mirroring/) | [Hardware Additions](/tags/#hardware-additions), [Automated Exfiltration](/tags/#automated-exfiltration), [Network Denial of Service](/tags/#network-denial-of-service), [Traffic Duplication](/tags/#traffic-duplication) | TTP | #### Reference diff --git a/docs/_stories/ryuk_ransomware.md b/docs/_stories/ryuk_ransomware.md index 0e3e682295..eda620fe81 100644 --- a/docs/_stories/ryuk_ransomware.md +++ b/docs/_stories/ryuk_ransomware.md @@ -35,16 +35,16 @@ Cybersecurity Infrastructure Security Agency (CISA) released Alert (AA20-302A) o | [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [NLTest Domain Trust Discovery](/endpoint/nltest_domain_trust_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | -| [Remote Desktop Network Bruteforce](/network/remote_desktop_network_bruteforce/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | TTP | -| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | Anomaly | +| [Remote Desktop Network Bruteforce](/network/remote_desktop_network_bruteforce/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | TTP | +| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Anomaly | | [Ryuk Test Files Detected](/endpoint/ryuk_test_files_detected/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | TTP | -| [Ryuk Wake on LAN Command](/endpoint/ryuk_wake_on_lan_command/) | [Windows Command Shell](/tags/#windows-command-shell) | TTP | +| [Ryuk Wake on LAN Command](/endpoint/ryuk_wake_on_lan_command/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | TTP | | [Spike in File Writes](/endpoint/spike_in_file_writes/) | | Anomaly | -| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task) | Anomaly | +| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | Anomaly | | [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task) | TTP | -| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task) | TTP | -| [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Windows Security Account Manager Stopped](/endpoint/windows_security_account_manager_stopped/) | [Service Stop](/tags/#service-stop) | TTP | #### Reference diff --git a/docs/_stories/samsam_ransomware.md b/docs/_stories/samsam_ransomware.md index ee80e1cccb..df30a5bf30 100644 --- a/docs/_stories/samsam_ransomware.md +++ b/docs/_stories/samsam_ransomware.md @@ -37,18 +37,18 @@ This Analytic Story includes searches designed to help detect and investigate si | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Active Scanning](/tags/#active-scanning), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Batch File Write to System32](/endpoint/batch_file_write_to_system32/) | [Malicious File](/tags/#malicious-file) | TTP | +| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning) | TTP | +| [Batch File Write to System32](/endpoint/batch_file_write_to_system32/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file) | TTP | | [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | -| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [Service Execution](/tags/#service-execution) | Hunting | +| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Hunting | | [Detect attackers scanning for vulnerable JBoss servers](/web/detect_attackers_scanning_for_vulnerable_jboss_servers/) | [System Information Discovery](/tags/#system-information-discovery) | TTP | | [Detect malicious requests to exploit JBoss servers](/web/detect_malicious_requests_to_exploit_jboss_servers/) | | TTP | | [File with Samsam Extension](/endpoint/file_with_samsam_extension/) | | TTP | -| [Remote Desktop Network Bruteforce](/network/remote_desktop_network_bruteforce/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | TTP | -| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol) | Anomaly | +| [Remote Desktop Network Bruteforce](/network/remote_desktop_network_bruteforce/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | TTP | +| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Anomaly | | [Samsam Test File Write](/endpoint/samsam_test_file_write/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | TTP | | [Spike in File Writes](/endpoint/spike_in_file_writes/) | | Anomaly | diff --git a/docs/_stories/silver_sparrow.md b/docs/_stories/silver_sparrow.md index a916b4ee1e..f5a1f8dc55 100644 --- a/docs/_stories/silver_sparrow.md +++ b/docs/_stories/silver_sparrow.md @@ -31,8 +31,8 @@ Silver Sparrow works is a dropper and uses typical persistence mechanisms on a M | Name | Technique | Type | | ----------- | ----------- |--------------| | [Suspicious Curl Network Connection](/endpoint/suspicious_curl_network_connection/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | -| [Suspicious PlistBuddy Usage](/endpoint/suspicious_plistbuddy_usage/) | [Launch Agent](/tags/#launch-agent) | TTP | -| [Suspicious PlistBuddy Usage via OSquery](/endpoint/suspicious_plistbuddy_usage_via_osquery/) | [Launch Agent](/tags/#launch-agent) | TTP | +| [Suspicious PlistBuddy Usage](/endpoint/suspicious_plistbuddy_usage/) | [Launch Agent](/tags/#launch-agent), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | +| [Suspicious PlistBuddy Usage via OSquery](/endpoint/suspicious_plistbuddy_usage_via_osquery/) | [Launch Agent](/tags/#launch-agent), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [Suspicious SQLite3 LSQuarantine Behavior](/endpoint/suspicious_sqlite3_lsquarantine_behavior/) | [Data Staged](/tags/#data-staged) | TTP | #### Reference diff --git a/docs/_stories/spearphishing_attachments.md b/docs/_stories/spearphishing_attachments.md index b1fbcd12f4..30a3e27168 100644 --- a/docs/_stories/spearphishing_attachments.md +++ b/docs/_stories/spearphishing_attachments.md @@ -37,24 +37,24 @@ This Analytic Story focuses on detecting signs that a malicious payload has been | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect Outlook exe writing a zip file](/endpoint/detect_outlook_exe_writing_a_zip_file/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Excel Spawning PowerShell](/endpoint/excel_spawning_powershell/) | [Security Account Manager](/tags/#security-account-manager) | TTP | -| [Excel Spawning Windows Script Host](/endpoint/excel_spawning_windows_script_host/) | [Security Account Manager](/tags/#security-account-manager) | TTP | -| [MSHTML Module Load in Office Product](/endpoint/mshtml_module_load_in_office_product/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Document Creating Schedule Task](/endpoint/office_document_creating_schedule_task/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Document Spawned Child Process To Download](/endpoint/office_document_spawned_child_process_to_download/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawning BITSAdmin](/endpoint/office_product_spawning_bitsadmin/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawning CertUtil](/endpoint/office_product_spawning_certutil/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawning MSHTA](/endpoint/office_product_spawning_mshta/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawning Rundll32 with no DLL](/endpoint/office_product_spawning_rundll32_with_no_dll/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawning Wmic](/endpoint/office_product_spawning_wmic/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Writing cab or inf](/endpoint/office_product_writing_cab_or_inf/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Spawning Control](/endpoint/office_spawning_control/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Process Creating LNK file in Suspicious Location](/endpoint/process_creating_lnk_file_in_suspicious_location/) | [Spearphishing Link](/tags/#spearphishing-link) | TTP | -| [Winword Spawning Cmd](/endpoint/winword_spawning_cmd/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Winword Spawning PowerShell](/endpoint/winword_spawning_powershell/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Detect Outlook exe writing a zip file](/endpoint/detect_outlook_exe_writing_a_zip_file/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Excel Spawning PowerShell](/endpoint/excel_spawning_powershell/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Excel Spawning Windows Script Host](/endpoint/excel_spawning_windows_script_host/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [MSHTML Module Load in Office Product](/endpoint/mshtml_module_load_in_office_product/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Document Creating Schedule Task](/endpoint/office_document_creating_schedule_task/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Document Spawned Child Process To Download](/endpoint/office_document_spawned_child_process_to_download/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawning BITSAdmin](/endpoint/office_product_spawning_bitsadmin/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawning CertUtil](/endpoint/office_product_spawning_certutil/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawning MSHTA](/endpoint/office_product_spawning_mshta/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawning Rundll32 with no DLL](/endpoint/office_product_spawning_rundll32_with_no_dll/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawning Wmic](/endpoint/office_product_spawning_wmic/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Writing cab or inf](/endpoint/office_product_writing_cab_or_inf/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Spawning Control](/endpoint/office_spawning_control/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Process Creating LNK file in Suspicious Location](/endpoint/process_creating_lnk_file_in_suspicious_location/) | [Phishing](/tags/#phishing), [Spearphishing Link](/tags/#spearphishing-link) | TTP | +| [Winword Spawning Cmd](/endpoint/winword_spawning_cmd/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Winword Spawning PowerShell](/endpoint/winword_spawning_powershell/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | #### Reference diff --git a/docs/_stories/suspicious_cloud_instance_activities.md b/docs/_stories/suspicious_cloud_instance_activities.md index 0eb6f09476..4d3f40bfb5 100644 --- a/docs/_stories/suspicious_cloud_instance_activities.md +++ b/docs/_stories/suspicious_cloud_instance_activities.md @@ -31,9 +31,9 @@ Monitoring your cloud infrastructure logs allows you enable governance, complian | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Abnormally High Number Of Cloud Instances Destroyed](/cloud/abnormally_high_number_of_cloud_instances_destroyed/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | -| [Abnormally High Number Of Cloud Instances Launched](/cloud/abnormally_high_number_of_cloud_instances_launched/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | -| [Cloud Instance Modified By Previously Unseen User](/cloud/cloud_instance_modified_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | +| [Abnormally High Number Of Cloud Instances Destroyed](/cloud/abnormally_high_number_of_cloud_instances_destroyed/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | +| [Abnormally High Number Of Cloud Instances Launched](/cloud/abnormally_high_number_of_cloud_instances_launched/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | +| [Cloud Instance Modified By Previously Unseen User](/cloud/cloud_instance_modified_by_previously_unseen_user/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | | [Detect shared ec2 snapshot](/cloud/detect_shared_ec2_snapshot/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | TTP | #### Reference diff --git a/docs/_stories/suspicious_cloud_user_activities.md b/docs/_stories/suspicious_cloud_user_activities.md index bff4078331..34350628a8 100644 --- a/docs/_stories/suspicious_cloud_user_activities.md +++ b/docs/_stories/suspicious_cloud_user_activities.md @@ -33,8 +33,8 @@ In addition to compromising the security of your data, when bad actors leverage | Name | Technique | Type | | ----------- | ----------- |--------------| | [AWS IAM AccessDenied Discovery Events](/cloud/aws_iam_accessdenied_discovery_events/) | [Cloud Infrastructure Discovery](/tags/#cloud-infrastructure-discovery) | Anomaly | -| [Abnormally High Number Of Cloud Infrastructure API Calls](/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | -| [Abnormally High Number Of Cloud Security Group API Calls](/cloud/abnormally_high_number_of_cloud_security_group_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts) | Anomaly | +| [Abnormally High Number Of Cloud Infrastructure API Calls](/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | +| [Abnormally High Number Of Cloud Security Group API Calls](/cloud/abnormally_high_number_of_cloud_security_group_api_calls/) | [Cloud Accounts](/tags/#cloud-accounts), [Valid Accounts](/tags/#valid-accounts) | Anomaly | | [Cloud API Calls From Previously Unseen User Roles](/cloud/cloud_api_calls_from_previously_unseen_user_roles/) | [Valid Accounts](/tags/#valid-accounts) | Anomaly | #### Reference diff --git a/docs/_stories/suspicious_command-line_executions.md b/docs/_stories/suspicious_command-line_executions.md index db10ec080f..c8bca3ceb6 100644 --- a/docs/_stories/suspicious_command-line_executions.md +++ b/docs/_stories/suspicious_command-line_executions.md @@ -30,10 +30,10 @@ The ability to execute arbitrary commands via the Windows CLI is a primary goal | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Windows Command Shell](/tags/#windows-command-shell) | Hunting | +| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | Hunting | | [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | TTP | -| [Detect Use of cmd exe to Launch Script Interpreters](/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters/) | [Windows Command Shell](/tags/#windows-command-shell) | TTP | -| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Rename System Utilities](/tags/#rename-system-utilities) | TTP | +| [Detect Use of cmd exe to Launch Script Interpreters](/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | TTP | +| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | | [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | | Anomaly | | [Unusually Long Command Line - MLTK](/endpoint/unusually_long_command_line_-_mltk/) | | Anomaly | diff --git a/docs/_stories/suspicious_compiled_html_activity.md b/docs/_stories/suspicious_compiled_html_activity.md index 73dfaaa5af..acca03dd17 100644 --- a/docs/_stories/suspicious_compiled_html_activity.md +++ b/docs/_stories/suspicious_compiled_html_activity.md @@ -33,10 +33,10 @@ Upon usage of InfoTech Storage Handlers, ms-its, its, mk, itss.dll will load. | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect HTML Help Renamed](/endpoint/detect_html_help_renamed/) | [Compiled HTML File](/tags/#compiled-html-file) | Hunting | -| [Detect HTML Help Spawn Child Process](/endpoint/detect_html_help_spawn_child_process/) | [Compiled HTML File](/tags/#compiled-html-file) | TTP | -| [Detect HTML Help URL in Command Line](/endpoint/detect_html_help_url_in_command_line/) | [Compiled HTML File](/tags/#compiled-html-file) | TTP | -| [Detect HTML Help Using InfoTech Storage Handlers](/endpoint/detect_html_help_using_infotech_storage_handlers/) | [Compiled HTML File](/tags/#compiled-html-file) | TTP | +| [Detect HTML Help Renamed](/endpoint/detect_html_help_renamed/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | Hunting | +| [Detect HTML Help Spawn Child Process](/endpoint/detect_html_help_spawn_child_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | TTP | +| [Detect HTML Help URL in Command Line](/endpoint/detect_html_help_url_in_command_line/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | TTP | +| [Detect HTML Help Using InfoTech Storage Handlers](/endpoint/detect_html_help_using_infotech_storage_handlers/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Compiled HTML File](/tags/#compiled-html-file) | TTP | #### Reference diff --git a/docs/_stories/suspicious_dns_traffic.md b/docs/_stories/suspicious_dns_traffic.md index 4cc8a34e6b..01df9d4326 100644 --- a/docs/_stories/suspicious_dns_traffic.md +++ b/docs/_stories/suspicious_dns_traffic.md @@ -32,10 +32,10 @@ Although DNS is one of the fundamental underlying protocols that make the Intern | Name | Technique | Type | | ----------- | ----------- |--------------| | [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | -| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns) | Anomaly | -| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol) | Anomaly | +| [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | Anomaly | +| [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | | [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise) | TTP | -| [Excessive DNS Failures](/network/excessive_dns_failures/) | [DNS](/tags/#dns) | Anomaly | +| [Excessive DNS Failures](/network/excessive_dns_failures/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | Anomaly | | [Excessive Usage of NSLOOKUP App](/endpoint/excessive_usage_of_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | #### Reference diff --git a/docs/_stories/suspicious_emails.md b/docs/_stories/suspicious_emails.md index 4e900e0c29..6f25f48afe 100644 --- a/docs/_stories/suspicious_emails.md +++ b/docs/_stories/suspicious_emails.md @@ -36,7 +36,7 @@ Once a phishing message has been detected, the next steps are to answer the foll | ----------- | ----------- |--------------| | [Email Attachments With Lots Of Spaces](/application/email_attachments_with_lots_of_spaces/) | | Anomaly | | [Monitor Email For Brand Abuse](/application/monitor_email_for_brand_abuse/) | | TTP | -| [Suspicious Email Attachment Extensions](/application/suspicious_email_attachment_extensions/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | Anomaly | +| [Suspicious Email Attachment Extensions](/application/suspicious_email_attachment_extensions/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | #### Reference diff --git a/docs/_stories/suspicious_mshta_activity.md b/docs/_stories/suspicious_mshta_activity.md index e88c3176f4..32ab891725 100644 --- a/docs/_stories/suspicious_mshta_activity.md +++ b/docs/_stories/suspicious_mshta_activity.md @@ -42,15 +42,15 @@ The objective of this step is to confirm the executed script code is benign or m | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect MSHTA Url in Command Line](/endpoint/detect_mshta_url_in_command_line/) | [Mshta](/tags/#mshta) | TTP | -| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Windows Command Shell](/tags/#windows-command-shell) | Hunting | +| [Detect MSHTA Url in Command Line](/endpoint/detect_mshta_url_in_command_line/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | Hunting | | [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | TTP | -| [Detect Rundll32 Inline HTA Execution](/endpoint/detect_rundll32_inline_hta_execution/) | [Mshta](/tags/#mshta) | TTP | -| [Detect mshta inline hta execution](/endpoint/detect_mshta_inline_hta_execution/) | [Mshta](/tags/#mshta) | TTP | -| [Detect mshta renamed](/endpoint/detect_mshta_renamed/) | [Mshta](/tags/#mshta) | Hunting | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | -| [Suspicious mshta child process](/endpoint/suspicious_mshta_child_process/) | [Mshta](/tags/#mshta) | TTP | -| [Suspicious mshta spawn](/endpoint/suspicious_mshta_spawn/) | [Mshta](/tags/#mshta) | TTP | +| [Detect Rundll32 Inline HTA Execution](/endpoint/detect_rundll32_inline_hta_execution/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [Detect mshta inline hta execution](/endpoint/detect_mshta_inline_hta_execution/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [Detect mshta renamed](/endpoint/detect_mshta_renamed/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | Hunting | +| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Suspicious mshta child process](/endpoint/suspicious_mshta_child_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [Suspicious mshta spawn](/endpoint/suspicious_mshta_spawn/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | #### Reference diff --git a/docs/_stories/suspicious_okta_activity.md b/docs/_stories/suspicious_okta_activity.md index 86d5fe9ddf..3d769d6b1b 100644 --- a/docs/_stories/suspicious_okta_activity.md +++ b/docs/_stories/suspicious_okta_activity.md @@ -31,10 +31,10 @@ With people moving quickly to adopt web-based applications and ways to manage th | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Multiple Okta Users With Invalid Credentials From The Same IP](/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip/) | [Default Accounts](/tags/#default-accounts) | TTP | -| [Okta Account Lockout Events](/application/okta_account_lockout_events/) | [Default Accounts](/tags/#default-accounts) | Anomaly | -| [Okta Failed SSO Attempts](/application/okta_failed_sso_attempts/) | [Default Accounts](/tags/#default-accounts) | Anomaly | -| [Okta User Logins From Multiple Cities](/application/okta_user_logins_from_multiple_cities/) | [Default Accounts](/tags/#default-accounts) | Anomaly | +| [Multiple Okta Users With Invalid Credentials From The Same IP](/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | TTP | +| [Okta Account Lockout Events](/application/okta_account_lockout_events/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | Anomaly | +| [Okta Failed SSO Attempts](/application/okta_failed_sso_attempts/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | Anomaly | +| [Okta User Logins From Multiple Cities](/application/okta_user_logins_from_multiple_cities/) | [Valid Accounts](/tags/#valid-accounts), [Default Accounts](/tags/#default-accounts) | Anomaly | #### Reference diff --git a/docs/_stories/suspicious_regsvcs_regasm_activity.md b/docs/_stories/suspicious_regsvcs_regasm_activity.md index ed0850cb23..dfbcbf1afb 100644 --- a/docs/_stories/suspicious_regsvcs_regasm_activity.md +++ b/docs/_stories/suspicious_regsvcs_regasm_activity.md @@ -30,12 +30,12 @@ Monitor and detect techniques used by attackers who leverage the mshta.exe proce | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect Regasm Spawning a Process](/endpoint/detect_regasm_spawning_a_process/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | -| [Detect Regasm with Network Connection](/endpoint/detect_regasm_with_network_connection/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | -| [Detect Regasm with no Command Line Arguments](/endpoint/detect_regasm_with_no_command_line_arguments/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | -| [Detect Regsvcs Spawning a Process](/endpoint/detect_regsvcs_spawning_a_process/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | -| [Detect Regsvcs with Network Connection](/endpoint/detect_regsvcs_with_network_connection/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | -| [Detect Regsvcs with No Command Line Arguments](/endpoint/detect_regsvcs_with_no_command_line_arguments/) | [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regasm Spawning a Process](/endpoint/detect_regasm_spawning_a_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regasm with Network Connection](/endpoint/detect_regasm_with_network_connection/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regasm with no Command Line Arguments](/endpoint/detect_regasm_with_no_command_line_arguments/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regsvcs Spawning a Process](/endpoint/detect_regsvcs_spawning_a_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regsvcs with Network Connection](/endpoint/detect_regsvcs_with_network_connection/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | +| [Detect Regsvcs with No Command Line Arguments](/endpoint/detect_regsvcs_with_no_command_line_arguments/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | #### Reference diff --git a/docs/_stories/suspicious_regsvr32_activity.md b/docs/_stories/suspicious_regsvr32_activity.md index 468b57b910..e2080cb776 100644 --- a/docs/_stories/suspicious_regsvr32_activity.md +++ b/docs/_stories/suspicious_regsvr32_activity.md @@ -30,8 +30,10 @@ One common adversary tactic is to bypass application control solutions via the r | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect Regsvr32 Application Control Bypass](/endpoint/detect_regsvr32_application_control_bypass/) | [Regsvr32](/tags/#regsvr32) | TTP | -| [Suspicious Regsvr32 Register Suspicious Path](/endpoint/suspicious_regsvr32_register_suspicious_path/) | [Regsvr32](/tags/#regsvr32) | TTP | +| [Detect Regsvr32 Application Control Bypass](/endpoint/detect_regsvr32_application_control_bypass/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | TTP | +| [Malicious InProcServer32 Modification](/endpoint/malicious_inprocserver32_modification/) | [Regsvr32](/tags/#regsvr32), [Modify Registry](/tags/#modify-registry) | TTP | +| [Regsvr32 Silent Param Dll Loading](/endpoint/regsvr32_silent_param_dll_loading/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | TTP | +| [Suspicious Regsvr32 Register Suspicious Path](/endpoint/suspicious_regsvr32_register_suspicious_path/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32) | TTP | #### Reference diff --git a/docs/_stories/suspicious_rundll32_activity.md b/docs/_stories/suspicious_rundll32_activity.md index 719980c449..445e490895 100644 --- a/docs/_stories/suspicious_rundll32_activity.md +++ b/docs/_stories/suspicious_rundll32_activity.md @@ -30,17 +30,17 @@ One common adversary tactic is to bypass application control solutions via the r | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect Rundll32 Application Control Bypass - advpack](/endpoint/detect_rundll32_application_control_bypass_-_advpack/) | [Rundll32](/tags/#rundll32) | TTP | -| [Detect Rundll32 Application Control Bypass - setupapi](/endpoint/detect_rundll32_application_control_bypass_-_setupapi/) | [Rundll32](/tags/#rundll32) | TTP | -| [Detect Rundll32 Application Control Bypass - syssetup](/endpoint/detect_rundll32_application_control_bypass_-_syssetup/) | [Rundll32](/tags/#rundll32) | TTP | -| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory) | TTP | -| [Rundll32 Control RunDLL Hunt](/endpoint/rundll32_control_rundll_hunt/) | [Rundll32](/tags/#rundll32) | Hunting | -| [Rundll32 Control RunDLL World Writable Directory](/endpoint/rundll32_control_rundll_world_writable_directory/) | [Rundll32](/tags/#rundll32) | TTP | -| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [Rundll32](/tags/#rundll32) | TTP | -| [Suspicious Rundll32 Rename](/endpoint/suspicious_rundll32_rename/) | [Rundll32](/tags/#rundll32), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | -| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [Rundll32](/tags/#rundll32) | TTP | -| [Suspicious Rundll32 dllregisterserver](/endpoint/suspicious_rundll32_dllregisterserver/) | [Rundll32](/tags/#rundll32) | TTP | -| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [Rundll32](/tags/#rundll32) | TTP | +| [Detect Rundll32 Application Control Bypass - advpack](/endpoint/detect_rundll32_application_control_bypass_-_advpack/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Detect Rundll32 Application Control Bypass - setupapi](/endpoint/detect_rundll32_application_control_bypass_-_setupapi/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Detect Rundll32 Application Control Bypass - syssetup](/endpoint/detect_rundll32_application_control_bypass_-_syssetup/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Dump LSASS via comsvcs DLL](/endpoint/dump_lsass_via_comsvcs_dll/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Rundll32 Control RunDLL Hunt](/endpoint/rundll32_control_rundll_hunt/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | Hunting | +| [Rundll32 Control RunDLL World Writable Directory](/endpoint/rundll32_control_rundll_world_writable_directory/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Rundll32 with no Command Line Arguments with Network](/endpoint/rundll32_with_no_command_line_arguments_with_network/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious Rundll32 Rename](/endpoint/suspicious_rundll32_rename/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Masquerading](/tags/#masquerading), [Rundll32](/tags/#rundll32), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | +| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious Rundll32 dllregisterserver](/endpoint/suspicious_rundll32_dllregisterserver/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious Rundll32 no Command Line Arguments](/endpoint/suspicious_rundll32_no_command_line_arguments/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | #### Reference diff --git a/docs/_stories/suspicious_windows_registry_activities.md b/docs/_stories/suspicious_windows_registry_activities.md index d5bb596658..86a6df8f30 100644 --- a/docs/_stories/suspicious_windows_registry_activities.md +++ b/docs/_stories/suspicious_windows_registry_activities.md @@ -32,11 +32,12 @@ Attackers are developing increasingly sophisticated techniques for hijacking tar | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors) | TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | -| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection) | TTP | -| [Registry Keys for Creating SHIM Databases](/endpoint/registry_keys_for_creating_shim_databases/) | [Application Shimming](/tags/#application-shimming) | TTP | +| [Disable UAC Remote Restriction](/endpoint/disable_uac_remote_restriction/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Registry Keys for Creating SHIM Databases](/endpoint/registry_keys_for_creating_shim_databases/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | #### Reference diff --git a/docs/_stories/suspicious_wmi_use.md b/docs/_stories/suspicious_wmi_use.md index 051927f838..3a72b51fa2 100644 --- a/docs/_stories/suspicious_wmi_use.md +++ b/docs/_stories/suspicious_wmi_use.md @@ -30,13 +30,13 @@ WMI is a Microsoft infrastructure for management data and operations on Windows | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect WMI Event Subscription Persistence](/endpoint/detect_wmi_event_subscription_persistence/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription) | TTP | +| [Detect WMI Event Subscription Persistence](/endpoint/detect_wmi_event_subscription_persistence/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [Process Execution via WMI](/endpoint/process_execution_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | | [Remote Process Instantiation via WMI](/endpoint/remote_process_instantiation_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | | [Remote WMI Command Attempt](/endpoint/remote_wmi_command_attempt/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | | [Script Execution via WMI](/endpoint/script_execution_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | | [WMI Permanent Event Subscription](/endpoint/wmi_permanent_event_subscription/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | -| [WMI Permanent Event Subscription - Sysmon](/endpoint/wmi_permanent_event_subscription_-_sysmon/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription) | TTP | +| [WMI Permanent Event Subscription - Sysmon](/endpoint/wmi_permanent_event_subscription_-_sysmon/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [WMI Temporary Event Subscription](/endpoint/wmi_temporary_event_subscription/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | #### Reference diff --git a/docs/_stories/suspicious_zoom_child_processes.md b/docs/_stories/suspicious_zoom_child_processes.md index f57871c652..1024cbb631 100644 --- a/docs/_stories/suspicious_zoom_child_processes.md +++ b/docs/_stories/suspicious_zoom_child_processes.md @@ -31,7 +31,7 @@ Current detections focus on finding new child processes of this application on a | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Windows Command Shell](/tags/#windows-command-shell) | Hunting | +| [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell) | Hunting | | [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | TTP | | [First Time Seen Child Process of Zoom](/endpoint/first_time_seen_child_process_of_zoom/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | Anomaly | diff --git a/docs/_stories/trickbot.md b/docs/_stories/trickbot.md index fc9312172c..59adc8961a 100644 --- a/docs/_stories/trickbot.md +++ b/docs/_stories/trickbot.md @@ -30,21 +30,21 @@ trickbot banking trojan campaigns targeting banks and other vertical sectors.Thi | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Account Discovery With Net App](/endpoint/account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account) | TTP | -| [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Account Discovery With Net App](/endpoint/account_discovery_with_net_app/) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery) | TTP | +| [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Cobalt Strike Named Pipes](/endpoint/cobalt_strike_named_pipes/) | [Process Injection](/tags/#process-injection) | TTP | -| [Mshta spawning Rundll32 OR Regsvr32 Process](/endpoint/mshta_spawning_rundll32_or_regsvr32_process/) | [Mshta](/tags/#mshta) | TTP | -| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | -| [Office Product Spawn CMD Process](/endpoint/office_product_spawn_cmd_process/) | [Mshta](/tags/#mshta) | TTP | +| [Mshta spawning Rundll32 OR Regsvr32 Process](/endpoint/mshta_spawning_rundll32_or_regsvr32_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | +| [Office Application Spawn rundll32 process](/endpoint/office_application_spawn_rundll32_process/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Document Executing Macro Code](/endpoint/office_document_executing_macro_code/) | [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment) | TTP | +| [Office Product Spawn CMD Process](/endpoint/office_product_spawn_cmd_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta) | TTP | | [Powershell Remote Thread To Known Windows Process](/endpoint/powershell_remote_thread_to_known_windows_process/) | [Process Injection](/tags/#process-injection) | TTP | | [Schedule Task with Rundll32 Command Trigger](/endpoint/schedule_task_with_rundll32_command_trigger/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | -| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [Rundll32](/tags/#rundll32) | TTP | +| [Suspicious Rundll32 StartW](/endpoint/suspicious_rundll32_startw/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | | [Trickbot Named Pipe](/endpoint/trickbot_named_pipe/) | [Process Injection](/tags/#process-injection) | TTP | -| [Wermgr Process Connecting To IP Check Web Services](/endpoint/wermgr_process_connecting_to_ip_check_web_services/) | [IP Addresses](/tags/#ip-addresses) | TTP | +| [Wermgr Process Connecting To IP Check Web Services](/endpoint/wermgr_process_connecting_to_ip_check_web_services/) | [Gather Victim Network Information](/tags/#gather-victim-network-information), [IP Addresses](/tags/#ip-addresses) | TTP | | [Wermgr Process Create Executable File](/endpoint/wermgr_process_create_executable_file/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information) | TTP | | [Wermgr Process Spawned CMD Or Powershell Process](/endpoint/wermgr_process_spawned_cmd_or_powershell_process/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | TTP | -| [Write Executable in SMB Share](/endpoint/write_executable_in_smb_share/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Write Executable in SMB Share](/endpoint/write_executable_in_smb_share/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | #### Reference diff --git a/docs/_stories/trusted_developer_utilities_proxy_execution.md b/docs/_stories/trusted_developer_utilities_proxy_execution.md index 927fb15e23..f10fddc439 100644 --- a/docs/_stories/trusted_developer_utilities_proxy_execution.md +++ b/docs/_stories/trusted_developer_utilities_proxy_execution.md @@ -31,7 +31,7 @@ The searches in this story help you detect and investigate suspicious activity t | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | +| [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | | [Suspicious microsoft workflow compiler usage](/endpoint/suspicious_microsoft_workflow_compiler_usage/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution) | TTP | #### Reference diff --git a/docs/_stories/trusted_developer_utilities_proxy_execution_msbuild.md b/docs/_stories/trusted_developer_utilities_proxy_execution_msbuild.md index 30cc38c193..1494782a0f 100644 --- a/docs/_stories/trusted_developer_utilities_proxy_execution_msbuild.md +++ b/docs/_stories/trusted_developer_utilities_proxy_execution_msbuild.md @@ -43,9 +43,10 @@ The objective of this step is to confirm the executed script code is benign or m | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | -| [Suspicious MSBuild Spawn](/endpoint/suspicious_msbuild_spawn/) | [MSBuild](/tags/#msbuild) | TTP | -| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [MSBuild](/tags/#msbuild), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | +| [MSBuild Suspicious Spawned By Script Process](/endpoint/msbuild_suspicious_spawned_by_script_process/) | [MSBuild](/tags/#msbuild), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution) | TTP | +| [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | TTP | +| [Suspicious MSBuild Spawn](/endpoint/suspicious_msbuild_spawn/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [MSBuild](/tags/#msbuild) | TTP | +| [Suspicious msbuild path](/endpoint/suspicious_msbuild_path/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | TTP | #### Reference diff --git a/docs/_stories/unusual_processes.md b/docs/_stories/unusual_processes.md index 359310e8cd..537355d6cb 100644 --- a/docs/_stories/unusual_processes.md +++ b/docs/_stories/unusual_processes.md @@ -32,7 +32,7 @@ In the event an unusual process is identified, it is imperative to better unders | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Active Scanning](/tags/#active-scanning), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning) | TTP | | [Credential Extraction indicative of FGDump and CacheDump with s option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction indicative of FGDump and CacheDump with v option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Extraction indicative of use of Mimikatz modules](/endpoint/credential_extraction_indicative_of_use_of_mimikatz_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | @@ -43,12 +43,16 @@ In the event an unusual process is identified, it is imperative to better unders | [First time seen command line argument](/endpoint/first_time_seen_command_line_argument/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Regsvr32](/tags/#regsvr32), [Indirect Command Execution](/tags/#indirect-command-execution) | Anomaly | | [More than usual number of LOLBAS applications in short time period](/endpoint/more_than_usual_number_of_lolbas_applications_in_short_time_period/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Scheduled Task/Job](/tags/#scheduled-task/job) | Anomaly | | [Rare Parent-Child Process Relationship](/endpoint/rare_parent-child_process_relationship/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Scheduled Task/Job](/tags/#scheduled-task/job), [Software Deployment Tools](/tags/#software-deployment-tools) | Anomaly | -| [RunDLL Loading DLL By Ordinal](/endpoint/rundll_loading_dll_by_ordinal/) | [Rundll32](/tags/#rundll32) | TTP | -| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Rename System Utilities](/tags/#rename-system-utilities) | TTP | +| [RunDLL Loading DLL By Ordinal](/endpoint/rundll_loading_dll_by_ordinal/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | +| [Rundll32 Shimcache Flush](/endpoint/rundll32_shimcache_flush/) | [Modify Registry](/tags/#modify-registry) | TTP | +| [Suspicious Copy on System32](/endpoint/suspicious_copy_on_system32/) | [Rename System Utilities](/tags/#rename-system-utilities), [Masquerading](/tags/#masquerading) | TTP | +| [System Processes Run From Unexpected Locations](/endpoint/system_processes_run_from_unexpected_locations/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | | [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | | Anomaly | | [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | | Anomaly | | [Unusually Long Command Line - MLTK](/endpoint/unusually_long_command_line_-_mltk/) | | Anomaly | +| [Verclsid CLSID Execution](/endpoint/verclsid_clsid_execution/) | [Verclsid](/tags/#verclsid), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution) | Hunting | | [WinRM Spawning a Process](/endpoint/winrm_spawning_a_process/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | TTP | +| [Wscript Or Cscript Suspicious Child Process](/endpoint/wscript_or_cscript_suspicious_child_process/) | [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation) | TTP | #### Reference diff --git a/docs/_stories/windows_defense_evasion_tactics.md b/docs/_stories/windows_defense_evasion_tactics.md index 9054a39c77..8361d5b752 100644 --- a/docs/_stories/windows_defense_evasion_tactics.md +++ b/docs/_stories/windows_defense_evasion_tactics.md @@ -30,32 +30,34 @@ Defense evasion is a tactic--identified in the MITRE ATT&CK framework--that adve | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Disable Registry Tool](/endpoint/disable_registry_tool/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disable Show Hidden Files](/endpoint/disable_show_hidden_files/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disable Windows SmartScreen Protection](/endpoint/disable_windows_smartscreen_protection/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling CMD Application](/endpoint/disabling_cmd_application/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling ControlPanel](/endpoint/disabling_controlpanel/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling Firewall with Netsh](/endpoint/disabling_firewall_with_netsh/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling FolderOptions Windows Feature](/endpoint/disabling_folderoptions_windows_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling NoRun Windows App](/endpoint/disabling_norun_windows_app/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [Disabling SystemRestore In Registry](/endpoint/disabling_systemrestore_in_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Disabling Task Manager](/endpoint/disabling_task_manager/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | -| [Eventvwr UAC Bypass](/endpoint/eventvwr_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [Excessive number of service control start as disabled](/endpoint/excessive_number_of_service_control_start_as_disabled/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | Anomaly | -| [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | -| [NET Profiler UAC bypass](/endpoint/net_profiler_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [SLUI RunAs Elevated](/endpoint/slui_runas_elevated/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [SLUI Spawning a Process](/endpoint/slui_spawning_a_process/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [Sdclt UAC Bypass](/endpoint/sdclt_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [SilentCleanup UAC Bypass](/endpoint/silentcleanup_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | +| [Disable Registry Tool](/endpoint/disable_registry_tool/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable Security Logs Using MiniNt Registry](/endpoint/disable_security_logs_using_minint_registry/) | [Modify Registry](/tags/#modify-registry) | TTP | +| [Disable Show Hidden Files](/endpoint/disable_show_hidden_files/) | [Hidden Files and Directories](/tags/#hidden-files-and-directories), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Hide Artifacts](/tags/#hide-artifacts), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable UAC Remote Restriction](/endpoint/disable_uac_remote_restriction/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disable Windows SmartScreen Protection](/endpoint/disable_windows_smartscreen_protection/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling CMD Application](/endpoint/disabling_cmd_application/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling ControlPanel](/endpoint/disabling_controlpanel/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling Firewall with Netsh](/endpoint/disabling_firewall_with_netsh/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling FolderOptions Windows Feature](/endpoint/disabling_folderoptions_windows_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling NoRun Windows App](/endpoint/disabling_norun_windows_app/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling Remote User Account Control](/endpoint/disabling_remote_user_account_control/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Disabling SystemRestore In Registry](/endpoint/disabling_systemrestore_in_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Disabling Task Manager](/endpoint/disabling_task_manager/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Eventvwr UAC Bypass](/endpoint/eventvwr_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Excessive number of service control start as disabled](/endpoint/excessive_number_of_service_control_start_as_disabled/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | Anomaly | +| [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | +| [NET Profiler UAC bypass](/endpoint/net_profiler_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [SLUI RunAs Elevated](/endpoint/slui_runas_elevated/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [SLUI Spawning a Process](/endpoint/slui_spawning_a_process/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Sdclt UAC Bypass](/endpoint/sdclt_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [SilentCleanup UAC Bypass](/endpoint/silentcleanup_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Suspicious Reg exe Process](/endpoint/suspicious_reg_exe_process/) | [Modify Registry](/tags/#modify-registry) | TTP | | [System Process Running from Unexpected Location](/endpoint/system_process_running_from_unexpected_location/) | [Masquerading](/tags/#masquerading) | Anomaly | -| [UAC Bypass MMC Load Unsigned Dll](/endpoint/uac_bypass_mmc_load_unsigned_dll/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [WSReset UAC Bypass](/endpoint/wsreset_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control) | TTP | -| [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [UAC Bypass MMC Load Unsigned Dll](/endpoint/uac_bypass_mmc_load_unsigned_dll/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [WSReset UAC Bypass](/endpoint/wsreset_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | +| [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | #### Reference diff --git a/docs/_stories/windows_discovery_techniques.md b/docs/_stories/windows_discovery_techniques.md index cf75442434..d0d3686229 100644 --- a/docs/_stories/windows_discovery_techniques.md +++ b/docs/_stories/windows_discovery_techniques.md @@ -35,14 +35,14 @@ Attackers may not have much if any insight into their target's environment befor | [Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit modules](/endpoint/reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules/) | [Trusted Relationship](/tags/#trusted-relationship), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Gather Victim Org Information](/tags/#gather-victim-org-information), [Active Scanning](/tags/#active-scanning) | TTP | | [Reconnaissance and Access to Computers and Domains via PowerSploit modules](/endpoint/reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules/) | [Gather Victim Host Information](/tags/#gather-victim-host-information), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Account Discovery](/tags/#account-discovery) | TTP | | [Reconnaissance and Access to Computers via Mimikatz modules](/endpoint/reconnaissance_and_access_to_computers_via_mimikatz_modules/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | -| [Reconnaissance and Access to Operating System Elements via PowerSploit modules](/endpoint/reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules/) | [System Service Discovery](/tags/#system-service-discovery), [Query Registry](/tags/#query-registry), [Network Service Scanning](/tags/#network-service-scanning), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Process Discovery](/tags/#process-discovery), [File and Directory Discovery](/tags/#file-and-directory-discovery), [Software Discovery](/tags/#software-discovery), [Software](/tags/#software) | TTP | +| [Reconnaissance and Access to Operating System Elements via PowerSploit modules](/endpoint/reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules/) | [Process Discovery](/tags/#process-discovery), [File and Directory Discovery](/tags/#file-and-directory-discovery), [Software](/tags/#software), [Network Service Scanning](/tags/#network-service-scanning), [Query Registry](/tags/#query-registry), [System Service Discovery](/tags/#system-service-discovery), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Software Discovery](/tags/#software-discovery) | TTP | | [Reconnaissance and Access to Processes and Services via Mimikatz modules](/endpoint/reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules/) | [System Service Discovery](/tags/#system-service-discovery), [Network Service Scanning](/tags/#network-service-scanning), [Process Discovery](/tags/#process-discovery) | TTP | -| [Reconnaissance and Access to Shared Resources via Mimikatz modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_mimikatz_modules/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Network Share Discovery](/tags/#network-share-discovery), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive) | TTP | -| [Reconnaissance and Access to Shared Resources via PowerSploit modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_powersploit_modules/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Network Share Discovery](/tags/#network-share-discovery), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive) | TTP | +| [Reconnaissance and Access to Shared Resources via Mimikatz modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_mimikatz_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Reconnaissance and Access to Shared Resources via PowerSploit modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | | [Reconnaissance of Access and Persistence Opportunities via PowerSploit modules](/endpoint/reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | -| [Reconnaissance of Connectivity via PowerSploit modules](/endpoint/reconnaissance_of_connectivity_via_powersploit_modules/) | [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Network Share Discovery](/tags/#network-share-discovery), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive) | TTP | -| [Reconnaissance of Credential Stores and Services via Mimikatz modules](/endpoint/reconnaissance_of_credential_stores_and_services_via_mimikatz_modules/) | [Credentials](/tags/#credentials), [Domain Properties](/tags/#domain-properties), [Network Trust Dependencies](/tags/#network-trust-dependencies), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Reconnaissance of Defensive Tools via PowerSploit modules](/endpoint/reconnaissance_of_defensive_tools_via_powersploit_modules/) | [Vulnerability Scanning](/tags/#vulnerability-scanning), [Software](/tags/#software) | TTP | +| [Reconnaissance of Connectivity via PowerSploit modules](/endpoint/reconnaissance_of_connectivity_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Reconnaissance of Credential Stores and Services via Mimikatz modules](/endpoint/reconnaissance_of_credential_stores_and_services_via_mimikatz_modules/) | [Account Manipulation](/tags/#account-manipulation), [Domain Properties](/tags/#domain-properties), [Valid Accounts](/tags/#valid-accounts), [Credentials](/tags/#credentials), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Gather Victim Identity Information](/tags/#gather-victim-identity-information), [Network Trust Dependencies](/tags/#network-trust-dependencies) | TTP | +| [Reconnaissance of Defensive Tools via PowerSploit modules](/endpoint/reconnaissance_of_defensive_tools_via_powersploit_modules/) | [Software](/tags/#software), [Vulnerability Scanning](/tags/#vulnerability-scanning), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Active Scanning](/tags/#active-scanning) | TTP | | [Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules](/endpoint/reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | | [Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules](/endpoint/reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Process Injection](/tags/#process-injection), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | diff --git a/docs/_stories/windows_file_extension_and_association_abuse.md b/docs/_stories/windows_file_extension_and_association_abuse.md index 7182428ee0..5120875c71 100644 --- a/docs/_stories/windows_file_extension_and_association_abuse.md +++ b/docs/_stories/windows_file_extension_and_association_abuse.md @@ -34,7 +34,7 @@ Run the searches in this story to detect and investigate suspicious behavior tha | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Execution of File with Multiple Extensions](/endpoint/execution_of_file_with_multiple_extensions/) | [Rename System Utilities](/tags/#rename-system-utilities) | TTP | +| [Execution of File with Multiple Extensions](/endpoint/execution_of_file_with_multiple_extensions/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | TTP | #### Reference diff --git a/docs/_stories/windows_log_manipulation.md b/docs/_stories/windows_log_manipulation.md index 3730051e98..cb1be485de 100644 --- a/docs/_stories/windows_log_manipulation.md +++ b/docs/_stories/windows_log_manipulation.md @@ -33,12 +33,12 @@ The Analytic Story gives users two different ways to detect manipulation of Wind | ----------- | ----------- |--------------| | [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Illegal Deletion of Logs via Mimikatz modules](/endpoint/illegal_deletion_of_logs_via_mimikatz_modules/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | -| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [USN Journal Deletion](/endpoint/usn_journal_deletion/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | -| [WevtUtil Usage To Clear Logs](/endpoint/wevtutil_usage_to_clear_logs/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [Wevtutil Usage To Disable Logs](/endpoint/wevtutil_usage_to_disable_logs/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [WevtUtil Usage To Clear Logs](/endpoint/wevtutil_usage_to_clear_logs/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Wevtutil Usage To Disable Logs](/endpoint/wevtutil_usage_to_disable_logs/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | +| [Windows Event Log Cleared](/endpoint/windows_event_log_cleared/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | #### Reference diff --git a/docs/_stories/windows_persistence_techniques.md b/docs/_stories/windows_persistence_techniques.md index f83b173379..b74de5fd92 100644 --- a/docs/_stories/windows_persistence_techniques.md +++ b/docs/_stories/windows_persistence_techniques.md @@ -30,30 +30,37 @@ Maintaining persistence is one of the first steps taken by attackers after the i | Name | Technique | Type | | ----------- | ----------- |--------------| +| [Active Setup Registry Autostart](/endpoint/active_setup_registry_autostart/) | [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Certutil exe certificate extraction](/endpoint/certutil_exe_certificate_extraction/) | | TTP | -| [Detect Path Interception By Creation Of program exe](/endpoint/detect_path_interception_by_creation_of_program_exe/) | [Path Interception by Unquoted Path](/tags/#path-interception-by-unquoted-path) | TTP | -| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | +| [Change Default File Association](/endpoint/change_default_file_association/) | [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Detect Path Interception By Creation Of program exe](/endpoint/detect_path_interception_by_creation_of_program_exe/) | [Path Interception by Unquoted Path](/tags/#path-interception-by-unquoted-path), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | +| [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | | [Illegal Account Creation via PowerSploit modules](/endpoint/illegal_account_creation_via_powersploit_modules/) | [Establish Accounts](/tags/#establish-accounts) | TTP | | [Illegal Enabling or Disabling of Accounts via DSInternals modules](/endpoint/illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | | [Illegal Management of Active Directory Elements and Policies via DSInternals modules](/endpoint/illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules/) | [Account Manipulation](/tags/#account-manipulation), [Rogue Domain Controller](/tags/#rogue-domain-controller), [Domain Policy Modification](/tags/#domain-policy-modification) | TTP | | [Illegal Management of Computers and Active Directory Elements via PowerSploit modules](/endpoint/illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules/) | [Account Manipulation](/tags/#account-manipulation), [Rogue Domain Controller](/tags/#rogue-domain-controller), [Domain Policy Modification](/tags/#domain-policy-modification) | TTP | | [Illegal Privilege Elevation and Persistence via PowerSploit modules](/endpoint/illegal_privilege_elevation_and_persistence_via_powersploit_modules/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Access Token Manipulation](/tags/#access-token-manipulation), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | -| [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors) | TTP | -| [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness) | TTP | -| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder) | TTP | -| [Registry Keys for Creating SHIM Databases](/endpoint/registry_keys_for_creating_shim_databases/) | [Application Shimming](/tags/#application-shimming) | TTP | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service) | TTP | +| [Logon Script Event Trigger Execution](/endpoint/logon_script_event_trigger_execution/) | [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)) | TTP | +| [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | +| [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Registry Keys for Creating SHIM Databases](/endpoint/registry_keys_for_creating_shim_databases/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [Schedule Task with HTTP Command Arguments](/endpoint/schedule_task_with_http_command_arguments/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | | [Schedule Task with Rundll32 Command Trigger](/endpoint/schedule_task_with_rundll32_command_trigger/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | -| [Schtasks used for forcing a reboot](/endpoint/schtasks_used_for_forcing_a_reboot/) | [Scheduled Task](/tags/#scheduled-task) | TTP | +| [Schtasks used for forcing a reboot](/endpoint/schtasks_used_for_forcing_a_reboot/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [Screensaver Event Trigger Execution](/endpoint/screensaver_event_trigger_execution/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Screensaver](/tags/#screensaver) | TTP | | [Setting Credentials via DSInternals modules](/endpoint/setting_credentials_via_dsinternals_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | | [Setting Credentials via Mimikatz modules](/endpoint/setting_credentials_via_mimikatz_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | | [Setting Credentials via PowerSploit modules](/endpoint/setting_credentials_via_powersploit_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Shim Database File Creation](/endpoint/shim_database_file_creation/) | [Application Shimming](/tags/#application-shimming) | TTP | -| [Shim Database Installation With Suspicious Parameters](/endpoint/shim_database_installation_with_suspicious_parameters/) | [Application Shimming](/tags/#application-shimming) | TTP | -| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task) | Anomaly | -| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task) | TTP | -| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task) | TTP | +| [Shim Database File Creation](/endpoint/shim_database_file_creation/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Shim Database Installation With Suspicious Parameters](/endpoint/shim_database_installation_with_suspicious_parameters/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | Anomaly | +| [Time Provider Persistence Registry](/endpoint/time_provider_persistence_registry/) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | #### Reference diff --git a/docs/_stories/windows_privilege_escalation.md b/docs/_stories/windows_privilege_escalation.md index 5f3c6562bd..37a0550cc8 100644 --- a/docs/_stories/windows_privilege_escalation.md +++ b/docs/_stories/windows_privilege_escalation.md @@ -30,11 +30,18 @@ Privilege escalation is a "land-and-expand" technique, wherein an adversary gain | Name | Technique | Type | | ----------- | ----------- |--------------| +| [Active Setup Registry Autostart](/endpoint/active_setup_registry_autostart/) | [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | +| [Change Default File Association](/endpoint/change_default_file_association/) | [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [Child Processes of Spoolsv exe](/endpoint/child_processes_of_spoolsv_exe/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | TTP | +| [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Illegal Privilege Elevation via Mimikatz modules](/endpoint/illegal_privilege_elevation_via_mimikatz_modules/) | [Access Token Manipulation](/tags/#access-token-manipulation), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | -| [Overwriting Accessibility Binaries](/endpoint/overwriting_accessibility_binaries/) | [Accessibility Features](/tags/#accessibility-features) | TTP | +| [Logon Script Event Trigger Execution](/endpoint/logon_script_event_trigger_execution/) | [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)) | TTP | +| [Overwriting Accessibility Binaries](/endpoint/overwriting_accessibility_binaries/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Accessibility Features](/tags/#accessibility-features) | TTP | +| [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Probing Access with Stolen Credentials via PowerSploit modules](/endpoint/probing_access_with_stolen_credentials_via_powersploit_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection) | TTP | +| [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Screensaver Event Trigger Execution](/endpoint/screensaver_event_trigger_execution/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Screensaver](/tags/#screensaver) | TTP | +| [Time Provider Persistence Registry](/endpoint/time_provider_persistence_registry/) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | #### Reference diff --git a/docs/_stories/windows_service_abuse.md b/docs/_stories/windows_service_abuse.md index cb0820168a..01821b3d60 100644 --- a/docs/_stories/windows_service_abuse.md +++ b/docs/_stories/windows_service_abuse.md @@ -30,11 +30,11 @@ The Windows operating system uses a services architecture to allow for running c | Name | Technique | Type | | ----------- | ----------- |--------------| -| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [Service Execution](/tags/#service-execution) | Anomaly | +| [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Anomaly | | [Illegal Service and Process Control via Mimikatz modules](/endpoint/illegal_service_and_process_control_via_mimikatz_modules/) | [Process Injection](/tags/#process-injection), [Native API](/tags/#native-api), [System Services](/tags/#system-services) | TTP | | [Illegal Service and Process Control via PowerSploit modules](/endpoint/illegal_service_and_process_control_via_powersploit_modules/) | [Process Injection](/tags/#process-injection), [Native API](/tags/#native-api), [System Services](/tags/#system-services) | TTP | -| [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness) | TTP | -| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service) | TTP | +| [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | +| [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | #### Reference diff --git a/docs/_stories/xmrig.md b/docs/_stories/xmrig.md index 0791d66d3e..a8a2207afa 100644 --- a/docs/_stories/xmrig.md +++ b/docs/_stories/xmrig.md @@ -30,14 +30,14 @@ XMRig is a high performance, open source, cross platform RandomX, KawPow, Crypto | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Active Scanning](/tags/#active-scanning), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning) | TTP | | [Attempt To Disable Services](/endpoint/attempt_to_disable_services/) | [Service Stop](/tags/#service-stop) | TTP | | [Attempt To delete Services](/endpoint/attempt_to_delete_services/) | [Service Stop](/tags/#service-stop) | TTP | | [Delete A Net User](/endpoint/delete_a_net_user/) | [Service Stop](/tags/#service-stop) | Anomaly | | [Deleting Of Net Users](/endpoint/deleting_of_net_users/) | [Account Access Removal](/tags/#account-access-removal) | TTP | | [Deny Permission using Cacls Utility](/endpoint/deny_permission_using_cacls_utility/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [Disable Net User Account](/endpoint/disable_net_user_account/) | [Service Stop](/tags/#service-stop) | TTP | -| [Disable Windows App Hotkeys](/endpoint/disable_windows_app_hotkeys/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Disable Windows App Hotkeys](/endpoint/disable_windows_app_hotkeys/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disabling Net User Account](/endpoint/disabling_net_user_account/) | [Account Access Removal](/tags/#account-access-removal) | TTP | | [Download Files Using Telegram](/endpoint/download_files_using_telegram/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [Enumerate Users Local Group Using Telegram](/endpoint/enumerate_users_local_group_using_telegram/) | [Account Discovery](/tags/#account-discovery) | TTP | @@ -45,19 +45,19 @@ XMRig is a high performance, open source, cross platform RandomX, KawPow, Crypto | [Excessive Service Stop Attempt](/endpoint/excessive_service_stop_attempt/) | [Service Stop](/tags/#service-stop) | Anomaly | | [Excessive Usage Of Cacls App](/endpoint/excessive_usage_of_cacls_app/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | Anomaly | | [Excessive Usage Of Net App](/endpoint/excessive_usage_of_net_app/) | [Account Access Removal](/tags/#account-access-removal) | Anomaly | -| [Excessive Usage Of Taskkill](/endpoint/excessive_usage_of_taskkill/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | Anomaly | +| [Excessive Usage Of Taskkill](/endpoint/excessive_usage_of_taskkill/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | Anomaly | | [Executables Or Script Creation In Suspicious Path](/endpoint/executables_or_script_creation_in_suspicious_path/) | [Masquerading](/tags/#masquerading) | TTP | | [Grant Permission Using Cacls Utility](/endpoint/grant_permission_using_cacls_utility/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | -| [Hide User Account From Sign-In Screen](/endpoint/hide_user_account_from_sign-in_screen/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Hide User Account From Sign-In Screen](/endpoint/hide_user_account_from_sign-in_screen/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [ICACLS Grant Command](/endpoint/icacls_grant_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [Icacls Deny Command](/endpoint/icacls_deny_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [Modify ACL permission To Files Or Folder](/endpoint/modify_acl_permission_to_files_or_folder/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [Modify ACLs Permission Of Files Or Folders](/endpoint/modify_acls_permission_of_files_or_folders/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | Anomaly | -| [Process Kill Base On File Path](/endpoint/process_kill_base_on_file_path/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools) | TTP | +| [Process Kill Base On File Path](/endpoint/process_kill_base_on_file_path/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Schtasks Run Task On Demand](/endpoint/schtasks_run_task_on_demand/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | -| [Suspicious Driver Loaded Path](/endpoint/suspicious_driver_loaded_path/) | [Windows Service](/tags/#windows-service) | TTP | +| [Suspicious Driver Loaded Path](/endpoint/suspicious_driver_loaded_path/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | | [Suspicious Process File Path](/endpoint/suspicious_process_file_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | -| [XMRIG Driver Loaded](/endpoint/xmrig_driver_loaded/) | [Windows Service](/tags/#windows-service) | TTP | +| [XMRIG Driver Loaded](/endpoint/xmrig_driver_loaded/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | #### Reference diff --git a/docs/detections.wiki b/docs/detections.wiki index 8dad067eaf..ca4efb76dc 100644 --- a/docs/detections.wiki +++ b/docs/detections.wiki @@ -144,7 +144,7 @@ The search looks at the change-analysis data model and detects email files creat * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/001/ T1114.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/ T1114], [https://attack.mitre.org/techniques/T1114/001/ T1114.001] * '''Last Updated''': 2020-07-21
@@ -188,6 +188,10 @@ To successfully implement this search, you must be ingesting data that records t ! Technique ! Tactic |- +| T1114 +| Email Collection +| Collection +|- | T1114.001 | Local Email Collection | Collection @@ -219,7 +223,7 @@ This search looks for an increase of data transfers from your email server to yo * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/002/ T1114.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/ T1114], [https://attack.mitre.org/techniques/T1114/002/ T1114.002] * '''Last Updated''': 2020-07-21
@@ -265,6 +269,10 @@ This search requires you to be ingesting your network traffic and populating the ! Technique ! Tactic |- +| T1114 +| Email Collection +| Collection +|- | T1114.002 | Remote Email Collection | Collection @@ -363,7 +371,7 @@ This search detects Okta login failures due to bad credentials for multiple user * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/001/ T1078.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/001/ T1078.001] * '''Last Updated''': 2020-07-21
@@ -412,6 +420,10 @@ This search is specific to Okta and requires Okta logs are being ingested in you ! Technique ! Tactic |- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- | T1078.001 | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access @@ -504,7 +516,7 @@ Detect Okta user lockout events * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/001/ T1078.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/001/ T1078.001] * '''Last Updated''': 2020-07-21
@@ -544,6 +556,10 @@ This search is specific to Okta and requires Okta logs are being ingested in you ! Technique ! Tactic |- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- | T1078.001 | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access @@ -573,7 +589,7 @@ Detect failed Okta SSO events * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/001/ T1078.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/001/ T1078.001] * '''Last Updated''': 2020-07-21
@@ -616,6 +632,10 @@ This search is specific to Okta and requires Okta logs are being ingested in you ! Technique ! Tactic |- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- | T1078.001 | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access @@ -645,7 +665,7 @@ This search detects logins from the same user from different cities in a 24 hour * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/001/ T1078.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/001/ T1078.001] * '''Last Updated''': 2020-07-21
@@ -687,6 +707,10 @@ This search is specific to Okta and requires Okta logs are being ingested in you ! Technique ! Tactic |- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- | T1078.001 | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access @@ -783,7 +807,7 @@ This search looks for emails that have attachments with suspicious file extensio * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Email -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001], [https://attack.mitre.org/techniques/T1566/ T1566] * '''Last Updated''': 2020-07-22
@@ -831,6 +855,10 @@ If Splunk Phantom is also configured in your environment, a Playbook called " | T1566.001 | Spearphishing Attachment | Initial Access +|- +| T1566 +| Phishing +| Initial Access |} @@ -1011,7 +1039,7 @@ This search looks for AWS CloudTrail events where a user created a policy versio * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2021-02-22
@@ -1059,6 +1087,10 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit | T1078.004 | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access |} @@ -1095,7 +1127,7 @@ This search looks for AWS CloudTrail events where a user A who has already permi * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] * '''Last Updated''': 2021-07-19
@@ -1140,6 +1172,10 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit | T1136.003 | Cloud Account | Persistence +|- +| T1136 +| Create Account +| Persistence |} @@ -1176,7 +1212,7 @@ This search looks for AWS CloudTrail events where a user A(victim A) creates a l * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] * '''Last Updated''': 2021-07-19
@@ -1225,6 +1261,10 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit | T1136.003 | Cloud Account | Persistence +|- +| T1136 +| Create Account +| Persistence |} @@ -1511,7 +1551,7 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] * '''Last Updated''': 2021-08-17
@@ -1571,6 +1611,10 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit | T1204.003 | Malicious Image | Execution +|- +| T1204 +| User Execution +| Execution |} @@ -1603,7 +1647,7 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] * '''Last Updated''': 2021-08-17
@@ -1663,6 +1707,10 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit | T1204.003 | Malicious Image | Execution +|- +| T1204 +| User Execution +| Execution |} @@ -1695,7 +1743,7 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] * '''Last Updated''': 2021-08-17
@@ -1755,6 +1803,10 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit | T1204.003 | Malicious Image | Execution +|- +| T1204 +| User Execution +| Execution |} @@ -1787,7 +1839,7 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] * '''Last Updated''': 2021-08-19
@@ -1843,6 +1895,10 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit | T1204.003 | Malicious Image | Execution +|- +| T1204 +| User Execution +| Execution |} @@ -1875,7 +1931,7 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] * '''Last Updated''': 2021-08-19
@@ -1931,6 +1987,10 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit | T1204.003 | Malicious Image | Execution +|- +| T1204 +| User Execution +| Execution |} @@ -2373,7 +2433,7 @@ The following query uses IAM events to track the success of a group being delete * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Splunk Security Analytics for AWS * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/003/ T1069.003], [https://attack.mitre.org/techniques/T1098/ T1098] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/003/ T1069.003], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1069/ T1069] * '''Last Updated''': 2021-03-31
@@ -2421,6 +2481,10 @@ The Splunk AWS Add-on and Splunk App for AWS is required to utilize this data. T | T1098 | Account Manipulation | Persistence +|- +| T1069 +| Permission Groups Discovery +| Discovery |} @@ -2457,7 +2521,7 @@ The search looks for AWS CloudTrail events to detect if any network ACLs were cr * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-01-11
@@ -2517,6 +2581,10 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- | T1562.007 | Disable or Modify Cloud Firewall | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -2547,7 +2615,7 @@ Enforcing network-access controls is one of the defensive mechanisms used by clo * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-01-12
@@ -2596,6 +2664,10 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- | T1562.007 | Disable or Modify Cloud Firewall | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -2804,7 +2876,7 @@ This search looks for AWS CloudTrail events where a user has set a default polic * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2021-03-02
@@ -2850,6 +2922,10 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit | T1078.004 | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access |} @@ -2886,7 +2962,7 @@ This search looks for AWS CloudTrail events where a user A who has already permi * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] * '''Last Updated''': 2021-07-19
@@ -2931,6 +3007,10 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit | T1136.003 | Cloud Account | Persistence +|- +| T1136 +| Create Account +| Persistence |} @@ -2967,7 +3047,7 @@ This search will detect a spike in the number of API calls made to your cloud in * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2020-09-07
@@ -3021,6 +3101,10 @@ You must be ingesting your cloud infrastructure logs. You also must run the base | T1078.004 | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access |} @@ -3051,7 +3135,7 @@ This search finds for the number successfully destroyed cloud instances for ever * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2020-08-21
@@ -3108,6 +3192,10 @@ You must be ingesting your cloud infrastructure logs. You also must run the base | T1078.004 | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access |} @@ -3136,7 +3224,7 @@ This search finds for the number successfully created cloud instances for every * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2020-08-21
@@ -3195,6 +3283,10 @@ You must be ingesting your cloud infrastructure logs. You also must run the base | T1078.004 | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access |} @@ -3223,7 +3315,7 @@ This search will detect a spike in the number of API calls made to your cloud in * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2020-09-07
@@ -3279,6 +3371,10 @@ You must be ingesting your cloud infrastructure logs. You also must run the base | T1078.004 | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access |} @@ -3712,7 +3808,7 @@ This search looks for cloud compute instances created by users who have not crea * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2021-07-13
@@ -3762,6 +3858,10 @@ You must be ingesting the appropriate cloud-infrastructure logs Run the "Pre | T1078.004 | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access |} @@ -4008,7 +4108,7 @@ This search looks for cloud instances being modified by users who have not previ * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/004/ T1078.004], [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2020-07-29
@@ -4062,6 +4162,10 @@ This search has a dependency on other searches to create and update a baseline o | T1078.004 | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access |} @@ -4428,7 +4532,7 @@ This search correlations detections by repository and risk_score * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] * '''Last Updated''': 2021-09-06
@@ -4465,6 +4569,10 @@ For Dev Sec Ops POC | T1204.003 | Malicious Image | Execution +|- +| T1204 +| User Execution +| Execution |} @@ -4493,7 +4601,7 @@ This search correlations detections by user and risk_score * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/003/ T1204.003], [https://attack.mitre.org/techniques/T1204/ T1204] * '''Last Updated''': 2021-09-06
@@ -4530,6 +4638,10 @@ For Dev Sec Ops POC | T1204.003 | Malicious Image | Execution +|- +| T1204 +| User Execution +| Execution |} @@ -5859,7 +5971,7 @@ This search is to detect a suspicious attachment file extension in Gsuite email * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001], [https://attack.mitre.org/techniques/T1566/ T1566] * '''Last Updated''': 2021-08-16
@@ -5876,7 +5988,7 @@ This search is to detect a suspicious attachment file extension in Gsuite email ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#DevSecOps|DevSecOps]] +* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] ====How To Implement==== @@ -5913,6 +6025,10 @@ To successfully implement this search, you need to be ingesting logs related to | T1566.001 | Spearphishing Attachment | Initial Access +|- +| T1566 +| Phishing +| Initial Access |} @@ -5947,7 +6063,7 @@ This search looks for Dependabot Alerts in Github logs. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1195/001/ T1195.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1195/001/ T1195.001], [https://attack.mitre.org/techniques/T1195/ T1195] * '''Last Updated''': 2021-09-01
@@ -6007,6 +6123,10 @@ You must index GitHub logs. You can follow the url in reference to onboard GitHu | T1195.001 | Compromise Software Dependencies and Development Tools | Initial Access +|- +| T1195 +| Supply Chain Compromise +| Initial Access |} @@ -6041,7 +6161,7 @@ This search looks for Pull Request from unknown user. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1195/001/ T1195.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1195/001/ T1195.001], [https://attack.mitre.org/techniques/T1195/ T1195] * '''Last Updated''': 2021-09-01
@@ -6102,6 +6222,10 @@ You must index GitHub logs. You can follow the url in reference to onboard GitHu | T1195.001 | Compromise Software Dependencies and Development Tools | Initial Access +|- +| T1195 +| Supply Chain Compromise +| Initial Access |} @@ -6154,7 +6278,7 @@ This search is to detect a pushed or commit to master or main branch. This is to ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#DevSecOps|DevSecOps]] +* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] ====How To Implement==== @@ -6225,7 +6349,7 @@ This search is to detect a pushed or commit to develop branch. This is to avoid ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#DevSecOps|DevSecOps]] +* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] ====How To Implement==== @@ -6280,7 +6404,7 @@ This search is to detect suspicious google drive or google docs files shared out * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1567/002/ T1567.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1567/002/ T1567.002], [https://attack.mitre.org/techniques/T1567/ T1567] * '''Last Updated''': 2021-08-16
@@ -6301,11 +6425,11 @@ This search is to detect suspicious google drive or google docs files shared out ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#DevSecOps|DevSecOps]] +* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] ====How To Implement==== -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. +To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. In order for the search to work for your environment, please edit the query to use your company specific email domain instead of `internal_test_email.com`. ====Required field==== @@ -6336,6 +6460,10 @@ To successfully implement this search, you need to be ingesting logs related to | T1567.002 | Exfiltration to Cloud Storage | Exfiltration +|- +| T1567 +| Exfiltration Over Web Service +| Exfiltration |} @@ -6370,7 +6498,7 @@ This search is to detect a gsuite email contains suspicious subject having known * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001], [https://attack.mitre.org/techniques/T1566/ T1566] * '''Last Updated''': 2021-08-19
@@ -6390,7 +6518,7 @@ This search is to detect a gsuite email contains suspicious subject having known ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#DevSecOps|DevSecOps]] +* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] ====How To Implement==== @@ -6411,6 +6539,10 @@ To successfully implement this search, you need to be ingesting logs related to | T1566.001 | Spearphishing Attachment | Initial Access +|- +| T1566 +| Phishing +| Initial Access |} @@ -6447,7 +6579,7 @@ This analytics is to detect a gmail containing a link that are known to be abuse * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001], [https://attack.mitre.org/techniques/T1566/ T1566] * '''Last Updated''': 2021-08-23
@@ -6467,7 +6599,7 @@ This analytics is to detect a gmail containing a link that are known to be abuse ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#DevSecOps|DevSecOps]] +* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] ====How To Implement==== @@ -6488,6 +6620,10 @@ To successfully implement this search, you need to be ingesting logs related to | T1566.001 | Spearphishing Attachment | Initial Access +|- +| T1566 +| Phishing +| Initial Access |} @@ -6522,7 +6658,7 @@ This search is to detect a suspicious outbound e-mail from internal email to ext * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048] * '''Last Updated''': 2021-08-17
@@ -6544,7 +6680,7 @@ This search is to detect a suspicious outbound e-mail from internal email to ext ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#DevSecOps|DevSecOps]] +* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] ====How To Implement==== @@ -6565,6 +6701,10 @@ To successfully implement this search, you need to be ingesting logs related to | T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration +|- +| T1048 +| Exfiltration Over Alternative Protocol +| Exfiltration |} @@ -6599,7 +6739,7 @@ This search is to detect a shared file in google drive with suspicious file name * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001], [https://attack.mitre.org/techniques/T1566/ T1566] * '''Last Updated''': 2021-08-23
@@ -6620,11 +6760,11 @@ This search is to detect a shared file in google drive with suspicious file name ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#DevSecOps|DevSecOps]] +* [[Documentation:ESSOC:stories:UseCase#Dev_Sec_Ops|Dev Sec Ops]] ====How To Implement==== -To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. +To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file extension, source email, destination email, num of attachment and etc. In order for the search to work for your environment, please edit the query to use your company specific email domain instead of `internal_test_email.com`. ====Required field==== @@ -6655,6 +6795,10 @@ To successfully implement this search, you need to be ingesting logs related to | T1566.001 | Spearphishing Attachment | Initial Access +|- +| T1566 +| Phishing +| Initial Access |} @@ -6691,7 +6835,7 @@ This search will detect more than 5 login failures in Office365 Azure Active Dir * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/001/ T1110.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/001/ T1110.001], [https://attack.mitre.org/techniques/T1110/ T1110] * '''Last Updated''': 2020-12-16
@@ -6746,6 +6890,10 @@ This search will detect more than 5 login failures in Office365 Azure Active Dir | T1110.001 | Password Guessing | Credential Access +|- +| T1110 +| Brute Force +| Credential Access |} @@ -7144,7 +7292,7 @@ This search detects the creation of a new Federation setting by alerting about a * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] * '''Last Updated''': 2021-01-26
@@ -7196,6 +7344,10 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 | T1136.003 | Cloud Account | Persistence +|- +| T1136 +| Create Account +| Persistence |} @@ -7232,7 +7384,7 @@ This search detects the creation of a new Federation setting by alerting about a * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] * '''Last Updated''': 2021-01-26
@@ -7284,6 +7436,10 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 | T1136.003 | Cloud Account | Persistence +|- +| T1136 +| Create Account +| Persistence |} @@ -7324,7 +7480,7 @@ This search detects newly added IP addresses/CIDR blocks to the list of MFA Trus * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-07-19
@@ -7383,6 +7539,10 @@ You must install Splunk Microsoft Office 365 add-on. This search works with o365 | T1562.007 | Disable or Modify Cloud Firewall | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -7669,7 +7829,7 @@ This search detects the addition of a new Federated domain. * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/003/ T1136.003], [https://attack.mitre.org/techniques/T1136/ T1136] * '''Last Updated''': 2021-01-26
@@ -7723,6 +7883,10 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 | T1136.003 | Cloud Account | Persistence +|- +| T1136 +| Create Account +| Persistence |} @@ -7849,7 +8013,7 @@ This search detects when an admin configured a forwarding rule for multiple mail * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/003/ T1114.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/003/ T1114.003], [https://attack.mitre.org/techniques/T1114/ T1114] * '''Last Updated''': 2020-12-16
@@ -7895,6 +8059,10 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 | T1114.003 | Email Forwarding Rule | Collection +|- +| T1114 +| Email Collection +| Collection |} @@ -7925,7 +8093,7 @@ This search detects the assignment of rights to accesss content from another mai * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/002/ T1114.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/002/ T1114.002], [https://attack.mitre.org/techniques/T1114/ T1114] * '''Last Updated''': 2020-12-15
@@ -7968,6 +8136,10 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 | T1114.002 | Remote Email Collection | Collection +|- +| T1114 +| Email Collection +| Collection |} @@ -7998,7 +8170,7 @@ This search detects when multiple user configured a forwarding rule to the same * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/003/ T1114.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/003/ T1114.003], [https://attack.mitre.org/techniques/T1114/ T1114] * '''Last Updated''': 2020-12-16
@@ -8044,6 +8216,10 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 | T1114.003 | Email Forwarding Rule | Collection +|- +| T1114 +| Email Collection +| Collection |} @@ -8492,7 +8668,7 @@ This search is to detect a suspicious 7z process with commandline pointing to SM * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001], [https://attack.mitre.org/techniques/T1560/ T1560] * '''Last Updated''': 2021-08-17
@@ -8545,6 +8721,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1560.001 | Archive via Utility | Collection +|- +| T1560 +| Archive Collected Data +| Collection |} @@ -8579,7 +8759,7 @@ Detect memory dumping of the LSASS process. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2019-12-06
@@ -8630,6 +8810,10 @@ This search requires Sysmon Logs and a Sysmon configuration, which includes Even | T1003.001 | LSASS Memory | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -8664,7 +8848,7 @@ this search is to detect a potential account discovery series of command used by * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-09-16
@@ -8726,6 +8910,10 @@ To successfully implement this search you need to be ingesting information on pr | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -8759,12 +8947,101 @@ admin or power user may used this series of command. ---- +===Active setup registry autostart=== +This analytic is to detect a suspicious modification of the active setup registry for persistence and privilege escalation. This technique was seen in several malware (poisonIvy), adware and APT to gain persistence to the compromised machine upon boot up. This TTP is a good indicator to further check the process id that do the modification since modification of this registry is not commonly done. check the legitimacy of the file and process involve in this rules to check if it is a valid setup installer that creating or modifying this registry. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/014/ T1547.014], [https://attack.mitre.org/techniques/T1547/ T1547] +* '''Last Updated''': 2021-09-28 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_value_name = "StubPath" Registry.registry_key_name = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `active_setup_registry_autostart_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + +* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] + + +====How To Implement==== +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +====Required field==== + +* _time + +* Registry.dest + +* Registry.user + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.registry_value_name + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1547.014 +| Active Setup +| Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Active setup installer may add or modify this registry. + +====Reference==== + + +* https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor%3aWin32%2fPoisonivy.E + +* https://attack.mitre.org/techniques/T1547/014/ + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1547.014/active_setup_stubpath/sysmon.log + + +''version'': 1 +
+
+ +---- + ===Add defaultuser and password in registry=== this search is to detect a suspicious registry modification to implement auto admin logon to a host. This technique was seen in BlackMatter ransomware to automatically logon to the compromise host after triggering a safemode boot to continue encrypting the whole network. This behavior is not a common practice and really a suspicious TTP or alert need to be consider if found within then network premise. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1552/002/ T1552.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1552/002/ T1552.002], [https://attack.mitre.org/techniques/T1552/ T1552] * '''Last Updated''': 2021-09-06
@@ -8809,6 +9086,10 @@ To successfully implement this search you need to be ingesting information on pr | T1552.002 | Credentials in Registry | Credential Access +|- +| T1552 +| Unsecured Credentials +| Credential Access |} @@ -8843,7 +9124,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-08-24
@@ -8887,6 +9168,10 @@ The following Hunting analytic requires PowerShell operational logs to be import | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -8925,7 +9210,7 @@ This search is to detect a suspicious modification of firewall to allow file and * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-06-23
@@ -8984,6 +9269,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.007 | Disable or Modify Cloud Firewall | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -9020,7 +9309,7 @@ This analytic detects a potential suspicious modification of firewall rule regis * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001], [https://attack.mitre.org/techniques/T1021/ T1021] * '''Last Updated''': 2021-05-26
@@ -9074,6 +9363,10 @@ To successfully implement this search you need to be ingesting information on pr | T1021.001 | Remote Desktop Protocol | Lateral Movement +|- +| T1021 +| Remote Services +| Lateral Movement |} @@ -9108,7 +9401,7 @@ The following analytic identifies suspicious PowerShell command to allow inbound * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001], [https://attack.mitre.org/techniques/T1021/ T1021] * '''Last Updated''': 2021-05-19
@@ -9152,6 +9445,10 @@ To successfully implement this search, you need to be ingesting logs with the po | T1021.001 | Remote Desktop Protocol | Lateral Movement +|- +| T1021 +| Remote Services +| Lateral Movement |} @@ -9186,7 +9483,7 @@ This search is to detect a suspicious modification to the firewall to allow netw * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/007/ T1562.007], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-06-23
@@ -9247,6 +9544,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.007 | Disable or Modify Cloud Firewall | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -9364,7 +9665,7 @@ The following detection identifies a 7z.exe spawned from `Rundll32.exe` or `Dllh * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001], [https://attack.mitre.org/techniques/T1560/ T1560] * '''Last Updated''': 2021-04-22
@@ -9421,6 +9722,10 @@ To successfully implement this search you need to be ingesting information on pr | T1560.001 | Archive via Utility | Collection +|- +| T1560 +| Archive Collected Data +| Collection |} @@ -9459,7 +9764,7 @@ The following analytic identifies the use of PowerShell downloading a file using * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-03-01
@@ -9517,6 +9822,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -9558,7 +9867,7 @@ The following analytic identifies the use of PowerShell downloading a file using * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-03-01
@@ -9618,6 +9927,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -9995,7 +10308,7 @@ This search looks for execution of commonly used attacker tools on an endpoint. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/005/ T1036.005], [https://attack.mitre.org/techniques/T1595/ T1595], [https://attack.mitre.org/techniques/T1003/ T1003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/005/ T1036.005], [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1003/ T1003], [https://attack.mitre.org/techniques/T1595/ T1595] * '''Last Updated''': 2021-06-21
@@ -10047,13 +10360,17 @@ To successfully implement this search, you must be ingesting data that records p | Match Legitimate Name or Location | Defense Evasion |- -| T1595 -| Active Scanning -| Reconnaissance +| T1036 +| Masquerading +| Defense Evasion |- | T1003 | OS Credential Dumping | Credential Access +|- +| T1595 +| Active Scanning +| Reconnaissance |} @@ -10088,7 +10405,7 @@ Attempt To Add Certificate To Untrusted Store * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1553/004/ T1553.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1553/004/ T1553.004], [https://attack.mitre.org/techniques/T1553/ T1553] * '''Last Updated''': 2021-09-16
@@ -10141,6 +10458,10 @@ You must be ingesting data that records process activity from your hosts to popu | T1553.004 | Install Root Certificate | Defense Evasion +|- +| T1553 +| Subvert Trust Controls +| Defense Evasion |} @@ -10265,7 +10586,7 @@ This search looks for attempts to stop security-related services on the endpoint * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2020-07-21
@@ -10328,6 +10649,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -10528,7 +10853,7 @@ Monitor for execution of reg.exe with parameters specifying an export of keys th * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-09-16
@@ -10589,6 +10914,10 @@ To successfully implement this search you need to be ingesting information on pr | T1003.002 | Security Account Manager | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -10623,7 +10952,7 @@ this search is to detect a suspicious registry modification to implement auto ad * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1552/002/ T1552.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1552/002/ T1552.002], [https://attack.mitre.org/techniques/T1552/ T1552] * '''Last Updated''': 2021-09-06
@@ -10668,6 +10997,10 @@ To successfully implement this search you need to be ingesting information on pr | T1552.002 | Credentials in Registry | Credential Access +|- +| T1552 +| Unsecured Credentials +| Credential Access |} @@ -10991,7 +11324,7 @@ The search looks for a batch file (.bat) written to the Windows system directory * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/002/ T1204.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/ T1204], [https://attack.mitre.org/techniques/T1204/002/ T1204.002] * '''Last Updated''': 2021-09-16
@@ -11043,6 +11376,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1204 +| User Execution +| Execution +|- | T1204.002 | Malicious File | Execution @@ -11248,7 +11585,7 @@ This analytic identifies a common behavior by Cobalt Strike and other frameworks * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/003/ T1059.003], [https://attack.mitre.org/techniques/T1543/003/ T1543.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/003/ T1059.003], [https://attack.mitre.org/techniques/T1543/003/ T1543.003], [https://attack.mitre.org/techniques/T1543/ T1543] * '''Last Updated''': 2021-05-20
@@ -11304,6 +11641,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.003 | Windows Command Shell | Execution @@ -11311,6 +11652,10 @@ To successfully implement this search you need to be ingesting information on pr | T1543.003 | Windows Service | Persistence, Privilege Escalation +|- +| T1543 +| Create or Modify System Process +| Persistence, Privilege Escalation |} @@ -11349,7 +11694,7 @@ This analytic detects a potential process using COM Object like CMLUA or CMSTPLU * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/003/ T1218.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/003/ T1218.003] * '''Last Updated''': 2021-05-13
@@ -11398,6 +11743,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.003 | CMSTP | Defense Evasion @@ -11802,6 +12151,93 @@ Unless there are specific use cases, manipulating or exporting certificates usin * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/certutil_exe_certificate_extraction/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Change default file association=== +This analytic is developed to detect suspicious registry modification to change the default file association of windows to malicious payload. This techninique was seen in some APT where it modify the default process to run file association, like .txt to notepad.exe. Instead notepad.exe it will point to a Script or other payload that will load malicious command to the compromised host. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/001/ T1546.001], [https://attack.mitre.org/techniques/T1546/ T1546] +* '''Last Updated''': 2021-09-27 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\shell\\open\\command\\*" Registry.registry_path = "*HKCR\\*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `change_default_file_association_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + +* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] + + +====How To Implement==== +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +====Required field==== + +* _time + +* Registry.dest + +* Registry.user + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.registry_value_name + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1546.001 +| Change Default File Association +| Privilege Escalation, Persistence +|- +| T1546 +| Event Triggered Execution +| Privilege Escalation, Persistence +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +unknown + +====Reference==== + + +* https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log + + ''version'': 1
@@ -12056,7 +12492,7 @@ this search is to detect execution of `cipher.exe` to clear the unallocated sect * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/004/ T1070.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/004/ T1070.004], [https://attack.mitre.org/techniques/T1070/ T1070] * '''Last Updated''': 2021-06-10
@@ -12115,6 +12551,10 @@ To successfully implement this search you need to be ingesting information on pr | T1070.004 | File Deletion | Defense Evasion +|- +| T1070 +| Indicator Removal on Host +| Defense Evasion |} @@ -12330,7 +12770,7 @@ This search is to detect a suspicious parent process execution of commandline to * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/007/ T1059.007] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/007/ T1059.007] * '''Last Updated''': 2021-09-14
@@ -12378,6 +12818,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.007 | JavaScript | Execution @@ -12777,7 +13221,7 @@ The following detection identifies control.exe loading either a .cpl or .inf fro * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/002/ T1218.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/002/ T1218.002] * '''Last Updated''': 2021-09-08
@@ -12831,6 +13275,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.002 | Control Panel | Defense Evasion @@ -12960,7 +13408,7 @@ Detect remote thread creation into LSASS consistent with credential dumping. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2019-12-06
@@ -13011,6 +13459,10 @@ This search needs Sysmon Logs with a Sysmon configuration, which includes EventC | T1003.001 | LSASS Memory | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -13045,7 +13497,7 @@ This detection is to identify a creation of "user mode service" where th * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/002/ T1569.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1569/002/ T1569.002] * '''Last Updated''': 2021-03-12
@@ -13088,6 +13540,10 @@ To successfully implement this search, you need to be ingesting logs with the Se ! Technique ! Tactic |- +| T1569 +| System Services +| Execution +|- | T1569.002 | Service Execution | Execution @@ -13127,7 +13583,7 @@ This search looks for the creation of local administrator accounts using net.exe * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/001/ T1136.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/001/ T1136.001], [https://attack.mitre.org/techniques/T1136/ T1136] * '''Last Updated''': 2021-09-08
@@ -13186,6 +13642,10 @@ You must be ingesting data that records process activity from your hosts to popu | T1136.001 | Local Account | Persistence +|- +| T1136 +| Create Account +| Persistence |} @@ -13220,7 +13680,7 @@ This search looks for the creation or deletion of hidden shares using net.exe. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/005/ T1070.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/005/ T1070.005] * '''Last Updated''': 2020-09-16
@@ -13277,6 +13737,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1070 +| Indicator Removal on Host +| Defense Evasion +|- | T1070.005 | Network Share Connection Removal | Defense Evasion @@ -13314,7 +13778,7 @@ Monitor for signs that Vssadmin or Wmic has been used to create a shadow copy. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2019-12-10
@@ -13373,6 +13837,10 @@ You must be ingesting endpoint data that tracks process activity, including pare | T1003.003 | NTDS | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -13407,7 +13875,7 @@ This search detects the use of wmic and Powershell to create a shadow copy. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-09-16
@@ -13466,6 +13934,10 @@ To successfully implement this search you need to be ingesting information on pr | T1003.003 | NTDS | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -13500,7 +13972,7 @@ Detect the hands on keyboard behavior of Windows Task Manager creating a process * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-02-03
@@ -13547,6 +14019,10 @@ This search requires Sysmon Logs and a Sysmon configuration, which includes Even | T1003.001 | LSASS Memory | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -13585,7 +14061,7 @@ This search detects credential dumping using copy command from a shadow copy. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-09-16
@@ -13644,6 +14120,10 @@ To successfully implement this search you need to be ingesting information on pr | T1003.003 | NTDS | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -13678,7 +14158,7 @@ This search detects the creation of a symlink to a shadow copy. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-09-16
@@ -13737,6 +14217,10 @@ To successfully implement this search you need to be ingesting information on pr | T1003.003 | NTDS | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -14593,23 +15077,23 @@ The following analytic identifies DLLHost.exe with no command line arguments wit * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint * '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-04-19 +* '''Last Updated''': 2021-10-13
====Search==== -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=dllhost.exe by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=dllhost.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | regex process="(dllhost\.exe.{0,4}$)" -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_id Ports.dest Ports.dest_port +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port | `drop_dm_object_name(Ports)` | rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_id connection_to_CNC dest_port +| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port | `dllhost_with_no_command_line_arguments_with_network_filter` ====Associated Analytic Story==== @@ -14672,7 +15156,7 @@ Although unlikely, some legitimate third party applications may use a moved copy * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_dllhost.log -''version'': 1 +''version'': 2
@@ -15324,7 +15808,7 @@ This search looks for specific authentication events from the Windows Security E * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/002/ T1550.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/ T1550], [https://attack.mitre.org/techniques/T1550/002/ T1550.002] * '''Last Updated''': 2020-10-15
@@ -15370,6 +15854,10 @@ To successfully implement this search, you must ingest your Windows Security Eve ! Technique ! Tactic |- +| T1550 +| Use Alternate Authentication Material +| Defense Evasion, Lateral Movement +|- | T1550.002 | Pass the Hash | Defense Evasion, Lateral Movement @@ -15403,7 +15891,7 @@ The following analytic identifies the common command-line argument used by Azure * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/ T1069] * '''Last Updated''': 2021-06-01
@@ -15463,20 +15951,28 @@ To successfully implement this search you need to be ingesting information on pr | Domain Account | Discovery |- -| T1087.001 -| Local Account +| T1069.001 +| Local Groups | Discovery |- | T1482 | Domain Trust Discovery | Discovery |- +| T1087.001 +| Local Account +| Discovery +|- +| T1087 +| Account Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery |- -| T1069.001 -| Local Groups +| T1069 +| Permission Groups Discovery | Discovery |} @@ -15518,7 +16014,7 @@ The following analytic is similar to SharpHound file modifications, but this ins * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/ T1069] * '''Last Updated''': 2021-06-01
@@ -15566,20 +16062,28 @@ To successfully implement this search you need to be ingesting information on fi | Domain Account | Discovery |- -| T1087.001 -| Local Account +| T1069.001 +| Local Groups | Discovery |- | T1482 | Domain Trust Discovery | Discovery |- +| T1087.001 +| Local Account +| Discovery +|- +| T1087 +| Account Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery |- -| T1069.001 -| Local Groups +| T1069 +| Permission Groups Discovery | Discovery |} @@ -15899,7 +16403,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-07-21
@@ -15945,6 +16449,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri | T1003.002 | Security Account Manager | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -15983,7 +16491,7 @@ This search looks for reading lsass memory consistent with credential dumping. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2019-12-03
@@ -16038,6 +16546,10 @@ This search needs Sysmon Logs and a sysmon configuration, which includes EventCo | T1003.001 | LSASS Memory | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -16068,7 +16580,7 @@ This search detects the memory of lsass.exe being dumped for offline credential * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-09-15
@@ -16113,6 +16625,10 @@ You must be ingesting endpoint data that tracks process activity, including Wind | T1003.003 | NTDS | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -16149,7 +16665,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-06-09
@@ -16192,6 +16708,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -16237,7 +16757,7 @@ This search identifies endpoints that have caused a relatively high number of ac * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/002/ T1078.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/002/ T1078.002] * '''Last Updated''': 2020-11-09
@@ -16285,6 +16805,10 @@ If Splunk>Phantom is also configured in your environment, a Playbook called & ! Technique ! Tactic |- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- | T1078.002 | Domain Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access @@ -16318,7 +16842,7 @@ This search detects user accounts that have been locked out a relatively high nu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/003/ T1078.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1078/003/ T1078.003] * '''Last Updated''': 2020-07-21
@@ -16360,6 +16884,10 @@ ou must ingest your Windows security event logs in the `Change` datamodel under ! Technique ! Tactic |- +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- | T1078.003 | Local Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access @@ -16393,7 +16921,7 @@ The following query identifies suspicious .aspx created in 3 paths identified by * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1505/003/ T1505.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1505/ T1505], [https://attack.mitre.org/techniques/T1505/003/ T1505.003] * '''Last Updated''': 2021-10-05
@@ -16443,6 +16971,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1505 +| Server Software Component +| Persistence +|- | T1505.003 | Web Shell | Persistence @@ -16486,7 +17018,7 @@ The following analytic identifies a renamed instance of hh.exe (HTML Help) execu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/001/ T1218.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/001/ T1218.001] * '''Last Updated''': 2021-09-16
@@ -16542,6 +17074,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.001 | Compiled HTML File | Defense Evasion @@ -16583,7 +17119,7 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/001/ T1218.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/001/ T1218.001] * '''Last Updated''': 2021-02-11
@@ -16639,6 +17175,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.001 | Compiled HTML File | Defense Evasion @@ -16684,7 +17224,7 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/001/ T1218.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/001/ T1218.001] * '''Last Updated''': 2021-09-16
@@ -16740,6 +17280,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.001 | Compiled HTML File | Defense Evasion @@ -16787,7 +17331,7 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/001/ T1218.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/001/ T1218.001] * '''Last Updated''': 2021-09-16
@@ -16843,6 +17387,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.001 | Compiled HTML File | Defense Evasion @@ -16890,7 +17438,7 @@ This search detects a potential kerberoasting attack via service principal name * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1558/003/ T1558.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1558/003/ T1558.003], [https://attack.mitre.org/techniques/T1558/ T1558] * '''Last Updated''': 2020-10-21
@@ -16940,6 +17488,10 @@ The test data is converted from Windows Security Event logs generated from Attac | T1558.003 | Kerberoasting | Credential Access +|- +| T1558 +| Steal or Forge Kerberos Tickets +| Credential Access |} @@ -16972,7 +17524,7 @@ This analytic identifies when Microsoft HTML Application Host (mshta.exe) utilit * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/005/ T1218.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] * '''Last Updated''': 2021-09-16
@@ -17028,6 +17580,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.005 | Mshta | Defense Evasion @@ -17069,7 +17625,7 @@ This search looks for reading loaded Images unique to credential dumping with Mi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2019-12-03
@@ -17123,6 +17679,10 @@ This search needs Sysmon Logs and a sysmon configuration, which includes EventCo | T1003.001 | LSASS Memory | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -17245,7 +17805,7 @@ This search looks for newly created accounts that have been elevated to local ad * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/001/ T1136.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/001/ T1136.001], [https://attack.mitre.org/techniques/T1136/ T1136] * '''Last Updated''': 2020-07-08
@@ -17295,6 +17855,10 @@ You must be ingesting Windows event logs using the Splunk Windows TA and collect | T1136.001 | Local Account | Persistence +|- +| T1136 +| Create Account +| Persistence |} @@ -17331,7 +17895,7 @@ This search looks for execution of process `outlook.exe` where the process is wr * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2020-07-21
@@ -17388,6 +17952,10 @@ You must be ingesting data that records filesystem and process activity from you ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -17421,7 +17989,7 @@ This search looks for specific authentication events from the Windows Security E * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/002/ T1550.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/ T1550], [https://attack.mitre.org/techniques/T1550/002/ T1550.002] * '''Last Updated''': 2020-10-21
@@ -17471,6 +18039,10 @@ The test data is converted from Windows Security Event logs generated from Attac ! Technique ! Tactic |- +| T1550 +| Use Alternate Authentication Material +| Defense Evasion, Lateral Movement +|- | T1550.002 | Pass the Hash | Defense Evasion, Lateral Movement @@ -17506,7 +18078,7 @@ The detection Detect Path Interception By Creation Of program exe is detecting t * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1574/009/ T1574.009] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1574/009/ T1574.009], [https://attack.mitre.org/techniques/T1574/ T1574] * '''Last Updated''': 2020-07-03
@@ -17572,6 +18144,10 @@ You must be ingesting data that records process activity from your hosts to popu | T1574.009 | Path Interception by Unquoted Path | Persistence, Privilege Escalation, Defense Evasion +|- +| T1574 +| Hijack Execution Flow +| Persistence, Privilege Escalation, Defense Evasion |} @@ -17606,7 +18182,7 @@ This search looks for executions of cmd.exe spawned by a process that is often a * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/003/ T1059.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/003/ T1059.003] * '''Last Updated''': 2020-11-10
@@ -17669,6 +18245,10 @@ You must be ingesting data that records process activity from your hosts and pop ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.003 | Windows Command Shell | Execution @@ -17787,7 +18367,7 @@ This search looks for events where `PsExec.exe` is run with the `accepteula` fla * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/002/ T1021.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1021/002/ T1021.002] * '''Last Updated''': 2021-09-16
@@ -17851,6 +18431,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1021 +| Remote Services +| Lateral Movement +|- | T1021.002 | SMB/Windows Admin Shares | Lateral Movement @@ -18050,7 +18634,7 @@ The following analytic identifies regasm.exe spawning a process. This particular * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/009/ T1218.009] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] * '''Last Updated''': 2021-02-12
@@ -18098,6 +18682,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.009 | Regsvcs/Regasm | Defense Evasion @@ -18141,7 +18729,7 @@ The following analytic identifies regasm.exe with a network connection to a publ * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/009/ T1218.009] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] * '''Last Updated''': 2021-02-16
@@ -18191,6 +18779,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.009 | Regsvcs/Regasm | Defense Evasion @@ -18232,7 +18824,7 @@ The following analytic identifies regasm.exe with no command line arguments. Thi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/009/ T1218.009] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] * '''Last Updated''': 2021-09-20
@@ -18289,6 +18881,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.009 | Regsvcs/Regasm | Defense Evasion @@ -18330,7 +18926,7 @@ The following analytic identifies regsvcs.exe spawning a process. This particula * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/009/ T1218.009] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] * '''Last Updated''': 2021-02-12
@@ -18380,6 +18976,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.009 | Regsvcs/Regasm | Defense Evasion @@ -18421,7 +19021,7 @@ The following analytic identifies Regsvcs.exe with a network connection to a pub * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/009/ T1218.009] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] * '''Last Updated''': 2021-02-16
@@ -18469,6 +19069,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.009 | Regsvcs/Regasm | Defense Evasion @@ -18510,7 +19114,7 @@ The following analytic identifies regsvcs.exe with no command line arguments. Th * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/009/ T1218.009] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/009/ T1218.009] * '''Last Updated''': 2021-09-20
@@ -18567,6 +19171,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.009 | Regsvcs/Regasm | Defense Evasion @@ -18609,7 +19217,7 @@ Upon investigating, look for network connections to remote destinations (interna * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/010/ T1218.010] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/010/ T1218.010] * '''Last Updated''': 2021-01-28
@@ -18667,6 +19275,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.010 | Regsvr32 | Defense Evasion @@ -18710,7 +19322,7 @@ The following analytic identifies renamed 7-Zip usage using Sysmon. At this stag * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001], [https://attack.mitre.org/techniques/T1560/ T1560] * '''Last Updated''': 2021-09-16
@@ -18769,6 +19381,10 @@ To successfully implement this search you need to be ingesting information on pr | T1560.001 | Archive via Utility | Collection +|- +| T1560 +| Archive Collected Data +| Collection |} @@ -18803,7 +19419,7 @@ The following analytic identifies renamed instances of `PsExec.exe` being utiliz * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/002/ T1569.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1569/002/ T1569.002] * '''Last Updated''': 2021-09-16
@@ -18867,6 +19483,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1569 +| System Services +| Execution +|- | T1569.002 | Service Execution | Execution @@ -19009,7 +19629,7 @@ The following analtyic identifies renamed instances of `WinRAR.exe`. In most cas * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001], [https://attack.mitre.org/techniques/T1560/ T1560] * '''Last Updated''': 2021-09-16
@@ -19068,6 +19688,10 @@ To successfully implement this search you need to be ingesting information on pr | T1560.001 | Archive via Utility | Collection +|- +| T1560 +| Archive Collected Data +| Collection |} @@ -19104,7 +19728,7 @@ The following analytic identifies rundll32.exe loading advpack.dll and ieadvpack * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-02-04
@@ -19160,6 +19784,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -19205,7 +19833,7 @@ The following analytic identifies rundll32.exe loading setupapi.dll and iesetupa * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-02-04
@@ -19261,6 +19889,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -19306,7 +19938,7 @@ The following analytic identifies rundll32.exe loading syssetup.dll by calling t * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-02-04
@@ -19362,6 +19994,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -19407,7 +20043,7 @@ The following analytic identifies "rundll32.exe" execution with inline p * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/005/ T1218.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] * '''Last Updated''': 2021-01-20
@@ -19465,6 +20101,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.005 | Mshta | Defense Evasion @@ -19506,7 +20146,7 @@ The following analytic identifies common command-line arguments used by SharpHou * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/ T1069] * '''Last Updated''': 2021-06-01
@@ -19560,20 +20200,28 @@ To successfully implement this search you need to be ingesting information on pr | Domain Account | Discovery |- -| T1087.001 -| Local Account +| T1069.001 +| Local Groups | Discovery |- | T1482 | Domain Trust Discovery | Discovery |- +| T1087.001 +| Local Account +| Discovery +|- +| T1087 +| Account Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery |- -| T1069.001 -| Local Groups +| T1069 +| Permission Groups Discovery | Discovery |} @@ -19617,7 +20265,7 @@ SharpHound is used as a reconnaissance collector, ingestor, for BloodHound. Shar * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/ T1069] * '''Last Updated''': 2021-05-27
@@ -19667,20 +20315,28 @@ To successfully implement this search you need to be ingesting information on fi | Domain Account | Discovery |- -| T1087.001 -| Local Account +| T1069.001 +| Local Groups | Discovery |- | T1482 | Domain Trust Discovery | Discovery |- +| T1087.001 +| Local Account +| Discovery +|- +| T1087 +| Account Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery |- -| T1069.001 -| Local Groups +| T1069 +| Permission Groups Discovery | Discovery |} @@ -19724,7 +20380,7 @@ The following analytic identifies SharpHound binary usage by using the original * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1069/001/ T1069.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1087/001/ T1087.001], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1069/002/ T1069.002], [https://attack.mitre.org/techniques/T1069/ T1069] * '''Last Updated''': 2021-05-27
@@ -19786,20 +20442,28 @@ To successfully implement this search you need to be ingesting information on pr | Domain Account | Discovery |- -| T1087.001 -| Local Account +| T1069.001 +| Local Groups | Discovery |- | T1482 | Domain Trust Discovery | Discovery |- +| T1087.001 +| Local Account +| Discovery +|- +| T1087 +| Account Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery |- -| T1069.001 -| Local Groups +| T1069 +| Permission Groups Discovery | Discovery |} @@ -19843,7 +20507,7 @@ This search looks for the execution of the cscript.exe or wscript.exe processes, * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/003/ T1059.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/003/ T1059.003] * '''Last Updated''': 2020-07-21
@@ -19891,6 +20555,10 @@ To successfully implement this search, you must be ingesting data that records p ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.003 | Windows Command Shell | Execution @@ -19929,7 +20597,7 @@ Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToCons * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/003/ T1546.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/003/ T1546.003], [https://attack.mitre.org/techniques/T1546/ T1546] * '''Last Updated''': 2021-06-16
@@ -19971,6 +20639,10 @@ To successfully implement this search, you need to be ingesting logs with that p | T1546.003 | Windows Management Instrumentation Event Subscription | Privilege Escalation, Persistence +|- +| T1546 +| Event Triggered Execution +| Privilege Escalation, Persistence |} @@ -20011,7 +20683,7 @@ The following analytic identifies "mshta.exe" execution with inline prot * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/005/ T1218.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] * '''Last Updated''': 2021-09-16
@@ -20067,6 +20739,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.005 | Mshta | Defense Evasion @@ -20108,7 +20784,7 @@ The following analytic identifies renamed instances of mshta.exe executing. Msht * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/005/ T1218.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] * '''Last Updated''': 2021-09-16
@@ -20164,6 +20840,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.005 | Mshta | Defense Evasion @@ -20375,7 +21055,7 @@ this search is to identify modification in registry to disable AMSI windows feat * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-06-22
@@ -20422,6 +21102,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -20458,7 +21142,7 @@ this search is to identify modification in registry to disable ETW windows featu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-06-22
@@ -20505,6 +21189,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -20539,7 +21227,7 @@ This search is to detect execution of wevtutil.exe to disable logs. This techniq * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/001/ T1070.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/001/ T1070.001] * '''Last Updated''': 2021-06-10
@@ -20589,6 +21277,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1070 +| Indicator Removal on Host +| Defense Evasion +|- | T1070.001 | Clear Windows Event Logs | Defense Evasion @@ -20711,7 +21403,7 @@ This search identifies modification of registry to disable the regedit or regist * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-31
@@ -20758,6 +21450,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -20785,6 +21481,88 @@ admin may disable this application for non technical user. * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Disable security logs using minint registry=== +This analytic is to detect a suspicious registry modification to disable security audit logs. This technique was shared by a researcher to disable Security logs of windows by adding this registry. The Windows will think it is WinPE and will not log any event to the Security Log + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112] +* '''Last Updated''': 2021-10-05 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Control\\MiniNt\\*" by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name Registry.registry_path Registry.registry_value_data +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `disable_security_logs_using_minint_registry_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] + + +====How To Implement==== +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +====Required field==== + +* _time + +* Registry.dest + +* Registry.user + +* Registry.registry_value_name + +* Registry.registry_key_name + +* Registry.registry_path + +* Registry.registry_value_data + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1112 +| Modify Registry +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Unknown. + +====Reference==== + + +* https://twitter.com/0gtweet/status/1182516740955226112 + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/minint_reg/sysmon.log + + ''version'': 1
@@ -20796,7 +21574,7 @@ The following analytic is to identify a modification in the Windows registry to * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1564/001/ T1564.001], [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1564/001/ T1564.001], [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1564/ T1564], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-31
@@ -20847,6 +21625,14 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1564 +| Hide Artifacts +| Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -20874,6 +21660,95 @@ unknown * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Disable uac remote restriction=== +This analytic is to detect a suspicious modification of registry to disable UAC remote restriction. This technique was well documented in Microsoft page where attacker may modify this registry value to bypassed UAC feature of windows host. This is a good indicator that some tries to bypassed UAC to suspicious process or gain privilege escalation. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] +* '''Last Updated''': 2021-09-29 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy" Registry.registry_value_data="0x00000001" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `disable_uac_remote_restriction_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] + +* [[Documentation:ESSOC:stories:UseCase#Suspicious_Windows_Registry_Activities|Suspicious Windows Registry Activities]] + + +====How To Implement==== +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +====Required field==== + +* _time + +* Registry.dest + +* Registry.user + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.registry_value_name + +* Registry.registry_value_data + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1548.002 +| Bypass User Account Control +| Privilege Escalation, Defense Evasion +|- +| T1548 +| Abuse Elevation Control Mechanism +| Privilege Escalation, Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +admin may set this policy for non-critical machine. + +====Reference==== + + +* https://docs.microsoft.com/en-us/troubleshoot/windows-server/windows-security/user-account-control-and-remote-restriction + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/LocalAccountTokenFilterPolicy/sysmon.log + + ''version'': 1
@@ -20885,7 +21760,7 @@ This analytic detects a suspicious registry modification to disable Windows hotk * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-05-05
@@ -20930,6 +21805,10 @@ To successfully implement this search, you must be ingesting data that records r | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -20964,7 +21843,7 @@ This search is to identifies a modification in registry to disable the windows d * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-31
@@ -21015,6 +21894,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -21053,7 +21936,7 @@ The following search identifies a modification of registry to disable the smarts * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-31
@@ -21100,6 +21983,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -21138,7 +22025,7 @@ this search is to identify modification in registry to disable cmd prompt applic * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-31
@@ -21185,6 +22072,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -21223,7 +22114,7 @@ this search is to identify registry modification to disable control panel window * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-31
@@ -21270,6 +22161,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -21308,7 +22203,7 @@ This search is to identifies suspicious firewall disabling using netsh applicati * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-31
@@ -21367,6 +22262,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -21405,7 +22304,7 @@ This search is to identify registry modification to disable folder options featu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-31
@@ -21452,6 +22351,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -21583,7 +22486,7 @@ This search is to identify modification of registry to disable run application i * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-31
@@ -21630,6 +22533,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -21670,7 +22577,7 @@ The search looks for modifications to registry keys that control the enforcement * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2020-11-18
@@ -21721,6 +22628,10 @@ To successfully implement this search, you must be ingesting data that records r | T1548.002 | Bypass User Account Control | Privilege Escalation, Defense Evasion +|- +| T1548 +| Abuse Elevation Control Mechanism +| Privilege Escalation, Defense Evasion |} @@ -21751,7 +22662,7 @@ The following search identifies the modification of registry related in disablin * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-31
@@ -21798,6 +22709,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -21836,7 +22751,7 @@ This search is to identifies modification of registry to disable the task manage * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-31
@@ -21883,6 +22798,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -21923,7 +22842,7 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command-li * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-08-24
@@ -21976,6 +22895,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -22012,7 +22935,7 @@ This analytic looks for the execution of `dsquery.exe` with command-line argumen * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-08-24
@@ -22065,6 +22988,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -22101,7 +23028,7 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-08-24
@@ -22154,6 +23081,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -22370,7 +23301,7 @@ This analytic looks for the execution of `dsquery.exe` with command-line argumen * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-09-01
@@ -22424,6 +23355,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -22461,7 +23396,7 @@ This analytic looks for the execution of `net.exe` with command-line arguments u * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-25
@@ -22515,6 +23450,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -22552,7 +23491,7 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-25
@@ -22606,6 +23545,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -22643,7 +23586,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-25
@@ -22683,6 +23626,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -22804,7 +23751,7 @@ This search is to detect dropping a suspicious file named as "license.dat * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/002/ T1204.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/ T1204], [https://attack.mitre.org/techniques/T1204/002/ T1204.002] * '''Last Updated''': 2021-07-30
@@ -22837,6 +23784,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1204 +| User Execution +| Execution +|- | T1204.002 | Malicious File | Execution @@ -22874,7 +23825,7 @@ Detect the usage of comsvcs.dll for dumping the lsass process. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-02-21
@@ -22937,6 +23888,10 @@ To successfully implement this search you need to be ingesting information on pr | T1003.001 | LSASS Memory | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -22974,7 +23929,7 @@ During triage, confirm this is procdump.exe executing. If it is the first time a * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/001/ T1003.001], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-09-16
@@ -23027,6 +23982,10 @@ To successfully implement this search you need to be ingesting information on pr | T1003.001 | LSASS Memory | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -23060,12 +24019,104 @@ None identified. ---- +===Etw registry disabled=== +This analytic is to detect a registry modification to disable ETW feature of windows. This technique is to evade EDR appliance to evade detections and hide its execution from audit logs. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/006/ T1562.006], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1562/ T1562] +* '''Last Updated''': 2021-10-07 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*") Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000 by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `etw_registry_disabled_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + +* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] + + +====How To Implement==== +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +====Required field==== + +* _time + +* Registry.dest + +* Registry.user + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.registry_value_name + +* Registry.registry_value_data + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1562.006 +| Indicator Blocking +| Defense Evasion +|- +| T1127 +| Trusted Developer Utilities Proxy Execution +| Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +unknown + +====Reference==== + + +* https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3 + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/etw_disable/sysmon.log + + +''version'': 1 +
+
+ +---- + ===Elevated group discovery with net=== This analytic looks for the execution of `net.exe` or `net1.exe` with command-line arguments utilized to query for specific elevated domain groups. Red Teams and adversaries alike use net.exe to enumerate elevated domain groups for situational awareness and Active Directory Discovery to identify high privileged users. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-25
@@ -23119,6 +24170,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -23160,7 +24215,7 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-25
@@ -23214,6 +24269,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -23255,7 +24314,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-25
@@ -23295,6 +24354,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -23406,6 +24469,92 @@ unknown * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Enable wdigest uselogoncredential registry=== +This analytic is to detect a suspicious registry modification to enable plain text credential feature of windows. This technique was used by several malware and also by mimikatz to be able to dumpe the a plain text credential to the compromised or target host. This TTP is really a good indicator that someone wants to dump the crendential of the host so it must be a good pivot for credential dumping techniques. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112], [https://attack.mitre.org/techniques/T1003/ T1003] +* '''Last Updated''': 2021-10-05 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name Registry.registry_path Registry.registry_value_data +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `enable_wdigest_uselogoncredential_registry_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + + +====How To Implement==== +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +====Required field==== + +* _time + +* Registry.dest + +* Registry.user + +* Registry.registry_value_name + +* Registry.registry_key_name + +* Registry.registry_path + +* Registry.registry_value_data + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1112 +| Modify Registry +| Defense Evasion +|- +| T1003 +| OS Credential Dumping +| Credential Access +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +unknown + +====Reference==== + + +* https://www.csoonline.com/article/3438824/how-to-detect-and-halt-credential-theft-via-windows-wdigest.html + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/wdigest_enable/sysmon.log + + ''version'': 1
@@ -23507,7 +24656,7 @@ The following analytic identifies the process - `esentutl.exe` - being used to c * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-08-18
@@ -23566,6 +24715,10 @@ To successfully implement this search you need to be ingesting information on pr | T1003.002 | Security Account Manager | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -23602,7 +24755,7 @@ The following search identifies Eventvwr bypass by identifying the registry modi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2021-03-01
@@ -23651,6 +24804,10 @@ To successfully implement this search you need to be ingesting information on pr | T1548.002 | Bypass User Account Control | Privilege Escalation, Defense Evasion +|- +| T1548 +| Abuse Elevation Control Mechanism +| Privilege Escalation, Defense Evasion |} @@ -23693,7 +24850,7 @@ The following detection identifies Microsoft Excel spawning PowerShell. Typicall * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-04-12
@@ -23750,6 +24907,10 @@ To successfully implement this search you need to be ingesting information on pr | T1003.002 | Security Account Manager | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -23786,7 +24947,7 @@ The following detection identifies Microsoft Excel spawning Windows Script Host * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-04-12
@@ -23835,6 +24996,10 @@ To successfully implement this search you need to be ingesting information on pr | T1003.002 | Security Account Manager | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -24231,7 +25396,7 @@ This search is to detect a suspicious excessive usage of sc.exe in a host machin * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/002/ T1569.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1569/002/ T1569.002] * '''Last Updated''': 2021-06-24
@@ -24275,6 +25440,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1569 +| System Services +| Execution +|- | T1569.002 | Service Execution | Execution @@ -24312,7 +25481,7 @@ This analytic identifies excessive usage of `taskkill.exe` application. This app * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-05-04
@@ -24362,6 +25531,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -24565,7 +25738,7 @@ This detection targets behaviors observed when threat actors have used sc.exe to * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-06-25
@@ -24617,6 +25790,10 @@ You must be ingesting data that records process activity from your hosts to popu | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -24827,7 +26004,7 @@ Module - New-managementroleassignment can assign a management role to a manageme * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-08-27
@@ -24872,6 +26049,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -24998,7 +26179,7 @@ This analytic will identify suspicious process of cscript.exe where it tries to * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/005/ T1059.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/005/ T1059.005] * '''Last Updated''': 2021-06-22
@@ -25046,6 +26227,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.005 | Visual Basic | Execution @@ -25083,7 +26268,7 @@ This search looks for processes launched from files that have double extensions * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/003/ T1036.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] * '''Last Updated''': 2020-11-18
@@ -25127,6 +26312,10 @@ To successfully implement this search, you must be ingesting data that records p ! Technique ! Tactic |- +| T1036 +| Masquerading +| Defense Evasion +|- | T1036.003 | Rename System Utilities | Defense Evasion @@ -25160,7 +26349,7 @@ The following analytic identifies the use of `reg.exe` exporting Windows Registr * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-09-09
@@ -25221,6 +26410,10 @@ To successfully implement this search you need to be ingesting information on pr | T1003.002 | Security Account Manager | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -25406,7 +26599,7 @@ This search looks for the first and last time a Windows service is seen running * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/002/ T1569.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1569/002/ T1569.002] * '''Last Updated''': 2020-07-21
@@ -25451,6 +26644,10 @@ While this search does not require you to adhere to Splunk CIM, you must be inge ! Technique ! Tactic |- +| T1569 +| System Services +| Execution +|- | T1569.002 | Service Execution | Execution @@ -25577,7 +26774,7 @@ Upon triage, fodhelper.exe will have a child process and read access will occur * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112], [https://attack.mitre.org/techniques/T1548/002/ T1548.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112], [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2021-03-01
@@ -25636,6 +26833,10 @@ To successfully implement this search you need to be ingesting information on pr | T1548.002 | Bypass User Account Control | Privilege Escalation, Defense Evasion +|- +| T1548 +| Abuse Elevation Control Mechanism +| Privilege Escalation, Defense Evasion |} @@ -25769,16 +26970,16 @@ The following analytic identifies gpupdate.exe with no command line arguments an ====Search==== -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=gpupdate.exe by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=gpupdate.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | regex process="(gpupdate\.exe.{0,4}$)" -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_id Ports.dest Ports.dest_port +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port | `drop_dm_object_name(Ports)` | rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_id connection_to_CNC dest_port +| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port | `gpupdate_with_no_command_line_arguments_with_network_filter` ====Associated Analytic Story==== @@ -26025,7 +27226,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-08-24
@@ -26078,6 +27279,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -26116,7 +27321,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-08-24
@@ -26160,6 +27365,10 @@ The following Hunting analytic requires PowerShell operational logs to be import | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -26544,7 +27753,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-08-24
@@ -26597,6 +27806,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -26631,7 +27844,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-08-24
@@ -26675,6 +27888,10 @@ The following Hunting analytic requires PowerShell operational logs to be import | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -26709,7 +27926,7 @@ The following hunting analytic identifies the use of `Get-WMIObject Win32_Group` * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/001/ T1069.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] * '''Last Updated''': 2021-09-14
@@ -26765,6 +27982,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.001 | Local Groups | Discovery @@ -26806,7 +28027,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/001/ T1069.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] * '''Last Updated''': 2021-09-14
@@ -26847,6 +28068,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.001 | Local Groups | Discovery @@ -27426,7 +28651,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-25
@@ -27480,6 +28705,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -27519,7 +28748,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-25
@@ -27559,6 +28788,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -28116,7 +29349,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-25
@@ -28170,6 +29403,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -28209,7 +29446,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-26
@@ -28249,6 +29486,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -28288,7 +29529,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/001/ T1087.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] * '''Last Updated''': 2021-08-23
@@ -28322,6 +29563,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1087 +| Account Discovery +| Discovery +|- | T1087.001 | Local Account | Discovery @@ -28359,7 +29604,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/001/ T1087.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] * '''Last Updated''': 2021-08-23
@@ -28391,6 +29636,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1087 +| Account Discovery +| Discovery +|- | T1087.001 | Local Account | Discovery @@ -28600,7 +29849,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-08-24
@@ -28653,6 +29902,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -28687,7 +29940,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-08-24
@@ -28731,6 +29984,10 @@ he following Hunting analytic requires PowerShell operational logs to be importe | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -28937,7 +30194,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-25
@@ -28991,6 +30248,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -29030,7 +30291,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/002/ T1069.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/002/ T1069.002] * '''Last Updated''': 2021-08-25
@@ -29070,6 +30331,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.002 | Domain Groups | Discovery @@ -29109,7 +30374,7 @@ This analytic looks for the execution of `powershell.exe` with command-line argu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/001/ T1087.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] * '''Last Updated''': 2021-08-23
@@ -29143,6 +30408,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1087 +| Account Discovery +| Discovery +|- | T1087.001 | Local Account | Discovery @@ -29180,7 +30449,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/001/ T1087.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] * '''Last Updated''': 2021-08-23
@@ -29212,6 +30481,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1087 +| Account Discovery +| Discovery +|- | T1087.001 | Local Account | Discovery @@ -29332,7 +30605,7 @@ This analytic identifies a suspicious registry modification to hide a user accou * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-05-05
@@ -29377,6 +30650,10 @@ To successfully implement this search, you must be ingesting data that records r | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -29411,7 +30688,7 @@ Attackers leverage an existing Windows binary, attrib.exe, to mark specific as h * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1222/001/ T1222.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1222/ T1222], [https://attack.mitre.org/techniques/T1222/001/ T1222.001] * '''Last Updated''': 2020-07-21
@@ -29457,6 +30734,10 @@ You must be ingesting data that records process activity from your hosts to popu ! Technique ! Tactic |- +| T1222 +| File and Directory Permissions Modification +| Defense Evasion +|- | T1222.001 | Windows File and Directory Permissions Modification | Defense Evasion @@ -29825,7 +31106,7 @@ This search is to detect a suspicious file creation namely passff.tar and cookie * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560/001/ T1560.001], [https://attack.mitre.org/techniques/T1560/ T1560] * '''Last Updated''': 2021-07-30
@@ -29871,6 +31152,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1560.001 | Archive via Utility | Collection +|- +| T1560 +| Archive Collected Data +| Collection |} @@ -30761,7 +32046,7 @@ This search is to detect a execution of jscript using cscript process. Commonly * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/007/ T1059.007] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/007/ T1059.007] * '''Last Updated''': 2021-09-13
@@ -30809,6 +32094,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.007 | JavaScript | Execution @@ -30848,7 +32137,7 @@ This search detects a potential kerberoasting attack via service principal name * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1558/003/ T1558.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1558/003/ T1558.003], [https://attack.mitre.org/techniques/T1558/ T1558] * '''Last Updated''': 2020-10-16
@@ -30896,6 +32185,10 @@ You must be ingesting endpoint data that tracks process activity, and include th | T1558.003 | Kerberoasting | Credential Access +|- +| T1558 +| Steal or Forge Kerberos Tickets +| Credential Access |} @@ -31014,7 +32307,7 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/001/ T1087.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] * '''Last Updated''': 2021-09-16
@@ -31048,6 +32341,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1087 +| Account Discovery +| Discovery +|- | T1087.001 | Local Account | Discovery @@ -31085,7 +32382,7 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command-li * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/001/ T1087.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1087/001/ T1087.001] * '''Last Updated''': 2021-09-16
@@ -31119,6 +32416,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1087 +| Account Discovery +| Discovery +|- | T1087.001 | Local Account | Discovery @@ -31151,12 +32452,99 @@ Administrators or power users may use this command for troubleshooting. ---- +===Logon script event trigger execution=== +This search is to detect a suspicious modification of registry entry to persist and gain privilege escalation upon booting up of compromised host. This technique was seen in several APT and malware where it modify UserInitMprLogonScript registry entry to its malicious payload to be executed upon boot up of the machine. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1037/ T1037], [https://attack.mitre.org/techniques/T1037/001/ T1037.001] +* '''Last Updated''': 2021-09-27 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path IN ("*\\Environment\\UserInitMprLogonScript") by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `logon_script_event_trigger_execution_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + +* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] + + +====How To Implement==== +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +====Required field==== + +* _time + +* Registry.dest + +* Registry.user + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.registry_value_name + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1037 +| Boot or Logon Initialization Scripts +| Persistence, Privilege Escalation +|- +| T1037.001 +| Logon Script (Windows) +| Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +unknown + +====Reference==== + + +* https://attack.mitre.org/techniques/T1037/001 + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1037.001/logonscript_reg/sysmon.log + + +''version'': 1 +
+
+ +---- + ===Ms scripting process loading ldap module=== This search is to detect a suspicious MS scripting process such as wscript.exe or cscript.exe that loading ldap module to process ldap query. This behavior was seen in FIN7 implant where it uses javascript to execute ldap query to parse host information that will send to its C2 server. this anomaly detections is a good initial step to hunt further a suspicious ldap query or ldap related events to the host that may give you good information regarding ldap or AD information processing or might be a attacker. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/007/ T1059.007] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/007/ T1059.007] * '''Last Updated''': 2021-09-13
@@ -31203,6 +32591,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.007 | JavaScript | Execution @@ -31242,7 +32634,7 @@ This search is to detect a suspicious MS scripting process such as wscript.exe o * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/007/ T1059.007] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/007/ T1059.007] * '''Last Updated''': 2021-09-13
@@ -31289,6 +32681,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.007 | JavaScript | Execution @@ -31317,6 +32713,93 @@ automation scripting language may used by network operator to do ldap query. * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/fin7/fin7_js_2/sysmon.log +''version'': 1 +
+
+ +---- + +===Msbuild suspicious spawned by script process=== +This analytic is to detect a suspicious child process of MSBuild spawned by Windows Script Host - cscript or wscript. This behavior or event are commonly seen and used by malware or adversaries to execute malicious msbuild process using malicious script in the compromised host. During triage, review parallel processes and identify any file modifications. MSBuild may load a script from the same path without having command-line arguments. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1127/001/ T1127.001], [https://attack.mitre.org/techniques/T1127/ T1127] +* '''Last Updated''': 2021-10-04 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("wscript.exe", "cscript.exe") AND `process_msbuild` by Processes.dest Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `msbuild_suspicious_spawned_by_script_process_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Trusted_Developer_Utilities_Proxy_Execution_MSBuild|Trusted Developer Utilities Proxy Execution MSBuild]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +====Required field==== + +* _time + +* Processes.dest + +* Processes.parent_process + +* Processes.parent_process_name + +* Processes.process_name + +* Processes.original_file_name + +* Processes.user + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1127.001 +| MSBuild +| Defense Evasion +|- +| T1127 +| Trusted Developer Utilities Proxy Execution +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +False positives should be limited as developers do not spawn MSBuild via a WSH. + +====Reference==== + + +* https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/# + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/regsvr32_silent/sysmon.log + + ''version'': 1
@@ -31328,7 +32811,7 @@ The following detection identifies the module load of mshtml.dll into an Office * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-09-09
@@ -31374,6 +32857,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -31481,7 +32968,7 @@ This search is to detect known mailsniper.ps1 functions executed in a machine. T * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/001/ T1114.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/ T1114], [https://attack.mitre.org/techniques/T1114/001/ T1114.001] * '''Last Updated''': 2021-05-19
@@ -31522,6 +33009,10 @@ To successfully implement this search, you need to be ingesting logs with the po ! Technique ! Tactic |- +| T1114 +| Email Collection +| Collection +|- | T1114.001 | Local Email Collection | Collection @@ -31548,6 +33039,104 @@ unknown * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log +''version'': 1 +
+
+ +---- + +===Malicious inprocserver32 modification=== +The following analytic identifies a process modifying the registry with a known malicious CLSID under InProcServer32. Most COM classes are registered with the operating system and are identified by a GUID that represents the Class Identifier (CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind the implementation of a COM class is the server (some binary) that is referenced within registry keys under the CLSID. The LocalServer32 key represents a path to an executable (exe) implementation, and the InprocServer32 key represents a path to a dynamic link library (DLL) implementation (Bohops). During triage, review parallel processes for suspicious activity. Pivot on the process GUID to see the full timeline of events. Analyze the value and look for file modifications. Being this is looking for inprocserver32, a DLL found in the value will most likely be loaded by a parallel process. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/010/ T1218.010], [https://attack.mitre.org/techniques/T1112/ T1112] +* '''Last Updated''': 2021-10-05 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid Processes.user +| `drop_dm_object_name(Processes)` +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest Registry.process_guid Registry.user +| `drop_dm_object_name(Registry)` +| fields _time dest registry_path registry_key_name registry_value_name process_name process_path process process_guid user] +| stats count min(_time) as firstTime max(_time) as lastTime by dest, process_name registry_path registry_key_name registry_value_name user +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `malicious_inprocserver32_modification_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvr32_Activity|Suspicious Regsvr32 Activity]] + +* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +====Required field==== + +* _time + +* dest + +* process_name + +* registry_path + +* registry_key_name + +* registry_value_name + +* user + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1218.010 +| Regsvr32 +| Defense Evasion +|- +| T1112 +| Modify Registry +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +False positives should be limited, filter as needed. In our test case, Remcos used regsvr32.exe to modify the registry. It may be required, dependent upon the EDR tool producing registry events, to remove (Default) from the command-line. + +====Reference==== + + +* https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ + +* https://tria.ge/210929-ap75vsddan + +* https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + + ''version'': 1
@@ -31559,7 +33148,7 @@ The following hunting analytic identifies PowerShell commands utilizing the Wind * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001], [https://attack.mitre.org/techniques/T1059/ T1059] * '''Last Updated''': 2021-10-05
@@ -31615,6 +33204,10 @@ You must be ingesting data that records process activity from your hosts to popu | T1059.001 | PowerShell | Execution +|- +| T1059 +| Command and Scripting Interpreter +| Execution |} @@ -31758,7 +33351,7 @@ This search looks for PowerShell processes started with parameters used to bypas * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2020-07-21
@@ -31816,6 +33409,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -31851,7 +33448,7 @@ This search looks for PowerShell processes launched with arguments that have cha * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-01-19
@@ -31909,6 +33506,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -31944,7 +33545,7 @@ This detection is to identify the abuse the Windows SC.exe to execute malicious * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/002/ T1569.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1569/002/ T1569.002] * '''Last Updated''': 2021-04-07
@@ -32000,6 +33601,10 @@ To successfully implement this search, you need to be ingesting Windows System l ! Technique ! Tactic |- +| T1569 +| System Services +| Execution +|- | T1569.002 | Service Execution | Execution @@ -32299,7 +33904,7 @@ This search looks for registry activity associated with modifications to the reg * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/010/ T1547.010] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/010/ T1547.010], [https://attack.mitre.org/techniques/T1547/ T1547] * '''Last Updated''': 2020-11-23
@@ -32348,6 +33953,10 @@ To successfully implement this search, you must be ingesting data that records r | T1547.010 | Port Monitors | Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation |} @@ -32461,7 +34070,7 @@ This search is to detect a suspicious mshta.exe process that spawn rundll32 or r * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/005/ T1218.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] * '''Last Updated''': 2021-07-19
@@ -32519,6 +34128,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.005 | Mshta | Defense Evasion @@ -32556,7 +34169,7 @@ This search is to detect a suspicious creation of msmpeng.exe or mpsvc.dll in no * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1574/002/ T1574.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1574/002/ T1574.002], [https://attack.mitre.org/techniques/T1574/ T1574] * '''Last Updated''': 2021-07-05
@@ -32605,6 +34218,10 @@ To successfully implement this search you need to be ingesting information on pr | T1574.002 | DLL Side-Loading | Persistence, Privilege Escalation, Defense Evasion +|- +| T1574 +| Hijack Execution Flow +| Persistence, Privilege Escalation, Defense Evasion |} @@ -32642,7 +34259,7 @@ The analytics returned fields allow analysts to investigate the event further by * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] * '''Last Updated''': 2021-04-14
@@ -32689,6 +34306,10 @@ To successfully implement this search, you need to be ingesting Domain Controlle | T1110.003 | Password Spraying | Credential Access +|- +| T1110 +| Brute Force +| Credential Access |} @@ -32726,7 +34347,7 @@ The analytics returned fields allow analysts to investigate the event further by * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] * '''Last Updated''': 2021-04-14
@@ -32773,6 +34394,10 @@ To successfully implement this search, you need to be ingesting Domain Controlle | T1110.003 | Password Spraying | Credential Access +|- +| T1110 +| Brute Force +| Credential Access |} @@ -32810,7 +34435,7 @@ The analytics returned fields allow analysts to investigate the event further by * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] * '''Last Updated''': 2021-04-15
@@ -32857,6 +34482,10 @@ To successfully implement this search, you need to be ingesting Domain Controlle | T1110.003 | Password Spraying | Credential Access +|- +| T1110 +| Brute Force +| Credential Access |} @@ -32898,7 +34527,7 @@ The analytics returned fields allow analysts to investigate the event further by * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] * '''Last Updated''': 2021-04-13
@@ -32948,6 +34577,10 @@ To successfully implement this search, you need to be ingesting Windows Event Lo | T1110.003 | Password Spraying | Credential Access +|- +| T1110 +| Brute Force +| Credential Access |} @@ -32989,7 +34622,7 @@ The analytics returned fields allow analysts to investigate the event further by * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] * '''Last Updated''': 2021-04-08
@@ -33036,6 +34669,10 @@ To successfully implement this search, you need to be ingesting Domain Controlle | T1110.003 | Password Spraying | Credential Access +|- +| T1110 +| Brute Force +| Credential Access |} @@ -33077,7 +34714,7 @@ The analytics returned fields allow analysts to investigate the event further by * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] * '''Last Updated''': 2021-04-13
@@ -33124,6 +34761,10 @@ To successfully implement this search, you need to be ingesting Domain Controlle | T1110.003 | Password Spraying | Credential Access +|- +| T1110 +| Brute Force +| Credential Access |} @@ -33165,7 +34806,7 @@ The analytics returned fields allow analysts to investigate the event further by * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] * '''Last Updated''': 2021-04-13
@@ -33218,6 +34859,10 @@ To successfully implement this search, you need to be ingesting Windows Event Lo | T1110.003 | Password Spraying | Credential Access +|- +| T1110 +| Brute Force +| Credential Access |} @@ -33261,7 +34906,7 @@ The analytics returned fields allow analysts to investigate the event further by * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/003/ T1110.003], [https://attack.mitre.org/techniques/T1110/ T1110] * '''Last Updated''': 2021-04-13
@@ -33313,6 +34958,10 @@ To successfully implement this search, you need to be ingesting Windows Event Lo | T1110.003 | Password Spraying | Credential Access +|- +| T1110 +| Brute Force +| Credential Access |} @@ -33353,7 +35002,7 @@ This search is to detect modification of registry to bypass UAC windows feature. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2021-07-12
@@ -33398,6 +35047,10 @@ To successfully implement this search you need to be ingesting information on pr | T1548.002 | Bypass User Account Control | Privilege Escalation, Defense Evasion +|- +| T1548 +| Abuse Elevation Control Mechanism +| Privilege Escalation, Defense Evasion |} @@ -33535,7 +35188,7 @@ The following hunting analytic will identify the use of localgroup discovery usi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/001/ T1069.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] * '''Last Updated''': 2021-09-14
@@ -33591,6 +35244,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.001 | Local Groups | Discovery @@ -33903,7 +35560,7 @@ This query detects the Nishang Invoke-PowerShellTCPOneLine utility that spawns a * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-03-03
@@ -33959,6 +35616,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -34002,7 +35663,7 @@ This search is to detect an anomaly event of non-chrome process accessing the fi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1555/003/ T1555.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1555/ T1555], [https://attack.mitre.org/techniques/T1555/003/ T1555.003] * '''Last Updated''': 2021-09-15
@@ -34053,6 +35714,10 @@ To successfully implement this search, you must ingest Windows Security Event lo ! Technique ! Tactic |- +| T1555 +| Credentials from Password Stores +| Credential Access +|- | T1555.003 | Credentials from Web Browsers | Credential Access @@ -34086,7 +35751,7 @@ This search is to detect an anomaly event of non-firefox process accessing the f * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1555/003/ T1555.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1555/ T1555], [https://attack.mitre.org/techniques/T1555/003/ T1555.003] * '''Last Updated''': 2021-09-15
@@ -34137,6 +35802,10 @@ To successfully implement this search, you must ingest Windows Security Event lo ! Technique ! Tactic |- +| T1555 +| Credentials from Password Stores +| Credential Access +|- | T1555.003 | Credentials from Web Browsers | Credential Access @@ -34172,7 +35841,7 @@ This technique uses "Install from Media" (IFM), which will extract a cop * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-01-28
@@ -34225,6 +35894,10 @@ You must be ingesting endpoint data that tracks process activity, including pare | T1003.003 | NTDS | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -34265,7 +35938,7 @@ This search is to detect a suspicious MS office application that drop or create * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-09-13
@@ -34313,6 +35986,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -34352,7 +36029,7 @@ this detection was designed to identifies suspicious spawned process of known MS * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-07-30
@@ -34408,6 +36085,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -34445,7 +36126,7 @@ this detection was designed to identifies suspicious spawned process of known MS * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-04-13
@@ -34503,6 +36184,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -34542,7 +36227,7 @@ this search detects a potential malicious office document that create schedule t * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-04-14
@@ -34591,6 +36276,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -34630,7 +36319,7 @@ this detection was designed to identifies suspicious office documents that using * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-04-14
@@ -34683,6 +36372,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -34720,7 +36413,7 @@ This search is to detect potential malicious office document executing lolbin ch * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-09-20
@@ -34776,6 +36469,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -34813,7 +36510,7 @@ this search is to detect a suspicious office product process that spawn cmd chil * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/005/ T1218.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] * '''Last Updated''': 2021-07-19
@@ -34869,6 +36566,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.005 | Mshta | Defense Evasion @@ -34906,7 +36607,7 @@ The following detection identifies the latest behavior utilized by different mal * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-04-26
@@ -34962,6 +36663,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -34999,7 +36704,7 @@ The following detection identifies the latest behavior utilized by different mal * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-04-26
@@ -35055,6 +36760,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -35094,7 +36803,7 @@ The following detection identifies the latest behavior utilized by different mal * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-04-26
@@ -35152,6 +36861,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -35189,7 +36902,7 @@ The following detection identifies the latest behavior utilized by IcedID malwar * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-04-22
@@ -35245,6 +36958,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -35286,7 +37003,7 @@ The following detection identifies the latest behavior utilized by Ursnif malwar * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-09-16
@@ -35344,6 +37061,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -35385,7 +37106,7 @@ The following analytic identifies behavior related to CVE-2021-40444. Whereas th * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-09-10
@@ -35437,6 +37158,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -35480,7 +37205,7 @@ The following detection identifies control.exe spawning from an office product. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-09-08
@@ -35536,6 +37261,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -35583,7 +37312,7 @@ Microsoft Windows contains accessibility features that can be launched with a ke * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/008/ T1546.008] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/ T1546], [https://attack.mitre.org/techniques/T1546/008/ T1546.008] * '''Last Updated''': 2020-07-21
@@ -35625,6 +37354,10 @@ You must be ingesting data that records the filesystem activity from your hosts ! Technique ! Tactic |- +| T1546 +| Event Triggered Execution +| Privilege Escalation, Persistence +|- | T1546.008 | Accessibility Features | Privilege Escalation, Persistence @@ -36007,7 +37740,7 @@ This detection identifies potential Pass the Token or Pass the Hash credential e * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/002/ T1550.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/ T1550], [https://attack.mitre.org/techniques/T1550/002/ T1550.002] * '''Last Updated''': 2021-09-01
@@ -36060,6 +37793,10 @@ You must be ingesting Windows Security logs from endpoint devices, i.e., destina ! Technique ! Tactic |- +| T1550 +| Use Alternate Authentication Material +| Defense Evasion, Lateral Movement +|- | T1550.002 | Pass the Hash | Defense Evasion, Lateral Movement @@ -36095,7 +37832,7 @@ This detection identifies potential Pass the Token or Pass the Hash credential e * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/002/ T1550.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/ T1550], [https://attack.mitre.org/techniques/T1550/002/ T1550.002] * '''Last Updated''': 2021-09-01
@@ -36148,6 +37885,10 @@ You must be ingesting Windows Security logs from devices of interest - at least ! Technique ! Tactic |- +| T1550 +| Use Alternate Authentication Material +| Defense Evasion, Lateral Movement +|- | T1550.002 | Pass the Hash | Defense Evasion, Lateral Movement @@ -36183,7 +37924,7 @@ The following Hunting analytic assists with identifying suspicious PowerShell ex * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-08-18
@@ -36392,6 +38133,10 @@ The following Hunting analytic requires PowerShell operational logs to be import ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -36441,7 +38186,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-06-10
@@ -36480,6 +38225,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -36523,7 +38272,7 @@ The following hunting analytic identifies the use of `get-localgroup` being used * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/001/ T1069.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] * '''Last Updated''': 2021-09-14
@@ -36579,6 +38328,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.001 | Local Groups | Discovery @@ -36620,7 +38373,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-06-10
@@ -36663,6 +38416,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -36803,7 +38560,7 @@ The following analytic identifies suspicious PowerShell script execution via Eve * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1027/005/ T1027.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1027/005/ T1027.005] * '''Last Updated''': 2021-06-10
@@ -36844,6 +38601,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1027 +| Obfuscated Files or Information +| Defense Evasion +|- | T1027.005 | Indicator Removal from Tools | Defense Evasion @@ -36889,7 +38650,7 @@ This search is to identifies a modification in registry to disable the windows d * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-07-05
@@ -36950,6 +38711,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -36984,7 +38749,7 @@ This search is to detect a suspicious enabling of smb1protocol through "powe * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1027/005/ T1027.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1027/005/ T1027.005] * '''Last Updated''': 2021-06-22
@@ -37027,6 +38792,10 @@ To successfully implement this search, you need to be ingesting logs with the po ! Technique ! Tactic |- +| T1027 +| Obfuscated Files or Information +| Defense Evasion +|- | T1027.005 | Indicator Removal from Tools | Defense Evasion @@ -37064,7 +38833,7 @@ This search is to detect a COM CLSID execution through powershell. This techniqu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/015/ T1546.015] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/015/ T1546.015], [https://attack.mitre.org/techniques/T1546/ T1546] * '''Last Updated''': 2021-08-10
@@ -37102,6 +38871,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1546.015 | Component Object Model Hijacking | Privilege Escalation, Persistence +|- +| T1546 +| Event Triggered Execution +| Privilege Escalation, Persistence |} @@ -37139,7 +38912,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-06-08
@@ -37182,6 +38955,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1055 | Process Injection | Defense Evasion, Privilege Escalation @@ -37232,7 +39009,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-06-08
@@ -37275,6 +39052,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1027 | Obfuscated Files or Information | Defense Evasion @@ -37326,7 +39107,7 @@ During triage, review parallel processes using an EDR product or 4688 events. It * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/001/ T1069.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] * '''Last Updated''': 2021-09-14
@@ -37367,6 +39148,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.001 | Local Groups | Discovery @@ -37414,7 +39199,7 @@ The following analytic identifies suspicious PowerShell script execution via Eve * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2021-06-10
@@ -37457,6 +39242,10 @@ To successfully implement this analytic, you will need to enable PowerShell Scri ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -37754,6 +39543,95 @@ Administrators may modify the boot configuration ignore failure during testing a * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data1/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Print processor registry autostart=== +This analytic is to detect a suspicious modification or new registry entry regarding print processor. This registry is known to be abuse by turla or other APT to gain persistence and privilege escalation to the compromised machine. This is done by adding the malicious dll payload on the new created key in this registry that will be executed as it restarted the spoolsv.exe process and services. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] +* '''Last Updated''': 2021-09-28 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\Control\\Print\\Environments\\Windows x64\\Print Processors*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `print_processor_registry_autostart_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + +* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] + + +====How To Implement==== +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +====Required field==== + +* _time + +* Registry.dest + +* Registry.user + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.registry_value_name + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1547.012 +| Print Processors +| Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +possible new printer installation may add driver component on this registry. + +====Reference==== + + +* https://attack.mitre.org/techniques/T1547/012/ + +* https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/ + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/print_reg/sysmon_print.log + + ''version'': 1
@@ -37767,7 +39645,7 @@ During triage, isolate the endpoint and review for source of exploitation. Captu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] * '''Last Updated''': 2021-07-01
@@ -37811,6 +39689,10 @@ You will need to ensure PrintService Admin and Operational logs are being logged | T1547.012 | Print Processors | Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation |} @@ -37854,7 +39736,7 @@ During triage, isolate the endpoint and review for source of exploitation. Captu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] * '''Last Updated''': 2021-07-01
@@ -37898,6 +39780,10 @@ You will need to ensure PrintService Admin and Operational logs are being logged | T1547.012 | Print Processors | Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation |} @@ -38015,7 +39901,7 @@ This search looks for a process launching an `*.lnk` file under `C:\User*` or `* * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/002/ T1566.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/002/ T1566.002] * '''Last Updated''': 2021-08-26
@@ -38070,6 +39956,10 @@ You must be ingesting data that records filesystem and process activity from you ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.002 | Spearphishing Link | Initial Access @@ -38282,7 +40172,7 @@ The following analytic identifies the use of `wmic.exe` using `delete` to remove * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-05-04
@@ -38341,6 +40231,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -38370,6 +40264,106 @@ Unknown. ---- +===Process writing dynamicwrapperx=== +DynamicWrapperX is an ActiveX component that can be used in a script to call Windows API functions, but it requires the dynwrapx.dll to be installed and registered. With that, a binary writing dynwrapx.dll to disk and registering it into the registry is highly suspect. Why is it needed? In most malicious instances, it will be written to disk at a non-standard location. During triage, review parallel processes and pivot on the process_guid. Review the registry for any suspicious modifications meant to load dynwrapx.dll. Identify any suspicious module loads of dynwrapx.dll. This will identify the process that will invoke vbs/wscript/cscript. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1559/001/ T1559.001] +* '''Last Updated''': 2021-10-05 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid Processes.user +| `drop_dm_object_name(Processes)` +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="dynwrapx.dll" by _time Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid Filesystem.user +| `drop_dm_object_name(Filesystem)` +| fields _time process_guid file_path file_name file_create_time user dest process_name] +| stats count min(_time) as firstTime max(_time) as lastTime by dest process_name process_guid file_name file_path file_create_time user +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `process_writing_dynamicwrapperx_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +====Required field==== + +* _time + +* dest + +* process_name + +* process_guid + +* file_name + +* file_path + +* file_create_time user + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1059 +| Command and Scripting Interpreter +| Execution +|- +| T1559.001 +| Component Object Model +| Execution +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +False positives should be limited, however it is possible to filter by Processes.process_name and specific processes (ex. wscript.exe). Filter as needed. This may need modification based on EDR telemetry and how it brings in registry data. For example, removal of (Default). + +====Reference==== + + +* https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/ + +* https://www.script-coding.com/dynwrapx_eng.html + +* https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ + +* https://tria.ge/210929-ap75vsddan + +* https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + ===Processes tapping keyboard events=== This search looks for processes in an MacOS system that is tapping keyboard events in MacOS, and essentially monitoring all keystrokes made by a user. This is a common technique used by RATs to log keystrokes from a victim, although it can also be used by legitimate processes like Siri to react on human input @@ -38442,7 +40436,7 @@ This search looks for processes launching netsh.exe. Netsh is a command-line scr * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/004/ T1562.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/004/ T1562.004], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-09-16
@@ -38495,6 +40489,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.004 | Disable or Modify System Firewall | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -39309,7 +41307,7 @@ This detection identifies access to PowerSploit modules that discover and access * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1007/ T1007], [https://attack.mitre.org/techniques/T1012/ T1012], [https://attack.mitre.org/techniques/T1046/ T1046], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1057/ T1057], [https://attack.mitre.org/techniques/T1083/ T1083], [https://attack.mitre.org/techniques/T1518/ T1518], [https://attack.mitre.org/techniques/T1592/002/ T1592.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1057/ T1057], [https://attack.mitre.org/techniques/T1083/ T1083], [https://attack.mitre.org/techniques/T1592/002/ T1592.002], [https://attack.mitre.org/techniques/T1046/ T1046], [https://attack.mitre.org/techniques/T1012/ T1012], [https://attack.mitre.org/techniques/T1007/ T1007], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1592/ T1592], [https://attack.mitre.org/techniques/T1518/ T1518] * '''Last Updated''': 2020-11-06
@@ -39351,22 +41349,6 @@ You must be ingesting Windows Security logs from devices of interest, including ! Technique ! Tactic |- -| T1007 -| System Service Discovery -| Discovery -|- -| T1012 -| Query Registry -| Discovery -|- -| T1046 -| Network Service Scanning -| Discovery -|- -| T1047 -| Windows Management Instrumentation -| Execution -|- | T1057 | Process Discovery | Discovery @@ -39375,13 +41357,33 @@ You must be ingesting Windows Security logs from devices of interest, including | File and Directory Discovery | Discovery |- -| T1518 -| Software Discovery -| Discovery -|- | T1592.002 | Software | Reconnaissance +|- +| T1046 +| Network Service Scanning +| Discovery +|- +| T1012 +| Query Registry +| Discovery +|- +| T1007 +| System Service Discovery +| Discovery +|- +| T1047 +| Windows Management Instrumentation +| Execution +|- +| T1592 +| Gather Victim Host Information +| Reconnaissance +|- +| T1518 +| Software Discovery +| Discovery |} @@ -39499,7 +41501,7 @@ This detection identifies use of Mimikatz modules for discovery and access to ne * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/002/ T1021.002], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1039/ T1039] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1039/ T1039], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1021/002/ T1021.002] * '''Last Updated''': 2020-11-06
@@ -39541,17 +41543,21 @@ You must be ingesting Windows Security logs from devices of interest, including ! Technique ! Tactic |- -| T1021.002 -| SMB/Windows Admin Shares +| T1021 +| Remote Services | Lateral Movement |- +| T1039 +| Data from Network Shared Drive +| Collection +|- | T1135 | Network Share Discovery | Discovery |- -| T1039 -| Data from Network Shared Drive -| Collection +| T1021.002 +| SMB/Windows Admin Shares +| Lateral Movement |} @@ -39584,7 +41590,7 @@ This detection identifies access to PowerSploit modules that discover and access * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/002/ T1021.002], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1039/ T1039] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1039/ T1039], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1021/002/ T1021.002] * '''Last Updated''': 2020-11-06
@@ -39626,17 +41632,21 @@ You must be ingesting Windows Security logs from devices of interest, including ! Technique ! Tactic |- -| T1021.002 -| SMB/Windows Admin Shares +| T1021 +| Remote Services | Lateral Movement |- +| T1039 +| Data from Network Shared Drive +| Collection +|- | T1135 | Network Share Discovery | Discovery |- -| T1039 -| Data from Network Shared Drive -| Collection +| T1021.002 +| SMB/Windows Admin Shares +| Lateral Movement |} @@ -39766,7 +41776,7 @@ This detection identifies access to PowerSploit modules for reconnaissance of co * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/002/ T1021.002], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1039/ T1039] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1039/ T1039], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1021/002/ T1021.002] * '''Last Updated''': 2020-11-06
@@ -39808,17 +41818,21 @@ You must be ingesting Windows Security logs from devices of interest, including ! Technique ! Tactic |- -| T1021.002 -| SMB/Windows Admin Shares +| T1021 +| Remote Services | Lateral Movement |- +| T1039 +| Data from Network Shared Drive +| Collection +|- | T1135 | Network Share Discovery | Discovery |- -| T1039 -| Data from Network Shared Drive -| Collection +| T1021.002 +| SMB/Windows Admin Shares +| Lateral Movement |} @@ -39851,7 +41865,7 @@ This detection identifies reconnaissance of credential stores and use of CryptoA * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1589/001/ T1589.001], [https://attack.mitre.org/techniques/T1590/001/ T1590.001], [https://attack.mitre.org/techniques/T1590/003/ T1590.003], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1590/001/ T1590.001], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1589/001/ T1589.001], [https://attack.mitre.org/techniques/T1590/ T1590], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1589/ T1589], [https://attack.mitre.org/techniques/T1590/003/ T1590.003] * '''Last Updated''': 2020-11-03
@@ -39893,29 +41907,37 @@ You must be ingesting Windows Security logs from devices of interest, including ! Technique ! Tactic |- -| T1589.001 -| Credentials -| Reconnaissance +| T1098 +| Account Manipulation +| Persistence |- | T1590.001 | Domain Properties | Reconnaissance |- -| T1590.003 -| Network Trust Dependencies +| T1078 +| Valid Accounts +| Defense Evasion, Persistence, Privilege Escalation, Initial Access +|- +| T1589.001 +| Credentials +| Reconnaissance +|- +| T1590 +| Gather Victim Network Information | Reconnaissance |- | T1068 | Exploitation for Privilege Escalation | Privilege Escalation |- -| T1078 -| Valid Accounts -| Defense Evasion, Persistence, Privilege Escalation, Initial Access +| T1589 +| Gather Victim Identity Information +| Reconnaissance |- -| T1098 -| Account Manipulation -| Persistence +| T1590.003 +| Network Trust Dependencies +| Reconnaissance |} @@ -39948,7 +41970,7 @@ This detection identifies use of PowerSploit modules for assessment of presence * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1595/002/ T1595.002], [https://attack.mitre.org/techniques/T1592/002/ T1592.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1592/002/ T1592.002], [https://attack.mitre.org/techniques/T1595/002/ T1595.002], [https://attack.mitre.org/techniques/T1592/ T1592], [https://attack.mitre.org/techniques/T1595/ T1595] * '''Last Updated''': 2020-11-05
@@ -39990,12 +42012,20 @@ You must be ingesting Windows Security logs from devices of interest, including ! Technique ! Tactic |- +| T1592.002 +| Software +| Reconnaissance +|- | T1595.002 | Vulnerability Scanning | Reconnaissance |- -| T1592.002 -| Software +| T1592 +| Gather Victim Host Information +| Reconnaissance +|- +| T1595 +| Active Scanning | Reconnaissance |} @@ -40201,7 +42231,7 @@ This search is to detect a suspicious commandline designed to delete files or di * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/004/ T1070.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/004/ T1070.004], [https://attack.mitre.org/techniques/T1070/ T1070] * '''Last Updated''': 2021-06-22
@@ -40260,6 +42290,10 @@ To successfully implement this search you need to be ingesting information on pr | T1070.004 | File Deletion | Defense Evasion +|- +| T1070 +| Indicator Removal on Host +| Defense Evasion |} @@ -40294,7 +42328,7 @@ The search looks for reg.exe modifying registry keys that define Windows service * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1574/011/ T1574.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1574/011/ T1574.011], [https://attack.mitre.org/techniques/T1574/ T1574] * '''Last Updated''': 2020-11-26
@@ -40345,6 +42379,10 @@ To successfully implement this search, you must be ingesting data that records r | T1574.011 | Services Registry Permissions Weakness | Persistence, Privilege Escalation, Defense Evasion +|- +| T1574 +| Hijack Execution Flow +| Persistence, Privilege Escalation, Defense Evasion |} @@ -40375,7 +42413,7 @@ The search looks for modifications to registry keys that can be used to launch a * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/001/ T1547.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/001/ T1547.001], [https://attack.mitre.org/techniques/T1547/ T1547] * '''Last Updated''': 2021-09-07
@@ -40383,7 +42421,7 @@ The search looks for modifications to registry keys that can be used to launch a ====Search==== -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user +| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run" AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` @@ -40436,6 +42474,10 @@ To successfully implement this search, you must be ingesting data that records r | T1547.001 | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation |} @@ -40466,7 +42508,7 @@ This search looks for modifications to registry keys that can be used to elevate * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/012/ T1546.012] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/012/ T1546.012], [https://attack.mitre.org/techniques/T1546/ T1546] * '''Last Updated''': 2020-11-27
@@ -40515,6 +42557,10 @@ To successfully implement this search, you must be ingesting data that records r | T1546.012 | Image File Execution Options Injection | Privilege Escalation, Persistence +|- +| T1546 +| Event Triggered Execution +| Privilege Escalation, Persistence |} @@ -40549,7 +42595,7 @@ This search looks for registry activity associated with application compatibilit * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/011/ T1546.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/011/ T1546.011], [https://attack.mitre.org/techniques/T1546/ T1546] * '''Last Updated''': 2020-11-26
@@ -40596,6 +42642,10 @@ To successfully implement this search, you must populate the Change_Analysis dat | T1546.011 | Application Shimming | Privilege Escalation, Persistence +|- +| T1546 +| Event Triggered Execution +| Privilege Escalation, Persistence |} @@ -40621,6 +42671,105 @@ There are many legitimate applications that leverage shim databases for compatib ---- +===Regsvr32 silent param dll loading=== +This analytic is to detect a loading of dll using regsvr32 application with silent parameter and dllinstall execution. This technique was seen in several RAT malware like remcos, njrat and APT's to load their malicious dll in the compromised machine. This TTP may executed by normal 3rd party application so it is better to pivot the parent process, parent commandline and commandline of the file that execute this regsvr32. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/010/ T1218.010] +* '''Last Updated''': 2021-10-04 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = regsvr32.exe Processes.process="*/i*" Processes.process="*/s*" by Processes.dest Processes.parent_process Processes.process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `regsvr32_silent_param_dll_loading_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvr32_Activity|Suspicious Regsvr32 Activity]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +====Required field==== + +* _time + +* Processes.dest + +* Processes.user + +* Processes.parent_process_name + +* Processes.parent_process + +* Processes.original_file_name + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_path + +* Processes.process_path + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- +| T1218.010 +| Regsvr32 +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Other third part application may used this parameter but not so common in base windows environment. + +====Reference==== + + +* https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/# + +* https://attack.mitre.org/techniques/T1218/010/ + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log + + +''version'': 1 +
+
+ +---- + ===Remcos rat file creation in remcos folder=== This search is to detect file creation in remcos folder in appdata which is the keylog and clipboard logs that will be send to its c2 server. This is really a good TTP indicator that there is a remcos rat in the system that do keylogging, clipboard grabbing and audio recording. @@ -40788,7 +42937,7 @@ This search looks for the remote desktop process mstsc.exe running on systems up * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001], [https://attack.mitre.org/techniques/T1021/ T1021] * '''Last Updated''': 2020-07-21
@@ -40835,6 +42984,10 @@ To successfully implement this search, you must be ingesting data that records p | T1021.001 | Remote Desktop Protocol | Lateral Movement +|- +| T1021 +| Remote Services +| Lateral Movement |} @@ -41743,7 +43896,7 @@ This search looks for executing scripts with rundll32. Adversaries may abuse run * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2020-11-30
@@ -41799,6 +43952,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -41832,7 +43989,7 @@ The following hunting detection identifies rundll32.exe with `control_rundll` wi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-09-08
@@ -41888,6 +44045,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -41933,7 +44094,7 @@ The following detection identifies rundll32.exe with `control_rundll` within the * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-09-08
@@ -41989,6 +44150,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -42202,7 +44367,7 @@ This search is to detect a suspicious rundll32.exe process having a http connect * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-07-26
@@ -42247,6 +44412,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -42284,7 +44453,7 @@ This search is to detect a suspicious rundll32 process that drops executable (.e * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-07-26
@@ -42327,6 +44496,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -42359,29 +44532,122 @@ unknown ---- -===Rundll32 with no command line arguments with network=== -The following analytic identifies rundll32.exe with no command line arguments and performing a network connection. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. +===Rundll32 shimcache flush=== +This analytic is to detect a suspicious rundll32 commandline to clear shim cache. This technique is a anti-forensic technique to clear the cache taht are one important artifacts in terms of digital forensic during attacks or incident. This TTP is a good indicator that someone tries to evade some tools and clear foothold on the machine. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] -* '''Last Updated''': 2021-04-19 +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112] +* '''Last Updated''': 2021-10-05
====Search==== -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_rundll32` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name Processes.original_file_name +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` AND Processes.process = "*apphelp.dll,ShimFlushCache*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `rundll32_shimcache_flush_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +====Required field==== + +* _time + +* Processes.dest + +* Processes.user + +* Processes.parent_process_name + +* Processes.parent_process + +* Processes.original_file_name + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_path + +* Processes.process_path + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1112 +| Modify Registry +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +unknown + +====Reference==== + + +* https://blueteamops.medium.com/shimcache-flush-89daff28d15e + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/shimcache_flush/sysmon.log + + +''version'': 1 +
+
+ +---- + +===Rundll32 with no command line arguments with network=== +The following analytic identifies rundll32.exe with no command line arguments and performing a network connection. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''Last Updated''': 2021-10-13 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_rundll32` by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | regex process="(rundll32\.exe.{0,4}$)" -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_id Ports.dest Ports.dest_port +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port | `drop_dm_object_name(Ports)` | rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_id connection_to_CNC dest_port +| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port | `rundll32_with_no_command_line_arguments_with_network_filter` ====Associated Analytic Story==== @@ -42430,6 +44696,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -42462,7 +44732,7 @@ Although unlikely, some legitimate applications may use a moved copy of rundll32 * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log -''version'': 2 +''version'': 3
@@ -42546,7 +44816,7 @@ This Splunk query identifies the use of Wake-on-LAN utilized by Ryuk ransomware. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/003/ T1059.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/003/ T1059.003] * '''Last Updated''': 2021-03-01
@@ -42596,6 +44866,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.003 | Windows Command Shell | Execution @@ -42639,7 +44913,7 @@ The following analytic identifies access to SAM, SYSTEM or SECURITY databases * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-07-23
@@ -42681,6 +44955,10 @@ To successfully implement this search, you must ingest Windows Security Event lo | T1003.002 | Security Account Manager | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -42723,7 +45001,7 @@ The following analytic identifies the Microsoft Software Licensing User Interfac * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2021-05-13
@@ -42776,6 +45054,10 @@ To successfully implement this search you need to be ingesting information on pr | T1548.002 | Bypass User Account Control | Privilege Escalation, Defense Evasion +|- +| T1548 +| Abuse Elevation Control Mechanism +| Privilege Escalation, Defense Evasion |} @@ -42818,7 +45100,7 @@ The following analytic identifies the Microsoft Software Licensing User Interfac * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2021-05-13
@@ -42871,6 +45153,10 @@ To successfully implement this search you need to be ingesting information on pr | T1548.002 | Bypass User Account Control | Privilege Escalation, Defense Evasion +|- +| T1548 +| Abuse Elevation Control Mechanism +| Privilege Escalation, Defense Evasion |} @@ -42984,7 +45270,7 @@ This search looks for arguments to sc.exe indicating the creation or modificatio * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/003/ T1543.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/003/ T1543.003], [https://attack.mitre.org/techniques/T1543/ T1543] * '''Last Updated''': 2020-07-21
@@ -43041,6 +45327,10 @@ To successfully implement this search you need to be ingesting information on pr | T1543.003 | Windows Service | Persistence, Privilege Escalation +|- +| T1543 +| Create or Modify System Process +| Persistence, Privilege Escalation |} @@ -43071,7 +45361,7 @@ This analytic is to detect an application try to connect and create ADSI Object * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1087/002/ T1087.002], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2021-09-07
@@ -43119,6 +45409,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1087.002 | Domain Account | Discovery +|- +| T1087 +| Account Discovery +| Discovery |} @@ -43333,7 +45627,7 @@ This search looks for flags passed to schtasks.exe on the command-line that indi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] * '''Last Updated''': 2020-12-17
@@ -43384,6 +45678,10 @@ You must be ingesting endpoint data that tracks process activity, including pare | T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation +|- +| T1053 +| Scheduled Task/Job +| Execution, Persistence, Privilege Escalation |} @@ -43497,7 +45795,7 @@ This search looks for flags passed to schtasks.exe on the command-line that indi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] * '''Last Updated''': 2020-07-21
@@ -43546,6 +45844,10 @@ You must be ingesting data that records process activity from your hosts to popu | T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation +|- +| T1053 +| Scheduled Task/Job +| Execution, Persistence, Privilege Escalation |} @@ -43576,7 +45878,7 @@ This search looks for flags passed to schtasks.exe on the command-line that indi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] * '''Last Updated''': 2020-12-07
@@ -43625,6 +45927,10 @@ To successfully implement this search you need to be ingesting information on pr | T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation +|- +| T1053 +| Scheduled Task/Job +| Execution, Persistence, Privilege Escalation |} @@ -43650,6 +45956,95 @@ Administrators may create jobs on systems forcing reboots to perform updates, ma ---- +===Screensaver event trigger execution=== +This analytic is developed to detect possible event trigger execution through screensaver registry entry modification for persistence or privilege escalation. This technique was seen in several APT and malware where they put the malicious payload path to the SCRNSAVE.EXE registry key to redirect the execution to their malicious payload path. This TTP is a good indicator that some attacker may modify this entry for their persistence and privilege escalation. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/ T1546], [https://attack.mitre.org/techniques/T1546/002/ T1546.002] +* '''Last Updated''': 2021-09-27 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\Control Panel\\Desktop\\SCRNSAVE.EXE*") by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `screensaver_event_trigger_execution_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + +* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] + + +====How To Implement==== +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +====Required field==== + +* _time + +* Registry.dest + +* Registry.user + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.registry_value_name + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1546 +| Event Triggered Execution +| Privilege Escalation, Persistence +|- +| T1546.002 +| Screensaver +| Privilege Escalation, Persistence +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +unknown + +====Reference==== + + +* https://attack.mitre.org/techniques/T1546/002/ + +* https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.002/scrnsave_reg/sysmon.log + + +''version'': 1 +
+
+ +---- + ===Script execution via wmi=== This search looks for scripts launched via WMI. @@ -43732,7 +46127,7 @@ This search is to detect a suspicious sdclt.exe registry modification. This tech * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2021-07-01
@@ -43777,6 +46172,10 @@ To successfully implement this search you need to be ingesting information on pr | T1548.002 | Bypass User Account Control | Privilege Escalation, Defense Evasion +|- +| T1548 +| Abuse Elevation Control Mechanism +| Privilege Escalation, Defense Evasion |} @@ -43810,29 +46209,130 @@ Limited to no false positives are expected. ---- -===Searchprotocolhost with no command line with network=== -The following analytic identifies searchprotocolhost.exe with no command line arguments and with a network connection. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. +===Sdelete application execution=== +This analytic is to detect the execution of sdelete.exe application sysinternal tools. This tool is one of the most use tool of malware and adversaries to remove or clear their tracks and artifact in the targetted host. This tool is designed to delete securely a file in file system that remove the forensic evidence on the machine. A good TTP query to check why user execute this application which is not a common practice. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] -* '''Last Updated''': 2021-04-19 +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1070/004/ T1070.004], [https://attack.mitre.org/techniques/T1070/ T1070] +* '''Last Updated''': 2021-10-06
====Search==== -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name +| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_sdelete` by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name Processes.parent_process +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `sdelete_application_execution_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Masquerading_-_Rename_System_Utilities|Masquerading - Rename System Utilities]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +====Required field==== + +* _time + +* Processes.dest + +* Processes.user + +* Processes.parent_process_name + +* Processes.parent_process + +* Processes.original_file_name + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_path + +* Processes.process_path + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1485 +| Data Destruction +| Impact +|- +| T1070.004 +| File Deletion +| Defense Evasion +|- +| T1070 +| Indicator Removal on Host +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +user may execute and use this application + +====Reference==== + + +* https://app.any.run/tasks/956f50be-2c13-465a-ac00-6224c14c5f89/ + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/sysmon.log + + +''version'': 1 +
+
+ +---- + +===Searchprotocolhost with no command line with network=== +The following analytic identifies searchprotocolhost.exe with no command line arguments and with a network connection. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] +* '''Last Updated''': 2021-10-13 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | regex process="(searchprotocolhost\.exe.{0,4}$)" -| join process_id [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_id Ports.dest Ports.dest_port +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_guid Ports.dest Ports.dest_port | `drop_dm_object_name(Ports)` | rename dest as connection_to_CNC] -| table _time dest parent_process_name process_name process_path process process_id connection_to_CNC dest_port +| table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port | `searchprotocolhost_with_no_command_line_with_network_filter` ====Associated Analytic Story==== @@ -43891,7 +46391,7 @@ Limited false positives may be present in small environments. Tuning may be requ * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon_searchprotocolhost.log -''version'': 1 +''version'': 2
@@ -43902,7 +46402,7 @@ This analytic detects a potential usage of secretsdump.py tool for dumping crede * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/003/ T1003.003], [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2021-05-26
@@ -43955,6 +46455,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1003.003 | NTDS | Credential Access +|- +| T1003 +| OS Credential Dumping +| Credential Access |} @@ -44080,7 +46584,7 @@ Monitor for changes of the ExecutionPolicy in the registry to the values "un * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/001/ T1059.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1059/001/ T1059.001] * '''Last Updated''': 2020-11-06
@@ -44126,6 +46630,10 @@ You must be ingesting data that records process activity from your hosts to popu ! Technique ! Tactic |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1059.001 | PowerShell | Execution @@ -44428,7 +46936,7 @@ This search looks for shim database files being written to default directories. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/011/ T1546.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/011/ T1546.011], [https://attack.mitre.org/techniques/T1546/ T1546] * '''Last Updated''': 2020-12-08
@@ -44473,6 +46981,10 @@ You must be ingesting data that records the filesystem activity from your hosts | T1546.011 | Application Shimming | Privilege Escalation, Persistence +|- +| T1546 +| Event Triggered Execution +| Privilege Escalation, Persistence |} @@ -44503,7 +47015,7 @@ This search detects the process execution and arguments required to silently cre * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/011/ T1546.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/011/ T1546.011], [https://attack.mitre.org/techniques/T1546/ T1546] * '''Last Updated''': 2020-11-23
@@ -44548,6 +47060,10 @@ You must be ingesting data that records process activity from your hosts to popu | T1546.011 | Application Shimming | Privilege Escalation, Persistence +|- +| T1546 +| Event Triggered Execution +| Privilege Escalation, Persistence |} @@ -44578,7 +47094,7 @@ This search detects accounts that were created and deleted in a short time perio * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/001/ T1136.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/001/ T1136.001], [https://attack.mitre.org/techniques/T1136/ T1136] * '''Last Updated''': 2020-07-06
@@ -44624,6 +47140,10 @@ This search requires you to have enabled your Group Management Audit Logs in you | T1136.001 | Local Account | Persistence +|- +| T1136 +| Create Account +| Persistence |} @@ -44656,7 +47176,7 @@ This search is to detect a suspicious modification of registry that may related * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2021-07-01
@@ -44701,6 +47221,10 @@ To successfully implement this search you need to be ingesting information on pr | T1548.002 | Bypass User Account Control | Privilege Escalation, Defense Evasion +|- +| T1548 +| Abuse Elevation Control Mechanism +| Privilege Escalation, Defense Evasion |} @@ -44737,7 +47261,7 @@ This search looks for process names that consist only of a single letter. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/002/ T1204.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/ T1204], [https://attack.mitre.org/techniques/T1204/002/ T1204.002] * '''Last Updated''': 2020-12-08
@@ -44782,6 +47306,10 @@ You must be ingesting data that records process activity from your hosts to popu ! Technique ! Tactic |- +| T1204 +| User Execution +| Execution +|- | T1204.002 | Malicious File | Execution @@ -44879,7 +47407,7 @@ The following analytic identifies a suspicious child process, `rundll32.exe`, wi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] * '''Last Updated''': 2021-07-01
@@ -44938,6 +47466,10 @@ To successfully implement this search you need to be ingesting information on pr | T1547.012 | Print Processors | Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation |} @@ -44976,7 +47508,7 @@ This search is to detect suspicious loading of dll in specific path relative to * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] * '''Last Updated''': 2021-07-01
@@ -45021,6 +47553,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1547.012 | Print Processors | Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation |} @@ -45141,7 +47677,7 @@ The following analytic identifies a `.dll` being written by `spoolsv.exe`. This * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] * '''Last Updated''': 2021-07-01
@@ -45198,6 +47734,10 @@ To successfully implement this search you need to be ingesting information on pr | T1547.012 | Print Processors | Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation |} @@ -45236,7 +47776,7 @@ The following analytic identifies a `.dll` being written by `spoolsv.exe`. This * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/012/ T1547.012], [https://attack.mitre.org/techniques/T1547/ T1547] * '''Last Updated''': 2021-07-01
@@ -45284,6 +47824,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1547.012 | Print Processors | Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation |} @@ -45404,7 +47948,7 @@ This search is to detect a modification or registry add to the safeboot registry * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/001/ T1547.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/001/ T1547.001], [https://attack.mitre.org/techniques/T1547/ T1547] * '''Last Updated''': 2021-06-10
@@ -45449,6 +47993,10 @@ To successfully implement this search, you must be ingesting data that records r | T1547.001 | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation |} @@ -45549,6 +48097,103 @@ unknown ====Test Dataset==== +''version'': 1 +
+
+ +---- + +===Suspicious copy on system32=== +This analytic is to detect a suspicious copy of file from systemroot folder of the windows OS. This technique is commonly used by APT or other malware as part of execution (LOLBIN) to run its malicious code using the available legitimate tool in OS. this type of event may seen or may execute of normal user in some instance but this is really a anomaly that needs to be check within the network. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/003/ T1036.003], [https://attack.mitre.org/techniques/T1036/ T1036] +* '''Last Updated''': 2021-10-05 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN("cmd.exe", "powershell*","pwsh.exe", "sqlps.exe", "sqltoolsps.exe", "powershell_ise.exe") AND `process_copy` AND Processes.process IN("*\\Windows\\System32\*", "*\\Windows\\SysWow64\\*") AND Processes.process = "*copy*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_copy_on_system32_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +====Required field==== + +* _time + +* Processes.dest + +* Processes.user + +* Processes.parent_process_name + +* Processes.parent_process + +* Processes.original_file_name + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_path + +* Processes.process_path + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1036.003 +| Rename System Utilities +| Defense Evasion +|- +| T1036 +| Masquerading +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +every user may do this event but very un-ussual. + +====Reference==== + + +* https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120 + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/copy_sysmon/sysmon.log + + ''version'': 1
@@ -45743,7 +48388,7 @@ This analytic will detect suspicious driver loaded paths. This technique is comm * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/003/ T1543.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/003/ T1543.003], [https://attack.mitre.org/techniques/T1543/ T1543] * '''Last Updated''': 2021-04-29
@@ -45791,6 +48436,10 @@ To successfully implement this search, you need to be ingesting logs with the dr | T1543.003 | Windows Service | Persistence, Privilege Escalation +|- +| T1543 +| Create or Modify System Process +| Persistence, Privilege Escalation |} @@ -45827,7 +48476,7 @@ The following analytic utilizes Windows Event ID 1100 to identify when Windows e * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/001/ T1070.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/001/ T1070.001] * '''Last Updated''': 2021-06-17
@@ -45868,6 +48517,10 @@ To successfully implement this search, you need to be ingesting Windows event lo ! Technique ! Tactic |- +| T1070 +| Indicator Removal on Host +| Defense Evasion +|- | T1070.001 | Clear Windows Event Logs | Defense Evasion @@ -46007,7 +48660,7 @@ this search is to detect a suspicious regsvr32 commandline "-s" to execu * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/010/ T1218.010] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/010/ T1218.010] * '''Last Updated''': 2021-07-27
@@ -46063,6 +48716,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.010 | Regsvr32 | Defense Evasion @@ -46100,7 +48757,7 @@ This search is to detect a suspicious rundll32.exe commandline to execute dll fi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-07-26
@@ -46156,6 +48813,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -46282,7 +48943,7 @@ The following analytic identifies renamed instances of msbuild.exe executing. Ms * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1127/001/ T1127.001], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1036/003/ T1036.003], [https://attack.mitre.org/techniques/T1127/001/ T1127.001] * '''Last Updated''': 2021-01-12
@@ -46342,13 +49003,21 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- -| T1127.001 -| MSBuild +| T1036 +| Masquerading +| Defense Evasion +|- +| T1127 +| Trusted Developer Utilities Proxy Execution | Defense Evasion |- | T1036.003 | Rename System Utilities | Defense Evasion +|- +| T1127.001 +| MSBuild +| Defense Evasion |} @@ -46387,7 +49056,7 @@ The following analytic identifies wmiprvse.exe spawning msbuild.exe. This behavi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1127/001/ T1127.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1127/001/ T1127.001] * '''Last Updated''': 2021-01-12
@@ -46443,6 +49112,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1127 +| Trusted Developer Utilities Proxy Execution +| Defense Evasion +|- | T1127.001 | MSBuild | Defense Evasion @@ -46489,7 +49162,7 @@ Upon triage, capture the property list file being written to disk and review for * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/001/ T1543.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/001/ T1543.001], [https://attack.mitre.org/techniques/T1543/ T1543] * '''Last Updated''': 2021-02-22
@@ -46540,6 +49213,10 @@ To successfully implement this search you need to be ingesting information on pr | T1543.001 | Launch Agent | Persistence, Privilege Escalation +|- +| T1543 +| Create or Modify System Process +| Persistence, Privilege Escalation |} @@ -46581,7 +49258,7 @@ Upon triage, capture the property list file being written to disk and review for * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/001/ T1543.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/001/ T1543.001], [https://attack.mitre.org/techniques/T1543/ T1543] * '''Last Updated''': 2021-02-22
@@ -46616,6 +49293,10 @@ OSQuery must be installed and configured to pick up process events (info at http | T1543.001 | Launch Agent | Persistence, Privilege Escalation +|- +| T1543 +| Create or Modify System Process +| Persistence, Privilege Escalation |} @@ -46834,7 +49515,7 @@ Adversaries may abuse Regsvr32.exe to proxy execution of malicious code by using * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/010/ T1218.010] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/010/ T1218.010] * '''Last Updated''': 2021-01-28
@@ -46892,6 +49573,10 @@ You must be ingesting endpoint data that tracks process activity, including pare ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.010 | Regsvr32 | Defense Evasion @@ -46937,7 +49622,7 @@ This search is to detect a suspicious rundll32.exe process with plugininit param * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-07-26
@@ -46993,6 +49678,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -47030,7 +49719,7 @@ The following analytic identifies renamed instances of rundll32.exe executing. r * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1218/011/ T1218.011], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] * '''Last Updated''': 2021-02-04
@@ -47088,6 +49777,14 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- +| T1036 +| Masquerading +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -47133,7 +49830,7 @@ The following analytic identifies rundll32.exe executing a DLL function name, St * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-02-04
@@ -47193,6 +49890,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -47238,7 +49939,7 @@ The following analytic identifies rundll32.exe using dllregisterserver on the co * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-02-09
@@ -47294,6 +49995,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -47343,7 +50048,7 @@ The following analytic identifies rundll32.exe with no command line arguments. I * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/011/ T1218.011] * '''Last Updated''': 2021-09-20
@@ -47404,6 +50109,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion @@ -47532,7 +50241,7 @@ The following detection identifies Scheduled Tasks registering (creating a new t * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] * '''Last Updated''': 2021-03-01
@@ -47589,6 +50298,10 @@ To successfully implement this search you need to be ingesting information on pr | T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation +|- +| T1053 +| Scheduled Task/Job +| Execution, Persistence, Privilege Escalation |} @@ -47808,7 +50521,7 @@ The following analytic identifies a renamed instance of microsoft.workflow.compi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] * '''Last Updated''': 2021-09-20
@@ -47868,6 +50581,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1036 +| Masquerading +| Defense Evasion +|- | T1127 | Trusted Developer Utilities Proxy Execution | Defense Evasion @@ -48006,7 +50723,7 @@ The following analytic identifies msbuild.exe executing from a non-standard path * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1127/001/ T1127.001], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1036/003/ T1036.003], [https://attack.mitre.org/techniques/T1127/001/ T1127.001] * '''Last Updated''': 2021-01-12
@@ -48066,13 +50783,21 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- -| T1127.001 -| MSBuild +| T1036 +| Masquerading +| Defense Evasion +|- +| T1127 +| Trusted Developer Utilities Proxy Execution | Defense Evasion |- | T1036.003 | Rename System Utilities | Defense Evasion +|- +| T1127.001 +| MSBuild +| Defense Evasion |} @@ -48109,7 +50834,7 @@ The following analytic identifies child processes spawning from "mshta.exe& * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/005/ T1218.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] * '''Last Updated''': 2021-01-12
@@ -48155,6 +50880,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.005 | Mshta | Defense Evasion @@ -48194,7 +50923,7 @@ The following analytic identifies wmiprvse.exe spawning mshta.exe. This behavior * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/005/ T1218.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/005/ T1218.005] * '''Last Updated''': 2021-01-20
@@ -48250,6 +50979,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.005 | Mshta | Defense Evasion @@ -48287,19 +51020,19 @@ Although unlikely, some legitimate applications may exhibit this behavior, trigg ---- ===Suspicious wevtutil usage=== -The wevtutil.exe application is the windows event log utility. This searches for wevtutil.exe with parameters for clearing the application, security, setup, or system event logs. +The wevtutil.exe application is the windows event log utility. This searches for wevtutil.exe with parameters for clearing the application, security, setup, trace or system event logs. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/001/ T1070.001] -* '''Last Updated''': 2020-07-22 +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/001/ T1070.001], [https://attack.mitre.org/techniques/T1070/ T1070] +* '''Last Updated''': 2021-10-11
====Search==== -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = wevtutil.exe Processes.process="*cl*" (Processes.process="*System*" OR Processes.process="*Security*" OR Processes.process="*Setup*" OR Processes.process="*Application*") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wevtutil.exe Processes.process IN ("* cl *", "*clear-log*") (Processes.process="*System*" OR Processes.process="*Security*" OR Processes.process="*Setup*" OR Processes.process="*Application*" OR Processes.process="*trace*") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` @@ -48342,6 +51075,10 @@ You must be ingesting data that records process activity from your hosts to popu | T1070.001 | Clear Windows Event Logs | Defense Evasion +|- +| T1070 +| Indicator Removal on Host +| Defense Evasion |} @@ -48356,12 +51093,16 @@ The wevtutil.exe application is a legitimate Windows event log utility. Administ ====Reference==== +* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md + + + ====Test Dataset==== * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-sysmon.log -''version'': 3 +''version'': 4
@@ -48643,7 +51384,7 @@ During triage, review the parallel processes - what process moved the native Win * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/003/ T1036.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1036/003/ T1036.003] * '''Last Updated''': 2020-12-08
@@ -48698,6 +51439,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1036 +| Masquerading +| Defense Evasion +|- | T1036.003 | Rename System Utilities | Defense Evasion @@ -48912,6 +51657,95 @@ Administrators or power users may use this command for troubleshooting. * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Time provider persistence registry=== +This analytic is to detect a suspiciouos modification of time provider registry for persistence and autostart. This technique can allow the attacker to persist on the compromised host and autostart as soon as the machine boot up. This TTP can be a good indicator of suspicious behavior since this registry is not commonly modified by normal user or even an admin. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1547/003/ T1547.003], [https://attack.mitre.org/techniques/T1547/ T1547] +* '''Last Updated''': 2021-09-29 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path ="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `time_provider_persistence_registry_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + +* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] + + +====How To Implement==== +To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. + +====Required field==== + +* _time + +* Registry.dest + +* Registry.user + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.registry_value_name + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1547.003 +| Time Providers +| Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +unknown + +====Reference==== + + +* https://pentestlab.blog/2019/10/22/persistence-time-providers/ + +* https://attack.mitre.org/techniques/T1547/003/ + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.003/timeprovider_reg/sysmon.log + + ''version'': 1
@@ -49009,7 +51843,7 @@ This search is to detect a suspicious loaded unsigned dll by MMC.exe application * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2021-07-12
@@ -49061,6 +51895,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1548.002 | Bypass User Account Control | Privilege Escalation, Defense Evasion +|- +| T1548 +| Abuse Elevation Control Mechanism +| Privilege Escalation, Defense Evasion |} @@ -49095,7 +51933,7 @@ This search is to detect a possible uac bypass using the colorui.dll COM Object. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/003/ T1218.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/003/ T1218.003] * '''Last Updated''': 2021-08-13
@@ -49142,6 +51980,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.003 | CMSTP | Defense Evasion @@ -49350,7 +52192,7 @@ This search is to detect a suspicious un-installation of application using msiex * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/007/ T1218.007] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/007/ T1218.007], [https://attack.mitre.org/techniques/T1218/ T1218] * '''Last Updated''': 2021-08-09
@@ -49403,6 +52245,10 @@ To successfully implement this search, you need to be ingesting logs with the pr | T1218.007 | Msiexec | Defense Evasion +|- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion |} @@ -49437,7 +52283,7 @@ Attackers often disable security tools to avoid detection. This search looks for * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2020-07-22
@@ -49487,6 +52333,10 @@ You must be ingesting data that records process activity from your hosts to popu | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -49987,6 +52837,204 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/AD_discovery/windows-powershell.log +''version'': 1 +
+
+ +---- + +===Vbscript execution using wscript app=== +This analytic is to detect a suspicious wscript commandline to execute vbscript. This technique was seen in several malware to execute malicious vbs file using wscript application. commonly vbs script is associated to cscript process and this can be a technique to evade process parent child detections or even some av script emulation system. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/005/ T1059.005], [https://attack.mitre.org/techniques/T1059/ T1059] +* '''Last Updated''': 2021-10-01 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name = "wscript.exe" AND Processes.parent_process = "*//e:vbscript*") OR (Processes.process_name = "wscript.exe" AND Processes.process = "*//e:vbscript*") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `vbscript_execution_using_wscript_app_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] + +* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +====Required field==== + +* _time + +* Processes.dest + +* Processes.user + +* Processes.parent_process_name + +* Processes.parent_process + +* Processes.original_file_name + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_path + +* Processes.process_path + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1059.005 +| Visual Basic +| Execution +|- +| T1059 +| Command and Scripting Interpreter +| Execution +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +unknown + +====Reference==== + + +* https://www.joesandbox.com/analysis/369332/0/html + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log + + +''version'': 1 +
+
+ +---- + +===Verclsid clsid execution=== +This analytic is to detect a possible abuse of verclsid to execute malicious file through generate CLSID. This process is a normal application of windows to verify the CLSID COM object before it is instantiated by Windows Explorer. This hunting query can be a good pivot point to analyze what is he CLSID or COM object pointing too to check if it is a valid application or not. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/012/ T1218.012], [https://attack.mitre.org/techniques/T1218/ T1218] +* '''Last Updated''': 2021-09-29 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_verclsid` AND Processes.process="*/S*" Processes.process="*/C*" AND Processes.process="*{*" AND Processes.process="*}*" by Processes.process_name Processes.original_file_name Processes.dest Processes.user Processes.parent_process_name Processes.parent_process +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `verclsid_clsid_execution_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +====Required field==== + +* _time + +* Processes.dest + +* Processes.user + +* Processes.parent_process_name + +* Processes.parent_process + +* Processes.original_file_name + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_path + +* Processes.process_path + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1218.012 +| Verclsid +| Defense Evasion +|- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +windows can used this application for its normal COM object validation. + +====Reference==== + + +* https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5 + +* https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/ + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.012/verclsid_exec/sysmon.log + + ''version'': 1
@@ -49998,7 +53046,7 @@ This query identifies a shell, PowerShell.exe or Cmd.exe, spawning from W3WP.exe * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1505/003/ T1505.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1505/ T1505], [https://attack.mitre.org/techniques/T1505/003/ T1505.003] * '''Last Updated''': 2021-03-03
@@ -50056,6 +53104,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1505 +| Server Software Component +| Persistence +|- | T1505.003 | Web Shell | Persistence @@ -50269,7 +53321,7 @@ Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToCons * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/003/ T1546.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1546/003/ T1546.003], [https://attack.mitre.org/techniques/T1546/ T1546] * '''Last Updated''': 2020-12-08
@@ -50320,6 +53372,10 @@ To successfully implement this search, you must be collecting Sysmon data using | T1546.003 | Windows Management Instrumentation Event Subscription | Privilege Escalation, Persistence +|- +| T1546 +| Event Triggered Execution +| Privilege Escalation, Persistence |} @@ -50517,7 +53573,7 @@ This search is to detect a suspicious modification of registry related to UAC by * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548/002/ T1548.002], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2021-07-01
@@ -50562,6 +53618,10 @@ To successfully implement this search you need to be ingesting information on pr | T1548.002 | Bypass User Account Control | Privilege Escalation, Defense Evasion +|- +| T1548 +| Abuse Elevation Control Mechanism +| Privilege Escalation, Defense Evasion |} @@ -50598,7 +53658,7 @@ this search is designed to detect potential malicious process loading COM object * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/003/ T1218.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218/ T1218], [https://attack.mitre.org/techniques/T1218/003/ T1218.003] * '''Last Updated''': 2021-06-02
@@ -50651,6 +53711,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1218 +| Signed Binary Proxy Execution +| Defense Evasion +|- | T1218.003 | CMSTP | Defense Evasion @@ -50690,7 +53754,7 @@ this search is designed to detect suspicious wermgr.exe process that tries to co * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1590/005/ T1590.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1590/ T1590], [https://attack.mitre.org/techniques/T1590/005/ T1590.005] * '''Last Updated''': 2021-04-19
@@ -50739,6 +53803,10 @@ To successfully implement this search, you need to be ingesting logs with the pr ! Technique ! Tactic |- +| T1590 +| Gather Victim Network Information +| Reconnaissance +|- | T1590.005 | IP Addresses | Reconnaissance @@ -50957,7 +54025,7 @@ The wevtutil.exe application is the windows event log utility. This searches for * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/001/ T1070.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/001/ T1070.001] * '''Last Updated''': 2021-06-15
@@ -51007,6 +54075,10 @@ You must be ingesting data that records process activity from your hosts to popu ! Technique ! Tactic |- +| T1070 +| Indicator Removal on Host +| Defense Evasion +|- | T1070.001 | Clear Windows Event Logs | Defense Evasion @@ -51044,7 +54116,7 @@ This search is to detect execution of wevtutil.exe to disable logs. This techniq * '''Product''': Splunk Behavioral Analytics * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/001/ T1070.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/001/ T1070.001] * '''Last Updated''': 2021-06-15
@@ -51092,6 +54164,10 @@ You must be ingesting data that records process activity from your hosts to popu ! Technique ! Tactic |- +| T1070 +| Indicator Removal on Host +| Defense Evasion +|- | T1070.001 | Clear Windows Event Logs | Defense Evasion @@ -51133,7 +54209,7 @@ Upon triage, identify the task scheduled source. Was it schtasks.exe or was it v * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] * '''Last Updated''': 2021-04-08
@@ -51185,6 +54261,10 @@ To successfully implement this search, you need to be ingesting Windows Security | T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation +|- +| T1053 +| Scheduled Task/Job +| Execution, Persistence, Privilege Escalation |} @@ -51231,7 +54311,7 @@ Upon triage, identify the task scheduled source. Was it schtasks.exe or via Task * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/005/ T1053.005], [https://attack.mitre.org/techniques/T1053/ T1053] * '''Last Updated''': 2021-04-12
@@ -51281,6 +54361,10 @@ To successfully implement this search, you need to be ingesting Windows Security | T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation +|- +| T1053 +| Scheduled Task/Job +| Execution, Persistence, Privilege Escalation |} @@ -51501,7 +54585,7 @@ The search looks for the Registry Key DisableAntiSpyware set to disable. This is * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562/001/ T1562.001], [https://attack.mitre.org/techniques/T1562/ T1562] * '''Last Updated''': 2021-03-02
@@ -51550,6 +54634,10 @@ To successfully implement this search you need to be ingesting information on pr | T1562.001 | Disable or Modify Tools | Defense Evasion +|- +| T1562 +| Impair Defenses +| Defense Evasion |} @@ -51584,7 +54672,7 @@ The following analytic utilizes Windows Security Event ID 1102 or System log eve * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/001/ T1070.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070/001/ T1070.001] * '''Last Updated''': 2020-07-06
@@ -51625,6 +54713,10 @@ To successfully implement this search, you need to be ingesting Windows event lo ! Technique ! Tactic |- +| T1070 +| Indicator Removal on Host +| Defense Evasion +|- | T1070.001 | Clear Windows Event Logs | Defense Evasion @@ -51734,6 +54826,103 @@ SAM is a critical windows service, stopping it would cause major issues on an en * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Winhlp32 spawning a process=== +The following analytic identifies winhlp32.exe, found natively in `c:\windows\`, spawning a child process that loads a file out of appdata, programdata, or temp. Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the ".hlp" file name extension. This particular instance is related to a Remcos sample where dynwrapx.dll is added to the registry under inprocserver32, and later module loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk. During triage, review parallel processes to identify further suspicious behavior. Review module loads for unsuspecting unsigned modules. Capture any file modifications and analyze. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] +* '''Last Updated''': 2021-10-05 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `winhlp32_spawning_a_process_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + +====Required field==== + +* _time + +* Processes.dest + +* Processes.user + +* Processes.parent_process_name + +* Processes.parent_process + +* Processes.original_file_name + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_path + +* Processes.process_path + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +False positives should be limited as winhlp32.exe is typically not used with the latest flavors of Windows OS. However, filter as needed. + +====Reference==== + + +* https://www.exploit-db.com/exploits/16541 + +* https://tria.ge/210929-ap75vsddan + +* https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + + ''version'': 1
@@ -51745,7 +54934,7 @@ The following detection identifies Microsoft Word spawning `cmd.exe`. Typically, * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-04-22
@@ -51801,6 +54990,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -51838,7 +55031,7 @@ The following detection identifies Microsoft Word spawning PowerShell. Typically * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-04-12
@@ -51894,6 +55087,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -51937,7 +55134,7 @@ The following detection identifies Microsoft Winword.exe spawning Windows Script * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/001/ T1566.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566], [https://attack.mitre.org/techniques/T1566/001/ T1566.001] * '''Last Updated''': 2021-04-12
@@ -51983,6 +55180,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1566 +| Phishing +| Initial Access +|- | T1566.001 | Spearphishing Attachment | Initial Access @@ -52022,7 +55223,7 @@ During triage, review parallel processes and identify any further suspicious beh * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/001/ T1069.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1069/ T1069], [https://attack.mitre.org/techniques/T1069/001/ T1069.001] * '''Last Updated''': 2021-09-14
@@ -52078,6 +55279,10 @@ To successfully implement this search you need to be ingesting information on pr ! Technique ! Tactic |- +| T1069 +| Permission Groups Discovery +| Discovery +|- | T1069.001 | Local Groups | Discovery @@ -52117,7 +55322,7 @@ This search is to detect suspicious dropping or creating an executable file in k * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/002/ T1021.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1021/002/ T1021.002] * '''Last Updated''': 2021-04-23
@@ -52166,6 +55371,10 @@ To successfully implement this search, you need to be ingesting Windows Security ! Technique ! Tactic |- +| T1021 +| Remote Services +| Lateral Movement +|- | T1021.002 | SMB/Windows Admin Shares | Lateral Movement @@ -52194,6 +55403,115 @@ unknown * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/trickbot/exe_smbshare/windows-security.log +''version'': 1 +
+
+ +---- + +===Wscript or cscript suspicious child process=== +This analytic is to detect a suspicious spawned process by wscript or cscript process. This technique was a common technique used by adversaries and malware to execute different LOLBIN, other script like powershell or create a suspended process to inject its code as a defense evasion. This TTP may detect some normal script that using several application tool that are in the list of the child process it detects but a good pivot and indicator that a script is may execute suspicious code. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1134/004/ T1134.004], [https://attack.mitre.org/techniques/T1134/ T1134] +* '''Last Updated''': 2021-10-06 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("cscript.exe", "wscript.exe") Processes.process_name IN ("regsvr32.exe", "rundll32.exe","winhlp32.exe","certutil.exe","msbuild.exe","cmd.exe","powershell*","wmic.exe","mshta.exe") by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `wscript_or_cscript_suspicious_child_process_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#FIN7|FIN7]] + +* [[Documentation:ESSOC:stories:UseCase#Remcos|Remcos]] + +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +====Required field==== + +* _time + +* Processes.dest + +* Processes.user + +* Processes.parent_process_name + +* Processes.parent_process + +* Processes.original_file_name + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_path + +* Processes.process_path + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|- +| T1543 +| Create or Modify System Process +| Persistence, Privilege Escalation +|- +| T1134.004 +| Parent PID Spoofing +| Defense Evasion, Privilege Escalation +|- +| T1134 +| Access Token Manipulation +| Defense Evasion, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +user may create vbs or js script that use several tool as part of its execution. + +====Reference==== + + +* https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120 + + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log + + ''version'': 1
@@ -52205,7 +55523,7 @@ This analytic identifies XMRIG coinminer driver installation on the system. The * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/003/ T1543.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/003/ T1543.003], [https://attack.mitre.org/techniques/T1543/ T1543] * '''Last Updated''': 2021-04-29
@@ -52253,6 +55571,10 @@ To successfully implement this search, you need to be ingesting logs with the dr | T1543.003 | Windows Service | Persistence, Privilege Escalation +|- +| T1543 +| Create or Modify System Process +| Persistence, Privilege Escalation |} @@ -52379,7 +55701,7 @@ This search allows you to identify DNS requests that are unusually large for the * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Resolution -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/004/ T1071.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/004/ T1071.004], [https://attack.mitre.org/techniques/T1071/ T1071] * '''Last Updated''': 2020-01-22
@@ -52441,6 +55763,10 @@ Detailed documentation on how to create a new field within Incident Review may b | T1071.004 | DNS | Command And Control +|- +| T1071 +| Application Layer Protocol +| Command And Control |} @@ -52469,7 +55795,7 @@ This search allows you to identify DNS requests and compute the standard deviati * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Resolution -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048] * '''Last Updated''': 2021-10-06
@@ -52519,6 +55845,10 @@ To successfully implement this search, you will need to ensure that DNS data is | T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration +|- +| T1048 +| Exfiltration Over Alternative Protocol +| Exfiltration |} @@ -52549,7 +55879,7 @@ By enabling Dynamic ARP Inspection as a Layer 2 Security measure on the organiza * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557/002/ T1557.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557/ T1557], [https://attack.mitre.org/techniques/T1557/002/ T1557.002] * '''Last Updated''': 2020-08-11
@@ -52605,6 +55935,10 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne | Network Denial of Service | Impact |- +| T1557 +| Man-in-the-Middle +| Credential Access, Collection +|- | T1557.002 | ARP Cache Poisoning | Credential Access, Collection @@ -52640,7 +55974,7 @@ By enabling IPv6 First Hop Security as a Layer 2 Security measure on the organiz * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557/002/ T1557.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557/ T1557], [https://attack.mitre.org/techniques/T1557/002/ T1557.002] * '''Last Updated''': 2020-10-28
@@ -52704,6 +56038,10 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne | Network Denial of Service | Impact |- +| T1557 +| Man-in-the-Middle +| Credential Access, Collection +|- | T1557.002 | ARP Cache Poisoning | Credential Access, Collection @@ -52837,7 +56175,7 @@ This search looks for outbound SMB connections made by hosts within your network * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/002/ T1071.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/002/ T1071.002], [https://attack.mitre.org/techniques/T1071/ T1071] * '''Last Updated''': 2020-07-21
@@ -52892,6 +56230,10 @@ In order to run this search effectively, we highly recommend that you leverage t | T1071.002 | File Transfer Protocols | Command And Control +|- +| T1071 +| Application Layer Protocol +| Command And Control |} @@ -52922,7 +56264,7 @@ By enabling Port Security on a Cisco switch you can restrict input to an interfa * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557/002/ T1557.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557/ T1557], [https://attack.mitre.org/techniques/T1557/002/ T1557.002] * '''Last Updated''': 2020-10-28
@@ -52984,6 +56326,10 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne | Network Denial of Service | Impact |- +| T1557 +| Man-in-the-Middle +| Credential Access, Collection +|- | T1557.002 | ARP Cache Poisoning | Credential Access, Collection @@ -53196,7 +56542,7 @@ Adversaries may abuse netbooting to load an unauthorized network device operatin * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1542/005/ T1542.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1542/005/ T1542.005], [https://attack.mitre.org/techniques/T1542/ T1542] * '''Last Updated''': 2020-10-28
@@ -53245,6 +56591,10 @@ This search looks for Network Traffic events to TFTP, FTP or SSH/SCP ports from | T1542.005 | TFTP Boot | Defense Evasion, Persistence +|- +| T1542 +| Pre-OS Boot +| Defense Evasion, Persistence |} @@ -53273,7 +56623,7 @@ Adversaries may leverage traffic mirroring in order to automate data exfiltratio * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1020/001/ T1020.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1020/ T1020], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1020/001/ T1020.001] * '''Last Updated''': 2020-10-28
@@ -53316,6 +56666,10 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne | Hardware Additions | Initial Access |- +| T1020 +| Automated Exfiltration +| Exfiltration +|- | T1498 | Network Denial of Service | Impact @@ -53740,7 +57094,7 @@ This search identifies DNS query failures by counting the number of DNS response * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Resolution -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/004/ T1071.004] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/004/ T1071.004], [https://attack.mitre.org/techniques/T1071/ T1071] * '''Last Updated''': 2020-07-21
@@ -53790,6 +57144,10 @@ To successfully implement this search you must ensure that DNS data is populatin | T1071.004 | DNS | Command And Control +|- +| T1071 +| Application Layer Protocol +| Command And Control |} @@ -53818,7 +57176,7 @@ This search looks for an increase of data transfers from your email server to yo * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/002/ T1114.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/002/ T1114.002], [https://attack.mitre.org/techniques/T1114/ T1114] * '''Last Updated''': 2020-07-21
@@ -53865,6 +57223,10 @@ This search requires you to be ingesting your network traffic and populating the | T1114.002 | Remote Email Collection | Collection +|- +| T1114 +| Email Collection +| Collection |} @@ -53893,7 +57255,7 @@ The search is used to identify attempts to use your DNS Infrastructure for DDoS * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Resolution -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1498/002/ T1498.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1498/002/ T1498.002] * '''Last Updated''': 2017-09-20
@@ -53932,6 +57294,10 @@ To successfully implement this search you must ensure that DNS data is populatin ! Technique ! Tactic |- +| T1498 +| Network Denial of Service +| Impact +|- | T1498.002 | Reflection Amplification | Impact @@ -53963,7 +57329,7 @@ This search is designed to detect high frequency of archive files data exfiltrat * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048] * '''Last Updated''': 2021-04-21
@@ -54022,6 +57388,10 @@ To successfully implement this search, you need to be ingesting logs with the st | T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration +|- +| T1048 +| Exfiltration Over Alternative Protocol +| Exfiltration |} @@ -54060,7 +57430,7 @@ This search is to detect potential plain HTTP POST method data exfiltration. Thi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048] * '''Last Updated''': 2021-04-22
@@ -54110,6 +57480,10 @@ To successfully implement this search, you need to be ingesting logs with the st | T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration +|- +| T1048 +| Exfiltration Over Alternative Protocol +| Exfiltration |} @@ -54225,7 +57599,7 @@ This search looks for network traffic on common ports where a higher layer proto * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1048/003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048] * '''Last Updated''': 2020-07-21
@@ -54272,6 +57646,10 @@ Running this search properly requires a technology that can inspect network traf | T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration +|- +| T1048 +| Exfiltration Over Alternative Protocol +| Exfiltration |} @@ -54374,7 +57752,7 @@ This search looks for RDP application network traffic and filters any source/des * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001], [https://attack.mitre.org/techniques/T1021/ T1021] * '''Last Updated''': 2020-07-21
@@ -54422,6 +57800,10 @@ You must ensure that your network traffic data is populating the Network_Traffic | T1021.001 | Remote Desktop Protocol | Lateral Movement +|- +| T1021 +| Remote Services +| Lateral Movement |} @@ -54452,7 +57834,7 @@ This search looks for network traffic on TCP/3389, the default port used by remo * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/001/ T1021.001], [https://attack.mitre.org/techniques/T1021/ T1021] * '''Last Updated''': 2020-07-07
@@ -54507,6 +57889,10 @@ To successfully implement this search you need to identify systems that commonly | T1021.001 | Remote Desktop Protocol | Lateral Movement +|- +| T1021 +| Remote Services +| Lateral Movement |} @@ -54535,7 +57921,7 @@ This search looks for spikes in the number of Server Message Block (SMB) traffic * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/002/ T1021.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/002/ T1021.002], [https://attack.mitre.org/techniques/T1021/ T1021] * '''Last Updated''': 2020-07-22
@@ -54587,6 +57973,10 @@ This search requires you to be ingesting your network traffic logs and populatin | T1021.002 | SMB/Windows Admin Shares | Lateral Movement +|- +| T1021 +| Remote Services +| Lateral Movement |} @@ -54615,7 +58005,7 @@ This search uses the Machine Learning Toolkit (MLTK) to identify spikes in the n * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/002/ T1021.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/002/ T1021.002], [https://attack.mitre.org/techniques/T1021/ T1021] * '''Last Updated''': 2020-07-22
@@ -54674,6 +58064,10 @@ Detailed documentation on how to create a new field within Incident Review is fo | T1021.002 | SMB/Windows Admin Shares | Lateral Movement +|- +| T1021 +| Remote Services +| Lateral Movement |} @@ -54702,7 +58096,7 @@ This search looks for network traffic identified as The Onion Router (TOR), a be * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/001/ T1071.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071/ T1071], [https://attack.mitre.org/techniques/T1071/001/ T1071.001] * '''Last Updated''': 2020-07-22
@@ -54752,6 +58146,10 @@ In order to properly run this search, Splunk needs to ingest data from firewalls ! Technique ! Tactic |- +| T1071 +| Application Layer Protocol +| Command And Control +|- | T1071.001 | Web Protocols | Command And Control @@ -55283,7 +58681,7 @@ There might be false positives associted with this detection since items like ar
 #############
 # Automatically generated by doc_gen.py in https://github.com/splunk/security_content''
-# On Date: 2021-10-14 15:40:37.024104 UTC''
+# On Date: 2021-10-22 23:24:27.824491 UTC''
 # Author: Splunk Security Research''
 # Contact: research@splunk.com''
 #############
diff --git a/docs/index.markdown b/docs/index.markdown
index 2a7fc944a3..a15fd25865 100644
--- a/docs/index.markdown
+++ b/docs/index.markdown
@@ -9,12 +9,12 @@ header:
   actions:
     - label: "Download"
       url: "https://splunkbase.splunk.com/app/3449/"
-excerpt: "Get the latest **FREE** Enterprise Security Content Update (ESCU) App with **637** detections for Splunk."
+excerpt: "Get the latest **FREE** Enterprise Security Content Update (ESCU) App with **658** detections for Splunk."
 feature_row:
   - image_path: /static/feature_detection.png
     alt: "customizable"
     title: "Detections"
-    excerpt: "See all **637** Splunk Analytics built to find evil 😈."
+    excerpt: "See all **658** Splunk Analytics built to find evil 😈."
     url: "/detections"
     btn_class: "btn--primary"
     btn_label: "Explore"
diff --git a/docs/stories.wiki b/docs/stories.wiki
index aba2d27089..08ec64a545 100644
--- a/docs/stories.wiki
+++ b/docs/stories.wiki
@@ -84,10 +84,13 @@ DNS poses a serious threat as a Denial of Service (DOS) amplifier, if it respond
 | [[Documentation:ESSOC:detections:Detections#Large_volume_of_dns_any_queries|Large Volume of DNS ANY Queries]]
 
 |
+[https://attack.mitre.org/techniques/T1498/ T1498], 
 [https://attack.mitre.org/techniques/T1498.002/ T1498.002]
 |
+Network Denial of Service, 
 Reflection Amplification
 |
+Impact, 
 Impact
 
 | Anomaly
@@ -186,10 +189,13 @@ Detect activities and various techniques associated with the abuse of `netsh.exe
 | [[Documentation:ESSOC:detections:Detections#Processes_launching_netsh|Processes launching netsh]]
 
 |
-[https://attack.mitre.org/techniques/T1562.004/ T1562.004]
+[https://attack.mitre.org/techniques/T1562.004/ T1562.004], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify System Firewall
+Disable or Modify System Firewall, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -242,10 +248,13 @@ Monitor for activities and techniques associated with Discovery and Reconnaissan
 | [[Documentation:ESSOC:detections:Detections#Adsisearcher_account_discovery|AdsiSearcher Account Discovery]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -264,10 +273,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Domain_account_discovery_with_net_app|Domain Account Discovery With Net App]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -275,10 +287,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Domain_account_discovery_with_dsquery|Domain Account Discovery with Dsquery]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -286,10 +301,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Domain_account_discovery_with_wmic|Domain Account Discovery with Wmic]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -319,10 +337,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Domain_group_discovery_with_dsquery|Domain Group Discovery With Dsquery]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -330,10 +351,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Domain_group_discovery_with_net|Domain Group Discovery With Net]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -341,10 +365,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Domain_group_discovery_with_wmic|Domain Group Discovery With Wmic]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -352,10 +379,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Domain_group_discovery_with_adsisearcher|Domain Group Discovery with Adsisearcher]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -363,10 +393,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Elevated_group_discovery_with_net|Elevated Group Discovery With Net]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -374,10 +407,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Elevated_group_discovery_with_wmic|Elevated Group Discovery With Wmic]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -385,10 +421,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Elevated_group_discovery_with_powerview|Elevated Group Discovery with PowerView]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -418,10 +457,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Get_aduser_with_powershell|Get ADUser with PowerShell]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -429,10 +471,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Get_aduser_with_powershell_script_block|Get ADUser with PowerShell Script Block]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -484,10 +529,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Get_domainuser_with_powershell|Get DomainUser with PowerShell]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -495,10 +543,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Get_domainuser_with_powershell_script_block|Get DomainUser with PowerShell Script Block]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -506,10 +557,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Get_wmiobject_group_discovery|Get WMIObject Group Discovery]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.001/ T1069.001]
 |
+Permission Groups Discovery, 
 Local Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -517,10 +571,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Get_wmiobject_group_discovery_with_script_block_logging|Get WMIObject Group Discovery with Script Block Logging]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.001/ T1069.001]
 |
+Permission Groups Discovery, 
 Local Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -594,10 +651,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getadgroup_with_powershell|GetAdGroup with PowerShell]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -605,10 +665,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getadgroup_with_powershell_script_block|GetAdGroup with PowerShell Script Block]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -682,10 +745,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getdomaingroup_with_powershell|GetDomainGroup with PowerShell]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -693,10 +759,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getdomaingroup_with_powershell_script_block|GetDomainGroup with PowerShell Script Block]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -704,10 +773,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getlocaluser_with_powershell|GetLocalUser with PowerShell]]
 
 |
+[https://attack.mitre.org/techniques/T1087/ T1087], 
 [https://attack.mitre.org/techniques/T1087.001/ T1087.001]
 |
+Account Discovery, 
 Local Account
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -715,10 +787,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getlocaluser_with_powershell_script_block|GetLocalUser with PowerShell Script Block]]
 
 |
+[https://attack.mitre.org/techniques/T1087/ T1087], 
 [https://attack.mitre.org/techniques/T1087.001/ T1087.001]
 |
+Account Discovery, 
 Local Account
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -748,10 +823,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getwmiobject_ds_user_with_powershell|GetWmiObject DS User with PowerShell]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -759,10 +837,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getwmiobject_ds_user_with_powershell_script_block|GetWmiObject DS User with PowerShell Script Block]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -792,10 +873,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getwmiobject_ds_group_with_powershell|GetWmiObject Ds Group with PowerShell]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -803,10 +887,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getwmiobject_ds_group_with_powershell_script_block|GetWmiObject Ds Group with PowerShell Script Block]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002]
 |
+Permission Groups Discovery, 
 Domain Groups
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -814,10 +901,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getwmiobject_user_account_with_powershell|GetWmiObject User Account with PowerShell]]
 
 |
+[https://attack.mitre.org/techniques/T1087/ T1087], 
 [https://attack.mitre.org/techniques/T1087.001/ T1087.001]
 |
+Account Discovery, 
 Local Account
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -825,10 +915,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Getwmiobject_user_account_with_powershell_script_block|GetWmiObject User Account with PowerShell Script Block]]
 
 |
+[https://attack.mitre.org/techniques/T1087/ T1087], 
 [https://attack.mitre.org/techniques/T1087.001/ T1087.001]
 |
+Account Discovery, 
 Local Account
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -836,10 +929,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Local_account_discovery_with_wmic|Local Account Discovery With Wmic]]
 
 |
+[https://attack.mitre.org/techniques/T1087/ T1087], 
 [https://attack.mitre.org/techniques/T1087.001/ T1087.001]
 |
+Account Discovery, 
 Local Account
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -847,10 +943,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Local_account_discovery_with_net|Local Account Discovery with Net]]
 
 |
+[https://attack.mitre.org/techniques/T1087/ T1087], 
 [https://attack.mitre.org/techniques/T1087.001/ T1087.001]
 |
+Account Discovery, 
 Local Account
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -869,10 +968,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Net_localgroup_discovery|Net Localgroup Discovery]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.001/ T1069.001]
 |
+Permission Groups Discovery, 
 Local Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -924,10 +1026,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Powershell_get_localgroup_discovery|PowerShell Get LocalGroup Discovery]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.001/ T1069.001]
 |
+Permission Groups Discovery, 
 Local Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -935,10 +1040,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Powershell_get_localgroup_discovery_with_script_block_logging|Powershell Get LocalGroup Discovery with Script Block Logging]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.001/ T1069.001]
 |
+Permission Groups Discovery, 
 Local Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -1034,10 +1142,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Wmic_group_discovery|Wmic Group Discovery]]
 
 |
+[https://attack.mitre.org/techniques/T1069/ T1069], 
 [https://attack.mitre.org/techniques/T1069.001/ T1069.001]
 |
+Permission Groups Discovery, 
 Local Groups
 |
+Discovery, 
 Discovery
 
 | Hunting
@@ -1105,10 +1216,13 @@ Monitor for activities and techniques associated with Password Spraying attacks
 | [[Documentation:ESSOC:detections:Detections#Multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos|Multiple Disabled Users Failing To Authenticate From Host Using Kerberos]]
 
 |
-[https://attack.mitre.org/techniques/T1110.003/ T1110.003]
+[https://attack.mitre.org/techniques/T1110.003/ T1110.003], 
+[https://attack.mitre.org/techniques/T1110/ T1110]
 |
-Password Spraying
+Password Spraying, 
+Brute Force
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -1116,10 +1230,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos|Multiple Invalid Users Failing To Authenticate From Host Using Kerberos]]
 
 |
-[https://attack.mitre.org/techniques/T1110.003/ T1110.003]
+[https://attack.mitre.org/techniques/T1110.003/ T1110.003], 
+[https://attack.mitre.org/techniques/T1110/ T1110]
 |
-Password Spraying
+Password Spraying, 
+Brute Force
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -1127,10 +1244,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm|Multiple Invalid Users Failing To Authenticate From Host Using NTLM]]
 
 |
-[https://attack.mitre.org/techniques/T1110.003/ T1110.003]
+[https://attack.mitre.org/techniques/T1110.003/ T1110.003], 
+[https://attack.mitre.org/techniques/T1110/ T1110]
 |
-Password Spraying
+Password Spraying, 
+Brute Force
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -1138,10 +1258,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Multiple_users_attempting_to_authenticate_using_explicit_credentials|Multiple Users Attempting To Authenticate Using Explicit Credentials]]
 
 |
-[https://attack.mitre.org/techniques/T1110.003/ T1110.003]
+[https://attack.mitre.org/techniques/T1110.003/ T1110.003], 
+[https://attack.mitre.org/techniques/T1110/ T1110]
 |
-Password Spraying
+Password Spraying, 
+Brute Force
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -1149,10 +1272,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Multiple_users_failing_to_authenticate_from_host_using_kerberos|Multiple Users Failing To Authenticate From Host Using Kerberos]]
 
 |
-[https://attack.mitre.org/techniques/T1110.003/ T1110.003]
+[https://attack.mitre.org/techniques/T1110.003/ T1110.003], 
+[https://attack.mitre.org/techniques/T1110/ T1110]
 |
-Password Spraying
+Password Spraying, 
+Brute Force
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -1160,10 +1286,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Multiple_users_failing_to_authenticate_from_host_using_ntlm|Multiple Users Failing To Authenticate From Host Using NTLM]]
 
 |
-[https://attack.mitre.org/techniques/T1110.003/ T1110.003]
+[https://attack.mitre.org/techniques/T1110.003/ T1110.003], 
+[https://attack.mitre.org/techniques/T1110/ T1110]
 |
-Password Spraying
+Password Spraying, 
+Brute Force
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -1171,10 +1300,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Multiple_users_failing_to_authenticate_from_process|Multiple Users Failing To Authenticate From Process]]
 
 |
-[https://attack.mitre.org/techniques/T1110.003/ T1110.003]
+[https://attack.mitre.org/techniques/T1110.003/ T1110.003], 
+[https://attack.mitre.org/techniques/T1110/ T1110]
 |
-Password Spraying
+Password Spraying, 
+Brute Force
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -1182,10 +1314,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Multiple_users_remotely_failing_to_authenticate_from_host|Multiple Users Remotely Failing To Authenticate From Host]]
 
 |
-[https://attack.mitre.org/techniques/T1110.003/ T1110.003]
+[https://attack.mitre.org/techniques/T1110.003/ T1110.003], 
+[https://attack.mitre.org/techniques/T1110/ T1110]
 |
-Password Spraying
+Password Spraying, 
+Brute Force
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -1376,10 +1511,13 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
 | [[Documentation:ESSOC:detections:Detections#Anomalous_usage_of_7zip|Anomalous usage of 7zip]]
 
 |
-[https://attack.mitre.org/techniques/T1560.001/ T1560.001]
+[https://attack.mitre.org/techniques/T1560.001/ T1560.001], 
+[https://attack.mitre.org/techniques/T1560/ T1560]
 |
-Archive via Utility
+Archive via Utility, 
+Archive Collected Data
 |
+Collection, 
 Collection
 
 | Anomaly
@@ -1387,13 +1525,19 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Cmd_echo_pipe_-_escalation|CMD Echo Pipe - Escalation]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.003/ T1059.003], 
-[https://attack.mitre.org/techniques/T1543.003/ T1543.003]
+[https://attack.mitre.org/techniques/T1543.003/ T1543.003], 
+[https://attack.mitre.org/techniques/T1543/ T1543]
 |
+Command and Scripting Interpreter, 
 Windows Command Shell, 
-Windows Service
+Windows Service, 
+Create or Modify System Process
 |
 Execution, 
+Execution, 
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -1423,10 +1567,13 @@ Defense Evasion, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Detect_regsvr32_application_control_bypass|Detect Regsvr32 Application Control Bypass]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.010/ T1218.010]
 |
+Signed Binary Proxy Execution, 
 Regsvr32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -1445,10 +1592,13 @@ Defense Evasion, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Rundll32_with_no_command_line_arguments_with_network|Rundll32 with no Command Line Arguments with Network]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -1500,13 +1650,19 @@ Defense Evasion, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_rename|Suspicious MSBuild Rename]]
 
 |
-[https://attack.mitre.org/techniques/T1127.001/ T1127.001], 
-[https://attack.mitre.org/techniques/T1036.003/ T1036.003]
+[https://attack.mitre.org/techniques/T1036/ T1036], 
+[https://attack.mitre.org/techniques/T1127/ T1127], 
+[https://attack.mitre.org/techniques/T1036.003/ T1036.003], 
+[https://attack.mitre.org/techniques/T1127.001/ T1127.001]
 |
-MSBuild, 
-Rename System Utilities
+Masquerading, 
+Trusted Developer Utilities Proxy Execution, 
+Rename System Utilities, 
+MSBuild
 |
 Defense Evasion, 
+Defense Evasion, 
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -1514,10 +1670,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_startw|Suspicious Rundll32 StartW]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -1525,10 +1684,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_no_command_line_arguments|Suspicious Rundll32 no Command Line Arguments]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -1547,13 +1709,16 @@ Defense Evasion, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Suspicious_microsoft_workflow_compiler_rename|Suspicious microsoft workflow compiler rename]]
 
 |
+[https://attack.mitre.org/techniques/T1036/ T1036], 
 [https://attack.mitre.org/techniques/T1127/ T1127], 
 [https://attack.mitre.org/techniques/T1036.003/ T1036.003]
 |
+Masquerading, 
 Trusted Developer Utilities Proxy Execution, 
 Rename System Utilities
 |
 Defense Evasion, 
+Defense Evasion, 
 Defense Evasion
 
 | Hunting
@@ -1561,13 +1726,19 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_path|Suspicious msbuild path]]
 
 |
-[https://attack.mitre.org/techniques/T1127.001/ T1127.001], 
-[https://attack.mitre.org/techniques/T1036.003/ T1036.003]
+[https://attack.mitre.org/techniques/T1036/ T1036], 
+[https://attack.mitre.org/techniques/T1127/ T1127], 
+[https://attack.mitre.org/techniques/T1036.003/ T1036.003], 
+[https://attack.mitre.org/techniques/T1127.001/ T1127.001]
 |
-MSBuild, 
-Rename System Utilities
+Masquerading, 
+Trusted Developer Utilities Proxy Execution, 
+Rename System Utilities, 
+MSBuild
 |
 Defense Evasion, 
+Defense Evasion, 
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -1629,10 +1800,13 @@ Monitor for and investigate activities--such as suspicious writes to the Windows
 | [[Documentation:ESSOC:detections:Detections#Detect_renamed_7-zip|Detect Renamed 7-Zip]]
 
 |
-[https://attack.mitre.org/techniques/T1560.001/ T1560.001]
+[https://attack.mitre.org/techniques/T1560.001/ T1560.001], 
+[https://attack.mitre.org/techniques/T1560/ T1560]
 |
-Archive via Utility
+Archive via Utility, 
+Archive Collected Data
 |
+Collection, 
 Collection
 
 | Hunting
@@ -1640,10 +1814,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Detect_renamed_winrar|Detect Renamed WinRAR]]
 
 |
-[https://attack.mitre.org/techniques/T1560.001/ T1560.001]
+[https://attack.mitre.org/techniques/T1560.001/ T1560.001], 
+[https://attack.mitre.org/techniques/T1560/ T1560]
 |
-Archive via Utility
+Archive via Utility, 
+Archive Collected Data
 |
+Collection, 
 Collection
 
 | Hunting
@@ -1651,10 +1828,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Email_files_written_outside_of_the_outlook_directory|Email files written outside of the Outlook directory]]
 
 |
+[https://attack.mitre.org/techniques/T1114/ T1114], 
 [https://attack.mitre.org/techniques/T1114.001/ T1114.001]
 |
+Email Collection, 
 Local Email Collection
 |
+Collection, 
 Collection
 
 | TTP
@@ -1662,10 +1842,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Email_servers_sending_high_volume_traffic_to_hosts|Email servers sending high volume traffic to hosts]]
 
 |
+[https://attack.mitre.org/techniques/T1114/ T1114], 
 [https://attack.mitre.org/techniques/T1114.002/ T1114.002]
 |
+Email Collection, 
 Remote Email Collection
 |
+Collection, 
 Collection
 
 | Anomaly
@@ -1673,10 +1856,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Hosts_receiving_high_volume_of_network_traffic_from_email_server|Hosts receiving high volume of network traffic from email server]]
 
 |
-[https://attack.mitre.org/techniques/T1114.002/ T1114.002]
+[https://attack.mitre.org/techniques/T1114.002/ T1114.002], 
+[https://attack.mitre.org/techniques/T1114/ T1114]
 |
-Remote Email Collection
+Remote Email Collection, 
+Email Collection
 |
+Collection, 
 Collection
 
 | Anomaly
@@ -1748,10 +1934,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Dns_query_length_outliers_-_mltk|DNS Query Length Outliers - MLTK]]
 
 |
-[https://attack.mitre.org/techniques/T1071.004/ T1071.004]
+[https://attack.mitre.org/techniques/T1071.004/ T1071.004], 
+[https://attack.mitre.org/techniques/T1071/ T1071]
 |
-DNS
+DNS, 
+Application Layer Protocol
 |
+Command And Control, 
 Command And Control
 
 | Anomaly
@@ -1759,10 +1948,13 @@ Command And Control
 | [[Documentation:ESSOC:detections:Detections#Dns_query_length_with_high_standard_deviation|DNS Query Length With High Standard Deviation]]
 
 |
-[https://attack.mitre.org/techniques/T1048.003/ T1048.003]
+[https://attack.mitre.org/techniques/T1048.003/ T1048.003], 
+[https://attack.mitre.org/techniques/T1048/ T1048]
 |
-Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
+Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, 
+Exfiltration Over Alternative Protocol
 |
+Exfiltration, 
 Exfiltration
 
 | Anomaly
@@ -1800,10 +1992,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Excessive_dns_failures|Excessive DNS Failures]]
 
 |
-[https://attack.mitre.org/techniques/T1071.004/ T1071.004]
+[https://attack.mitre.org/techniques/T1071.004/ T1071.004], 
+[https://attack.mitre.org/techniques/T1071/ T1071]
 |
-DNS
+DNS, 
+Application Layer Protocol
 |
+Command And Control, 
 Command And Control
 
 | Anomaly
@@ -1822,10 +2017,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Multiple_archive_files_http_post_traffic|Multiple Archive Files Http Post Traffic]]
 
 |
-[https://attack.mitre.org/techniques/T1048.003/ T1048.003]
+[https://attack.mitre.org/techniques/T1048.003/ T1048.003], 
+[https://attack.mitre.org/techniques/T1048/ T1048]
 |
-Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
+Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, 
+Exfiltration Over Alternative Protocol
 |
+Exfiltration, 
 Exfiltration
 
 | TTP
@@ -1833,10 +2031,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Plain_http_post_exfiltrated_data|Plain HTTP POST Exfiltrated Data]]
 
 |
-[https://attack.mitre.org/techniques/T1048.003/ T1048.003]
+[https://attack.mitre.org/techniques/T1048.003/ T1048.003], 
+[https://attack.mitre.org/techniques/T1048/ T1048]
 |
-Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
+Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, 
+Exfiltration Over Alternative Protocol
 |
+Exfiltration, 
 Exfiltration
 
 | TTP
@@ -1855,10 +2056,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Protocol_or_port_mismatch|Protocol or Port Mismatch]]
 
 |
-[https://attack.mitre.org/techniques/T1048.003/ T1048.003]
+[https://attack.mitre.org/techniques/T1048.003/ T1048.003], 
+[https://attack.mitre.org/techniques/T1048/ T1048]
 |
-Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
+Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, 
+Exfiltration Over Alternative Protocol
 |
+Exfiltration, 
 Exfiltration
 
 | Anomaly
@@ -1866,10 +2070,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Tor_traffic|TOR Traffic]]
 
 |
+[https://attack.mitre.org/techniques/T1071/ T1071], 
 [https://attack.mitre.org/techniques/T1071.001/ T1071.001]
 |
+Application Layer Protocol, 
 Web Protocols
 |
+Command And Control, 
 Command And Control
 
 | TTP
@@ -1923,10 +2130,13 @@ Uncover activity consistent with credential dumping, a technique wherein attacke
 | [[Documentation:ESSOC:detections:Detections#Access_lsass_memory_for_dump_creation|Access LSASS Memory for Dump Creation]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2053,10 +2263,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Attempted_credential_dump_from_registry_via_reg_exe|Attempted Credential Dump From Registry via Reg exe]]
 
 |
-[https://attack.mitre.org/techniques/T1003.002/ T1003.002]
+[https://attack.mitre.org/techniques/T1003.002/ T1003.002], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-Security Account Manager
+Security Account Manager, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2064,10 +2277,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Create_remote_thread_into_lsass|Create Remote Thread into LSASS]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2075,10 +2291,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Creation_of_shadow_copy|Creation of Shadow Copy]]
 
 |
-[https://attack.mitre.org/techniques/T1003.003/ T1003.003]
+[https://attack.mitre.org/techniques/T1003.003/ T1003.003], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-NTDS
+NTDS, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2086,10 +2305,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Creation_of_shadow_copy_with_wmic_and_powershell|Creation of Shadow Copy with wmic and powershell]]
 
 |
-[https://attack.mitre.org/techniques/T1003.003/ T1003.003]
+[https://attack.mitre.org/techniques/T1003.003/ T1003.003], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-NTDS
+NTDS, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2097,10 +2319,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Creation_of_lsass_dump_with_taskmgr|Creation of lsass Dump with Taskmgr]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2108,10 +2333,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Credential_dumping_via_copy_command_from_shadow_copy|Credential Dumping via Copy Command from Shadow Copy]]
 
 |
-[https://attack.mitre.org/techniques/T1003.003/ T1003.003]
+[https://attack.mitre.org/techniques/T1003.003/ T1003.003], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-NTDS
+NTDS, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2119,10 +2347,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Credential_dumping_via_symlink_to_shadow_copy|Credential Dumping via Symlink to Shadow Copy]]
 
 |
-[https://attack.mitre.org/techniques/T1003.003/ T1003.003]
+[https://attack.mitre.org/techniques/T1003.003/ T1003.003], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-NTDS
+NTDS, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2243,10 +2474,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Detect_copy_of_shadowcopy_with_script_block_logging|Detect Copy of ShadowCopy with Script Block Logging]]
 
 |
-[https://attack.mitre.org/techniques/T1003.002/ T1003.002]
+[https://attack.mitre.org/techniques/T1003.002/ T1003.002], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-Security Account Manager
+Security Account Manager, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2254,10 +2488,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Detect_credential_dumping_through_lsass_access|Detect Credential Dumping through LSASS access]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2265,10 +2502,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Detect_dump_lsass_memory_using_comsvcs|Detect Dump LSASS Memory using comsvcs]]
 
 |
-[https://attack.mitre.org/techniques/T1003.003/ T1003.003]
+[https://attack.mitre.org/techniques/T1003.003/ T1003.003], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-NTDS
+NTDS, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2276,10 +2516,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Detect_kerberoasting|Detect Kerberoasting]]
 
 |
-[https://attack.mitre.org/techniques/T1558.003/ T1558.003]
+[https://attack.mitre.org/techniques/T1558.003/ T1558.003], 
+[https://attack.mitre.org/techniques/T1558/ T1558]
 |
-Kerberoasting
+Kerberoasting, 
+Steal or Forge Kerberos Tickets
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2287,10 +2530,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Detect_mimikatz_using_loaded_images|Detect Mimikatz Using Loaded Images]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2298,10 +2544,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_comsvcs_dll|Dump LSASS via comsvcs DLL]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2309,10 +2558,27 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_procdump|Dump LSASS via procdump]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
+Credential Access
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Enable_wdigest_uselogoncredential_registry|Enable WDigest UseLogonCredential Registry]]
+
+|
+[https://attack.mitre.org/techniques/T1112/ T1112], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
+|
+Modify Registry, 
+OS Credential Dumping
+|
+Defense Evasion, 
 Credential Access
 
 | TTP
@@ -2320,10 +2586,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Esentutl_sam_copy|Esentutl SAM Copy]]
 
 |
-[https://attack.mitre.org/techniques/T1003.002/ T1003.002]
+[https://attack.mitre.org/techniques/T1003.002/ T1003.002], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-Security Account Manager
+Security Account Manager, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | Hunting
@@ -2331,10 +2600,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Extraction_of_registry_hives|Extraction of Registry Hives]]
 
 |
-[https://attack.mitre.org/techniques/T1003.002/ T1003.002]
+[https://attack.mitre.org/techniques/T1003.002/ T1003.002], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-Security Account Manager
+Security Account Manager, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2342,10 +2614,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Ntdsutil_export_ntds|Ntdsutil Export NTDS]]
 
 |
-[https://attack.mitre.org/techniques/T1003.003/ T1003.003]
+[https://attack.mitre.org/techniques/T1003.003/ T1003.003], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-NTDS
+NTDS, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2353,10 +2628,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Sam_database_file_access_attempt|SAM Database File Access Attempt]]
 
 |
-[https://attack.mitre.org/techniques/T1003.002/ T1003.002]
+[https://attack.mitre.org/techniques/T1003.002/ T1003.002], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-Security Account Manager
+Security Account Manager, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | Hunting
@@ -2364,10 +2642,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Secretdumps_offline_ntds_dumping_tool|SecretDumps Offline NTDS Dumping Tool]]
 
 |
-[https://attack.mitre.org/techniques/T1003.003/ T1003.003]
+[https://attack.mitre.org/techniques/T1003.003/ T1003.003], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-NTDS
+NTDS, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2375,10 +2656,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Set_default_powershell_execution_policy_to_unrestricted_or_bypass|Set Default PowerShell Execution Policy To Unrestricted or Bypass]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -2531,10 +2815,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Mailsniper_invoke_functions|Mailsniper Invoke functions]]
 
 |
+[https://attack.mitre.org/techniques/T1114/ T1114], 
 [https://attack.mitre.org/techniques/T1114.001/ T1114.001]
 |
+Email Collection, 
 Local Email Collection
 |
+Collection, 
 Collection
 
 | TTP
@@ -2542,10 +2829,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Multiple_archive_files_http_post_traffic|Multiple Archive Files Http Post Traffic]]
 
 |
-[https://attack.mitre.org/techniques/T1048.003/ T1048.003]
+[https://attack.mitre.org/techniques/T1048.003/ T1048.003], 
+[https://attack.mitre.org/techniques/T1048/ T1048]
 |
-Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
+Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, 
+Exfiltration Over Alternative Protocol
 |
+Exfiltration, 
 Exfiltration
 
 | TTP
@@ -2564,10 +2854,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#O365_suspicious_admin_email_forwarding|O365 Suspicious Admin Email Forwarding]]
 
 |
-[https://attack.mitre.org/techniques/T1114.003/ T1114.003]
+[https://attack.mitre.org/techniques/T1114.003/ T1114.003], 
+[https://attack.mitre.org/techniques/T1114/ T1114]
 |
-Email Forwarding Rule
+Email Forwarding Rule, 
+Email Collection
 |
+Collection, 
 Collection
 
 | Anomaly
@@ -2575,10 +2868,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#O365_suspicious_user_email_forwarding|O365 Suspicious User Email Forwarding]]
 
 |
-[https://attack.mitre.org/techniques/T1114.003/ T1114.003]
+[https://attack.mitre.org/techniques/T1114.003/ T1114.003], 
+[https://attack.mitre.org/techniques/T1114/ T1114]
 |
-Email Forwarding Rule
+Email Forwarding Rule, 
+Email Collection
 |
+Collection, 
 Collection
 
 | Anomaly
@@ -2586,10 +2882,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Plain_http_post_exfiltrated_data|Plain HTTP POST Exfiltrated Data]]
 
 |
-[https://attack.mitre.org/techniques/T1048.003/ T1048.003]
+[https://attack.mitre.org/techniques/T1048.003/ T1048.003], 
+[https://attack.mitre.org/techniques/T1048/ T1048]
 |
-Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
+Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, 
+Exfiltration Over Alternative Protocol
 |
+Exfiltration, 
 Exfiltration
 
 | TTP
@@ -2697,10 +2996,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Detect_credential_dumping_through_lsass_access|Detect Credential Dumping through LSASS access]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2708,10 +3010,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Detect_mimikatz_using_loaded_images|Detect Mimikatz Using Loaded Images]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -2774,10 +3079,13 @@ Looks for activities and techniques associated with the disabling of security to
 | [[Documentation:ESSOC:detections:Detections#Attempt_to_add_certificate_to_untrusted_store|Attempt To Add Certificate To Untrusted Store]]
 
 |
-[https://attack.mitre.org/techniques/T1553.004/ T1553.004]
+[https://attack.mitre.org/techniques/T1553.004/ T1553.004], 
+[https://attack.mitre.org/techniques/T1553/ T1553]
 |
-Install Root Certificate
+Install Root Certificate, 
+Subvert Trust Controls
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -2785,10 +3093,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Attempt_to_stop_security_service|Attempt To Stop Security Service]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -2796,10 +3107,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Processes_launching_netsh|Processes launching netsh]]
 
 |
-[https://attack.mitre.org/techniques/T1562.004/ T1562.004]
+[https://attack.mitre.org/techniques/T1562.004/ T1562.004], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify System Firewall
+Disable or Modify System Firewall, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -2807,10 +3121,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]]
 
 |
-[https://attack.mitre.org/techniques/T1543.003/ T1543.003]
+[https://attack.mitre.org/techniques/T1543.003/ T1543.003], 
+[https://attack.mitre.org/techniques/T1543/ T1543]
 |
-Windows Service
+Windows Service, 
+Create or Modify System Process
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -2829,10 +3146,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Unload_sysmon_filter_driver|Unload Sysmon Filter Driver]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -3002,10 +3322,13 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
 | [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadstring|Any Powershell DownloadString]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3013,10 +3336,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Detect_exchange_web_shell|Detect Exchange Web Shell]]
 
 |
+[https://attack.mitre.org/techniques/T1505/ T1505], 
 [https://attack.mitre.org/techniques/T1505.003/ T1505.003]
 |
+Server Software Component, 
 Web Shell
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -3024,10 +3350,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#Detect_new_local_admin_account|Detect New Local Admin account]]
 
 |
-[https://attack.mitre.org/techniques/T1136.001/ T1136.001]
+[https://attack.mitre.org/techniques/T1136.001/ T1136.001], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Local Account
+Local Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -3035,10 +3364,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]]
 
 |
+[https://attack.mitre.org/techniques/T1021/ T1021], 
 [https://attack.mitre.org/techniques/T1021.002/ T1021.002]
 |
+Remote Services, 
 SMB/Windows Admin Shares
 |
+Lateral Movement, 
 Lateral Movement
 
 | TTP
@@ -3046,10 +3378,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]]
 
 |
+[https://attack.mitre.org/techniques/T1569/ T1569], 
 [https://attack.mitre.org/techniques/T1569.002/ T1569.002]
 |
+System Services, 
 Service Execution
 |
+Execution, 
 Execution
 
 | Hunting
@@ -3057,10 +3392,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_comsvcs_dll|Dump LSASS via comsvcs DLL]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -3068,10 +3406,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_procdump|Dump LSASS via procdump]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -3079,10 +3420,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Email_servers_sending_high_volume_traffic_to_hosts|Email servers sending high volume traffic to hosts]]
 
 |
+[https://attack.mitre.org/techniques/T1114/ T1114], 
 [https://attack.mitre.org/techniques/T1114.002/ T1114.002]
 |
+Email Collection, 
 Remote Email Collection
 |
+Collection, 
 Collection
 
 | Anomaly
@@ -3090,10 +3434,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_connect_to_internet_with_hidden_window|Malicious PowerShell Process - Connect To Internet With Hidden Window]]
 
 |
-[https://attack.mitre.org/techniques/T1059.001/ T1059.001]
+[https://attack.mitre.org/techniques/T1059.001/ T1059.001], 
+[https://attack.mitre.org/techniques/T1059/ T1059]
 |
-PowerShell
+PowerShell, 
+Command and Scripting Interpreter
 |
+Execution, 
 Execution
 
 | Hunting
@@ -3101,10 +3448,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_execution_policy_bypass|Malicious PowerShell Process - Execution Policy Bypass]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3112,10 +3462,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Nishang_powershelltcponeline|Nishang PowershellTCPOneLine]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3123,10 +3476,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Ntdsutil_export_ntds|Ntdsutil Export NTDS]]
 
 |
-[https://attack.mitre.org/techniques/T1003.003/ T1003.003]
+[https://attack.mitre.org/techniques/T1003.003/ T1003.003], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-NTDS
+NTDS, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -3134,10 +3490,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Set_default_powershell_execution_policy_to_unrestricted_or_bypass|Set Default PowerShell Execution Policy To Unrestricted or Bypass]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3156,10 +3515,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#W3wp_spawning_shell|W3WP Spawning Shell]]
 
 |
+[https://attack.mitre.org/techniques/T1505/ T1505], 
 [https://attack.mitre.org/techniques/T1505.003/ T1505.003]
 |
+Server Software Component, 
 Web Shell
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -3219,10 +3581,13 @@ Adversaries may transfer tools or other files from an external system into a com
 | [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadfile|Any Powershell DownloadFile]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3230,10 +3595,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadstring|Any Powershell DownloadString]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3326,10 +3694,13 @@ Detect and investigate tactics, techniques, and procedures around how attackers
 | [[Documentation:ESSOC:detections:Detections#Detect_activity_related_to_pass_the_hash_attacks|Detect Activity Related to Pass the Hash Attacks]]
 
 |
+[https://attack.mitre.org/techniques/T1550/ T1550], 
 [https://attack.mitre.org/techniques/T1550.002/ T1550.002]
 |
+Use Alternate Authentication Material, 
 Pass the Hash
 |
+Defense Evasion, Lateral Movement, 
 Defense Evasion, Lateral Movement
 
 | TTP
@@ -3337,10 +3708,13 @@ Defense Evasion, Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Detect_pass_the_hash|Detect Pass the Hash]]
 
 |
+[https://attack.mitre.org/techniques/T1550/ T1550], 
 [https://attack.mitre.org/techniques/T1550.002/ T1550.002]
 |
+Use Alternate Authentication Material, 
 Pass the Hash
 |
+Defense Evasion, Lateral Movement, 
 Defense Evasion, Lateral Movement
 
 | TTP
@@ -3348,10 +3722,13 @@ Defense Evasion, Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]]
 
 |
+[https://attack.mitre.org/techniques/T1021/ T1021], 
 [https://attack.mitre.org/techniques/T1021.002/ T1021.002]
 |
+Remote Services, 
 SMB/Windows Admin Shares
 |
+Lateral Movement, 
 Lateral Movement
 
 | TTP
@@ -3359,10 +3736,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]]
 
 |
+[https://attack.mitre.org/techniques/T1569/ T1569], 
 [https://attack.mitre.org/techniques/T1569.002/ T1569.002]
 |
+System Services, 
 Service Execution
 |
+Execution, 
 Execution
 
 | Hunting
@@ -3370,10 +3750,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Kerberoasting_spn_request_with_rc4_encryption|Kerberoasting spn request with RC4 encryption]]
 
 |
-[https://attack.mitre.org/techniques/T1558.003/ T1558.003]
+[https://attack.mitre.org/techniques/T1558.003/ T1558.003], 
+[https://attack.mitre.org/techniques/T1558/ T1558]
 |
-Kerberoasting
+Kerberoasting, 
+Steal or Forge Kerberos Tickets
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -3381,10 +3764,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Potential_pass_the_token_or_hash_observed_at_the_destination_device|Potential Pass the Token or Hash Observed at the Destination Device]]
 
 |
+[https://attack.mitre.org/techniques/T1550/ T1550], 
 [https://attack.mitre.org/techniques/T1550.002/ T1550.002]
 |
+Use Alternate Authentication Material, 
 Pass the Hash
 |
+Defense Evasion, Lateral Movement, 
 Defense Evasion, Lateral Movement
 
 | TTP
@@ -3392,10 +3778,13 @@ Defense Evasion, Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Potential_pass_the_token_or_hash_observed_by_an_event_collecting_device|Potential Pass the Token or Hash Observed by an Event Collecting Device]]
 
 |
+[https://attack.mitre.org/techniques/T1550/ T1550], 
 [https://attack.mitre.org/techniques/T1550.002/ T1550.002]
 |
+Use Alternate Authentication Material, 
 Pass the Hash
 |
+Defense Evasion, Lateral Movement, 
 Defense Evasion, Lateral Movement
 
 | TTP
@@ -3403,10 +3792,13 @@ Defense Evasion, Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_traffic|Remote Desktop Network Traffic]]
 
 |
-[https://attack.mitre.org/techniques/T1021.001/ T1021.001]
+[https://attack.mitre.org/techniques/T1021.001/ T1021.001], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-Remote Desktop Protocol
+Remote Desktop Protocol, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -3414,10 +3806,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Remote_desktop_process_running_on_system|Remote Desktop Process Running On System]]
 
 |
-[https://attack.mitre.org/techniques/T1021.001/ T1021.001]
+[https://attack.mitre.org/techniques/T1021.001/ T1021.001], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-Remote Desktop Protocol
+Remote Desktop Protocol, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Hunting
@@ -3425,10 +3820,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Schtasks_scheduling_job_on_remote_system|Schtasks scheduling job on remote system]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -3478,10 +3876,13 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an
 | [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadfile|Any Powershell DownloadFile]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3489,10 +3890,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadstring|Any Powershell DownloadString]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3544,10 +3948,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Detect_empire_with_powershell_script_block_logging|Detect Empire with PowerShell Script Block Logging]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3620,10 +4027,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_connect_to_internet_with_hidden_window|Malicious PowerShell Process - Connect To Internet With Hidden Window]]
 
 |
-[https://attack.mitre.org/techniques/T1059.001/ T1059.001]
+[https://attack.mitre.org/techniques/T1059.001/ T1059.001], 
+[https://attack.mitre.org/techniques/T1059/ T1059]
 |
-PowerShell
+PowerShell, 
+Command and Scripting Interpreter
 |
+Execution, 
 Execution
 
 | Hunting
@@ -3642,10 +4052,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_with_obfuscation_techniques|Malicious PowerShell Process With Obfuscation Techniques]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3653,10 +4066,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Powershell_4104_hunting|PowerShell 4104 Hunting]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | Hunting
@@ -3664,10 +4080,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Powershell_domain_enumeration|PowerShell Domain Enumeration]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3675,10 +4094,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Powershell_loading_dotnet_into_memory_via_system_reflection_assembly|PowerShell Loading DotNET into Memory via System Reflection Assembly]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3686,10 +4108,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Powershell_creating_thread_mutex|Powershell Creating Thread Mutex]]
 
 |
+[https://attack.mitre.org/techniques/T1027/ T1027], 
 [https://attack.mitre.org/techniques/T1027.005/ T1027.005]
 |
+Obfuscated Files or Information, 
 Indicator Removal from Tools
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -3697,10 +4122,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Powershell_enable_smb1protocol_feature|Powershell Enable SMB1Protocol Feature]]
 
 |
+[https://attack.mitre.org/techniques/T1027/ T1027], 
 [https://attack.mitre.org/techniques/T1027.005/ T1027.005]
 |
+Obfuscated Files or Information, 
 Indicator Removal from Tools
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -3708,10 +4136,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Powershell_execute_com_object|Powershell Execute COM Object]]
 
 |
-[https://attack.mitre.org/techniques/T1546.015/ T1546.015]
+[https://attack.mitre.org/techniques/T1546.015/ T1546.015], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
 |
-Component Object Model Hijacking
+Component Object Model Hijacking, 
+Event Triggered Execution
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
 | TTP
@@ -3719,12 +4150,15 @@ Privilege Escalation, Persistence
 | [[Documentation:ESSOC:detections:Detections#Powershell_fileless_process_injection_via_getprocaddress|Powershell Fileless Process Injection via GetProcAddress]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1055/ T1055], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 Process Injection, 
 PowerShell
 |
+Execution, 
 Defense Evasion, Privilege Escalation, 
 Execution
 
@@ -3733,12 +4167,15 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Powershell_fileless_script_contains_base64_encoded_content|Powershell Fileless Script Contains Base64 Encoded Content]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1027/ T1027], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 Obfuscated Files or Information, 
 PowerShell
 |
+Execution, 
 Defense Evasion, 
 Execution
 
@@ -3747,10 +4184,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Powershell_processing_stream_of_data|Powershell Processing Stream Of Data]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3791,10 +4231,13 @@ Reconnaissance
 | [[Documentation:ESSOC:detections:Detections#Set_default_powershell_execution_policy_to_unrestricted_or_bypass|Set Default PowerShell Execution Policy To Unrestricted or Bypass]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -3872,10 +4315,30 @@ Adversaries may rename legitimate system utilities to try to evade security mech
 | [[Documentation:ESSOC:detections:Detections#Execution_of_file_with_multiple_extensions|Execution of File with Multiple Extensions]]
 
 |
+[https://attack.mitre.org/techniques/T1036/ T1036], 
 [https://attack.mitre.org/techniques/T1036.003/ T1036.003]
 |
+Masquerading, 
 Rename System Utilities
 |
+Defense Evasion, 
+Defense Evasion
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Sdelete_application_execution|Sdelete Application Execution]]
+
+|
+[https://attack.mitre.org/techniques/T1485/ T1485], 
+[https://attack.mitre.org/techniques/T1070.004/ T1070.004], 
+[https://attack.mitre.org/techniques/T1070/ T1070]
+|
+Data Destruction, 
+File Deletion, 
+Indicator Removal on Host
+|
+Impact, 
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -3883,13 +4346,19 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_rename|Suspicious MSBuild Rename]]
 
 |
-[https://attack.mitre.org/techniques/T1127.001/ T1127.001], 
-[https://attack.mitre.org/techniques/T1036.003/ T1036.003]
+[https://attack.mitre.org/techniques/T1036/ T1036], 
+[https://attack.mitre.org/techniques/T1127/ T1127], 
+[https://attack.mitre.org/techniques/T1036.003/ T1036.003], 
+[https://attack.mitre.org/techniques/T1127.001/ T1127.001]
 |
-MSBuild, 
-Rename System Utilities
+Masquerading, 
+Trusted Developer Utilities Proxy Execution, 
+Rename System Utilities, 
+MSBuild
 |
 Defense Evasion, 
+Defense Evasion, 
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -3897,13 +4366,19 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_rename|Suspicious Rundll32 Rename]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
+[https://attack.mitre.org/techniques/T1036/ T1036], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011], 
 [https://attack.mitre.org/techniques/T1036.003/ T1036.003]
 |
+Signed Binary Proxy Execution, 
+Masquerading, 
 Rundll32, 
 Rename System Utilities
 |
 Defense Evasion, 
+Defense Evasion, 
+Defense Evasion, 
 Defense Evasion
 
 | Hunting
@@ -3911,13 +4386,16 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_microsoft_workflow_compiler_rename|Suspicious microsoft workflow compiler rename]]
 
 |
+[https://attack.mitre.org/techniques/T1036/ T1036], 
 [https://attack.mitre.org/techniques/T1127/ T1127], 
 [https://attack.mitre.org/techniques/T1036.003/ T1036.003]
 |
+Masquerading, 
 Trusted Developer Utilities Proxy Execution, 
 Rename System Utilities
 |
 Defense Evasion, 
+Defense Evasion, 
 Defense Evasion
 
 | Hunting
@@ -3925,13 +4403,19 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_path|Suspicious msbuild path]]
 
 |
-[https://attack.mitre.org/techniques/T1127.001/ T1127.001], 
-[https://attack.mitre.org/techniques/T1036.003/ T1036.003]
+[https://attack.mitre.org/techniques/T1036/ T1036], 
+[https://attack.mitre.org/techniques/T1127/ T1127], 
+[https://attack.mitre.org/techniques/T1036.003/ T1036.003], 
+[https://attack.mitre.org/techniques/T1127.001/ T1127.001]
 |
-MSBuild, 
-Rename System Utilities
+Masquerading, 
+Trusted Developer Utilities Proxy Execution, 
+Rename System Utilities, 
+MSBuild
 |
 Defense Evasion, 
+Defense Evasion, 
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -3950,10 +4434,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#System_processes_run_from_unexpected_locations|System Processes Run From Unexpected Locations]]
 
 |
+[https://attack.mitre.org/techniques/T1036/ T1036], 
 [https://attack.mitre.org/techniques/T1036.003/ T1036.003]
 |
+Masquerading, 
 Rename System Utilities
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -4061,10 +4548,13 @@ CVE-2021-40444 is a remote code execution vulnerability in MSHTML, recently used
 | [[Documentation:ESSOC:detections:Detections#Control_loading_from_world_writable_directory|Control Loading from World Writable Directory]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.002/ T1218.002]
 |
+Signed Binary Proxy Execution, 
 Control Panel
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -4072,10 +4562,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Mshtml_module_load_in_office_product|MSHTML Module Load in Office Product]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4083,10 +4576,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_product_writing_cab_or_inf|Office Product Writing cab or inf]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4094,10 +4590,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_spawning_control|Office Spawning Control]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4105,10 +4604,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Rundll32_control_rundll_hunt|Rundll32 Control RunDLL Hunt]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | Hunting
@@ -4116,10 +4618,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Rundll32_control_rundll_world_writable_directory|Rundll32 Control RunDLL World Writable Directory]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -4167,10 +4672,13 @@ Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and managemen
 | [[Documentation:ESSOC:detections:Detections#Anomalous_usage_of_7zip|Anomalous usage of 7zip]]
 
 |
-[https://attack.mitre.org/techniques/T1560.001/ T1560.001]
+[https://attack.mitre.org/techniques/T1560.001/ T1560.001], 
+[https://attack.mitre.org/techniques/T1560/ T1560]
 |
-Archive via Utility
+Archive via Utility, 
+Archive Collected Data
 |
+Collection, 
 Collection
 
 | Anomaly
@@ -4178,10 +4686,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Detect_outbound_smb_traffic|Detect Outbound SMB Traffic]]
 
 |
-[https://attack.mitre.org/techniques/T1071.002/ T1071.002]
+[https://attack.mitre.org/techniques/T1071.002/ T1071.002], 
+[https://attack.mitre.org/techniques/T1071/ T1071]
 |
-File Transfer Protocols
+File Transfer Protocols, 
+Application Layer Protocol
 |
+Command And Control, 
 Command And Control
 
 | TTP
@@ -4189,10 +4700,13 @@ Command And Control
 | [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.003/ T1059.003]
 |
+Command and Scripting Interpreter, 
 Windows Command Shell
 |
+Execution, 
 Execution
 
 | Hunting
@@ -4200,10 +4714,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Detect_rundll32_inline_hta_execution|Detect Rundll32 Inline HTA Execution]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.005/ T1218.005]
 |
+Signed Binary Proxy Execution, 
 Mshta
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -4211,10 +4728,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#First_time_seen_running_windows_service|First Time Seen Running Windows Service]]
 
 |
+[https://attack.mitre.org/techniques/T1569/ T1569], 
 [https://attack.mitre.org/techniques/T1569.002/ T1569.002]
 |
+System Services, 
 Service Execution
 |
+Execution, 
 Execution
 
 | Anomaly
@@ -4233,10 +4753,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]]
 
 |
-[https://attack.mitre.org/techniques/T1543.003/ T1543.003]
+[https://attack.mitre.org/techniques/T1543.003/ T1543.003], 
+[https://attack.mitre.org/techniques/T1543/ T1543]
 |
-Windows Service
+Windows Service, 
+Create or Modify System Process
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -4244,10 +4767,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Scheduled_task_deleted_or_created_via_cmd|Scheduled Task Deleted Or Created via CMD]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -4255,10 +4781,13 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Schtasks_scheduling_job_on_remote_system|Schtasks scheduling job on remote system]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -4288,10 +4817,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#Tor_traffic|TOR Traffic]]
 
 |
+[https://attack.mitre.org/techniques/T1071/ T1071], 
 [https://attack.mitre.org/techniques/T1071.001/ T1071.001]
 |
+Application Layer Protocol, 
 Web Protocols
 |
+Command And Control, 
 Command And Control
 
 | TTP
@@ -4432,10 +4964,13 @@ Monitor your environment for suspicious behaviors that resemble the techniques e
 | [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_connect_to_internet_with_hidden_window|Malicious PowerShell Process - Connect To Internet With Hidden Window]]
 
 |
-[https://attack.mitre.org/techniques/T1059.001/ T1059.001]
+[https://attack.mitre.org/techniques/T1059.001/ T1059.001], 
+[https://attack.mitre.org/techniques/T1059/ T1059]
 |
-PowerShell
+PowerShell, 
+Command and Scripting Interpreter
 |
+Execution, 
 Execution
 
 | Hunting
@@ -4443,10 +4978,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]]
 
 |
-[https://attack.mitre.org/techniques/T1547.001/ T1547.001]
+[https://attack.mitre.org/techniques/T1547.001/ T1547.001], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Registry Run Keys / Startup Folder
+Registry Run Keys / Startup Folder, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -4510,10 +5048,13 @@ ProxyShell is a chain of exploits targeting on-premise Microsoft Exchange Server
 | [[Documentation:ESSOC:detections:Detections#Detect_exchange_web_shell|Detect Exchange Web Shell]]
 
 |
+[https://attack.mitre.org/techniques/T1505/ T1505], 
 [https://attack.mitre.org/techniques/T1505.003/ T1505.003]
 |
+Server Software Component, 
 Web Shell
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -4532,10 +5073,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Exchange_powershell_module_usage|Exchange PowerShell Module Usage]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -4543,10 +5087,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#W3wp_spawning_shell|W3WP Spawning Shell]]
 
 |
+[https://attack.mitre.org/techniques/T1505/ T1505], 
 [https://attack.mitre.org/techniques/T1505.003/ T1505.003]
 |
+Server Software Component, 
 Web Shell
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -4660,10 +5207,13 @@ Command And Control
 | [[Documentation:ESSOC:detections:Detections#Suspicious_plistbuddy_usage|Suspicious PlistBuddy Usage]]
 
 |
-[https://attack.mitre.org/techniques/T1543.001/ T1543.001]
+[https://attack.mitre.org/techniques/T1543.001/ T1543.001], 
+[https://attack.mitre.org/techniques/T1543/ T1543]
 |
-Launch Agent
+Launch Agent, 
+Create or Modify System Process
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -4671,10 +5221,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Suspicious_plistbuddy_usage_via_osquery|Suspicious PlistBuddy Usage via OSquery]]
 
 |
-[https://attack.mitre.org/techniques/T1543.001/ T1543.001]
+[https://attack.mitre.org/techniques/T1543.001/ T1543.001], 
+[https://attack.mitre.org/techniques/T1543/ T1543]
 |
-Launch Agent
+Launch Agent, 
+Create or Modify System Process
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -4731,10 +5284,13 @@ Detect signs of malicious payloads that may indicate that your environment has b
 | [[Documentation:ESSOC:detections:Detections#Detect_outlook_exe_writing_a_zip_file|Detect Outlook exe writing a zip file]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4742,10 +5298,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Excel_spawning_powershell|Excel Spawning PowerShell]]
 
 |
-[https://attack.mitre.org/techniques/T1003.002/ T1003.002]
+[https://attack.mitre.org/techniques/T1003.002/ T1003.002], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-Security Account Manager
+Security Account Manager, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -4753,10 +5312,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Excel_spawning_windows_script_host|Excel Spawning Windows Script Host]]
 
 |
-[https://attack.mitre.org/techniques/T1003.002/ T1003.002]
+[https://attack.mitre.org/techniques/T1003.002/ T1003.002], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-Security Account Manager
+Security Account Manager, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -4764,10 +5326,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Mshtml_module_load_in_office_product|MSHTML Module Load in Office Product]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4775,10 +5340,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_application_spawn_rundll32_process|Office Application Spawn rundll32 process]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4786,10 +5354,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_document_creating_schedule_task|Office Document Creating Schedule Task]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4797,10 +5368,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_document_executing_macro_code|Office Document Executing Macro Code]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4808,10 +5382,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_document_spawned_child_process_to_download|Office Document Spawned Child Process To Download]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4819,10 +5396,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_product_spawning_bitsadmin|Office Product Spawning BITSAdmin]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4830,10 +5410,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_product_spawning_certutil|Office Product Spawning CertUtil]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4841,10 +5424,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_product_spawning_mshta|Office Product Spawning MSHTA]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4852,10 +5438,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_product_spawning_rundll32_with_no_dll|Office Product Spawning Rundll32 with no DLL]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4863,10 +5452,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_product_spawning_wmic|Office Product Spawning Wmic]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4874,10 +5466,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_product_writing_cab_or_inf|Office Product Writing cab or inf]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4885,10 +5480,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_spawning_control|Office Spawning Control]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4896,10 +5494,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Process_creating_lnk_file_in_suspicious_location|Process Creating LNK file in Suspicious Location]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.002/ T1566.002]
 |
+Phishing, 
 Spearphishing Link
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4907,10 +5508,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Winword_spawning_cmd|Winword Spawning Cmd]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4918,10 +5522,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Winword_spawning_powershell|Winword Spawning PowerShell]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -4969,10 +5576,13 @@ Leveraging the Windows command-line interface (CLI) is one of the most common at
 | [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.003/ T1059.003]
 |
+Command and Scripting Interpreter, 
 Windows Command Shell
 |
+Execution, 
 Execution
 
 | Hunting
@@ -4991,10 +5601,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Detect_use_of_cmd_exe_to_launch_script_interpreters|Detect Use of cmd exe to Launch Script Interpreters]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.003/ T1059.003]
 |
+Command and Scripting Interpreter, 
 Windows Command Shell
 |
+Execution, 
 Execution
 
 | TTP
@@ -5002,10 +5615,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#System_processes_run_from_unexpected_locations|System Processes Run From Unexpected Locations]]
 
 |
+[https://attack.mitre.org/techniques/T1036/ T1036], 
 [https://attack.mitre.org/techniques/T1036.003/ T1036.003]
 |
+Masquerading, 
 Rename System Utilities
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5071,10 +5687,13 @@ Monitor and detect techniques used by attackers who leverage the mshta.exe proce
 | [[Documentation:ESSOC:detections:Detections#Detect_html_help_renamed|Detect HTML Help Renamed]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.001/ T1218.001]
 |
+Signed Binary Proxy Execution, 
 Compiled HTML File
 |
+Defense Evasion, 
 Defense Evasion
 
 | Hunting
@@ -5082,10 +5701,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_html_help_spawn_child_process|Detect HTML Help Spawn Child Process]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.001/ T1218.001]
 |
+Signed Binary Proxy Execution, 
 Compiled HTML File
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5093,10 +5715,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_html_help_url_in_command_line|Detect HTML Help URL in Command Line]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.001/ T1218.001]
 |
+Signed Binary Proxy Execution, 
 Compiled HTML File
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5104,10 +5729,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_html_help_using_infotech_storage_handlers|Detect HTML Help Using InfoTech Storage Handlers]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.001/ T1218.001]
 |
+Signed Binary Proxy Execution, 
 Compiled HTML File
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5166,10 +5794,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Dns_query_length_outliers_-_mltk|DNS Query Length Outliers - MLTK]]
 
 |
-[https://attack.mitre.org/techniques/T1071.004/ T1071.004]
+[https://attack.mitre.org/techniques/T1071.004/ T1071.004], 
+[https://attack.mitre.org/techniques/T1071/ T1071]
 |
-DNS
+DNS, 
+Application Layer Protocol
 |
+Command And Control, 
 Command And Control
 
 | Anomaly
@@ -5177,10 +5808,13 @@ Command And Control
 | [[Documentation:ESSOC:detections:Detections#Dns_query_length_with_high_standard_deviation|DNS Query Length With High Standard Deviation]]
 
 |
-[https://attack.mitre.org/techniques/T1048.003/ T1048.003]
+[https://attack.mitre.org/techniques/T1048.003/ T1048.003], 
+[https://attack.mitre.org/techniques/T1048/ T1048]
 |
-Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
+Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, 
+Exfiltration Over Alternative Protocol
 |
+Exfiltration, 
 Exfiltration
 
 | Anomaly
@@ -5199,10 +5833,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Excessive_dns_failures|Excessive DNS Failures]]
 
 |
-[https://attack.mitre.org/techniques/T1071.004/ T1071.004]
+[https://attack.mitre.org/techniques/T1071.004/ T1071.004], 
+[https://attack.mitre.org/techniques/T1071/ T1071]
 |
-DNS
+DNS, 
+Application Layer Protocol
 |
+Command And Control, 
 Command And Control
 
 | Anomaly
@@ -5281,10 +5918,13 @@ Email remains one of the primary means for attackers to gain an initial foothold
 | [[Documentation:ESSOC:detections:Detections#Suspicious_email_attachment_extensions|Suspicious Email Attachment Extensions]]
 
 |
-[https://attack.mitre.org/techniques/T1566.001/ T1566.001]
+[https://attack.mitre.org/techniques/T1566.001/ T1566.001], 
+[https://attack.mitre.org/techniques/T1566/ T1566]
 |
-Spearphishing Attachment
+Spearphishing Attachment, 
+Phishing
 |
+Initial Access, 
 Initial Access
 
 | Anomaly
@@ -5328,10 +5968,13 @@ Monitor and detect techniques used by attackers who leverage the mshta.exe proce
 | [[Documentation:ESSOC:detections:Detections#Detect_mshta_url_in_command_line|Detect MSHTA Url in Command Line]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.005/ T1218.005]
 |
+Signed Binary Proxy Execution, 
 Mshta
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5339,10 +5982,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.003/ T1059.003]
 |
+Command and Scripting Interpreter, 
 Windows Command Shell
 |
+Execution, 
 Execution
 
 | Hunting
@@ -5361,10 +6007,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Detect_rundll32_inline_hta_execution|Detect Rundll32 Inline HTA Execution]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.005/ T1218.005]
 |
+Signed Binary Proxy Execution, 
 Mshta
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5372,10 +6021,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_mshta_inline_hta_execution|Detect mshta inline hta execution]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.005/ T1218.005]
 |
+Signed Binary Proxy Execution, 
 Mshta
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5383,10 +6035,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_mshta_renamed|Detect mshta renamed]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.005/ T1218.005]
 |
+Signed Binary Proxy Execution, 
 Mshta
 |
+Defense Evasion, 
 Defense Evasion
 
 | Hunting
@@ -5394,10 +6049,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]]
 
 |
-[https://attack.mitre.org/techniques/T1547.001/ T1547.001]
+[https://attack.mitre.org/techniques/T1547.001/ T1547.001], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Registry Run Keys / Startup Folder
+Registry Run Keys / Startup Folder, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -5405,10 +6063,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Suspicious_mshta_child_process|Suspicious mshta child process]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.005/ T1218.005]
 |
+Signed Binary Proxy Execution, 
 Mshta
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5416,10 +6077,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_mshta_spawn|Suspicious mshta spawn]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.005/ T1218.005]
 |
+Signed Binary Proxy Execution, 
 Mshta
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5471,10 +6135,13 @@ Monitor your Okta environment for suspicious activities. Due to the Covid outbre
 | [[Documentation:ESSOC:detections:Detections#Multiple_okta_users_with_invalid_credentials_from_the_same_ip|Multiple Okta Users With Invalid Credentials From The Same IP]]
 
 |
+[https://attack.mitre.org/techniques/T1078/ T1078], 
 [https://attack.mitre.org/techniques/T1078.001/ T1078.001]
 |
+Valid Accounts, 
 Default Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | TTP
@@ -5482,10 +6149,13 @@ Defense Evasion, Persistence, Privilege Escalation, Initial Access
 | [[Documentation:ESSOC:detections:Detections#Okta_account_lockout_events|Okta Account Lockout Events]]
 
 |
+[https://attack.mitre.org/techniques/T1078/ T1078], 
 [https://attack.mitre.org/techniques/T1078.001/ T1078.001]
 |
+Valid Accounts, 
 Default Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | Anomaly
@@ -5493,10 +6163,13 @@ Defense Evasion, Persistence, Privilege Escalation, Initial Access
 | [[Documentation:ESSOC:detections:Detections#Okta_failed_sso_attempts|Okta Failed SSO Attempts]]
 
 |
+[https://attack.mitre.org/techniques/T1078/ T1078], 
 [https://attack.mitre.org/techniques/T1078.001/ T1078.001]
 |
+Valid Accounts, 
 Default Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | Anomaly
@@ -5504,10 +6177,13 @@ Defense Evasion, Persistence, Privilege Escalation, Initial Access
 | [[Documentation:ESSOC:detections:Detections#Okta_user_logins_from_multiple_cities|Okta User Logins From Multiple Cities]]
 
 |
+[https://attack.mitre.org/techniques/T1078/ T1078], 
 [https://attack.mitre.org/techniques/T1078.001/ T1078.001]
 |
+Valid Accounts, 
 Default Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | Anomaly
@@ -5553,10 +6229,13 @@ Monitor and detect techniques used by attackers who leverage the mshta.exe proce
 | [[Documentation:ESSOC:detections:Detections#Detect_regasm_spawning_a_process|Detect Regasm Spawning a Process]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.009/ T1218.009]
 |
+Signed Binary Proxy Execution, 
 Regsvcs/Regasm
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5564,10 +6243,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_regasm_with_network_connection|Detect Regasm with Network Connection]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.009/ T1218.009]
 |
+Signed Binary Proxy Execution, 
 Regsvcs/Regasm
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5575,10 +6257,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_regasm_with_no_command_line_arguments|Detect Regasm with no Command Line Arguments]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.009/ T1218.009]
 |
+Signed Binary Proxy Execution, 
 Regsvcs/Regasm
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5586,10 +6271,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_regsvcs_spawning_a_process|Detect Regsvcs Spawning a Process]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.009/ T1218.009]
 |
+Signed Binary Proxy Execution, 
 Regsvcs/Regasm
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5597,10 +6285,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_regsvcs_with_network_connection|Detect Regsvcs with Network Connection]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.009/ T1218.009]
 |
+Signed Binary Proxy Execution, 
 Regsvcs/Regasm
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5608,10 +6299,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_regsvcs_with_no_command_line_arguments|Detect Regsvcs with No Command Line Arguments]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.009/ T1218.009]
 |
+Signed Binary Proxy Execution, 
 Regsvcs/Regasm
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5659,10 +6353,41 @@ Monitor and detect techniques used by attackers who leverage the regsvr32.exe pr
 | [[Documentation:ESSOC:detections:Detections#Detect_regsvr32_application_control_bypass|Detect Regsvr32 Application Control Bypass]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.010/ T1218.010]
 |
+Signed Binary Proxy Execution, 
 Regsvr32
 |
+Defense Evasion, 
+Defense Evasion
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Malicious_inprocserver32_modification|Malicious InProcServer32 Modification]]
+
+|
+[https://attack.mitre.org/techniques/T1218.010/ T1218.010], 
+[https://attack.mitre.org/techniques/T1112/ T1112]
+|
+Regsvr32, 
+Modify Registry
+|
+Defense Evasion, 
+Defense Evasion
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Regsvr32_silent_param_dll_loading|Regsvr32 Silent Param Dll Loading]]
+
+|
+[https://attack.mitre.org/techniques/T1218/ T1218], 
+[https://attack.mitre.org/techniques/T1218.010/ T1218.010]
+|
+Signed Binary Proxy Execution, 
+Regsvr32
+|
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5670,10 +6395,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_regsvr32_register_suspicious_path|Suspicious Regsvr32 Register Suspicious Path]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.010/ T1218.010]
 |
+Signed Binary Proxy Execution, 
 Regsvr32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5683,6 +6411,8 @@ Defense Evasion
 
 * Actions on Objectives
 
+* Exploitation
+
 
 ====Reference====
 
@@ -5721,10 +6451,13 @@ Monitor and detect techniques used by attackers who leverage rundll32.exe to exe
 | [[Documentation:ESSOC:detections:Detections#Detect_rundll32_application_control_bypass_-_advpack|Detect Rundll32 Application Control Bypass - advpack]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5732,10 +6465,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_rundll32_application_control_bypass_-_setupapi|Detect Rundll32 Application Control Bypass - setupapi]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5743,10 +6479,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Detect_rundll32_application_control_bypass_-_syssetup|Detect Rundll32 Application Control Bypass - syssetup]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5754,10 +6493,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_comsvcs_dll|Dump LSASS via comsvcs DLL]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -5765,10 +6507,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Rundll32_control_rundll_hunt|Rundll32 Control RunDLL Hunt]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | Hunting
@@ -5776,10 +6521,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Rundll32_control_rundll_world_writable_directory|Rundll32 Control RunDLL World Writable Directory]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5787,10 +6535,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Rundll32_with_no_command_line_arguments_with_network|Rundll32 with no Command Line Arguments with Network]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5798,13 +6549,19 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_rename|Suspicious Rundll32 Rename]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
+[https://attack.mitre.org/techniques/T1036/ T1036], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011], 
 [https://attack.mitre.org/techniques/T1036.003/ T1036.003]
 |
+Signed Binary Proxy Execution, 
+Masquerading, 
 Rundll32, 
 Rename System Utilities
 |
 Defense Evasion, 
+Defense Evasion, 
+Defense Evasion, 
 Defense Evasion
 
 | Hunting
@@ -5812,10 +6569,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_startw|Suspicious Rundll32 StartW]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5823,10 +6583,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_dllregisterserver|Suspicious Rundll32 dllregisterserver]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5834,10 +6597,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_no_command_line_arguments|Suspicious Rundll32 no Command Line Arguments]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -5887,10 +6653,13 @@ Attackers are increasingly abusing Windows Management Instrumentation (WMI), a f
 | [[Documentation:ESSOC:detections:Detections#Detect_wmi_event_subscription_persistence|Detect WMI Event Subscription Persistence]]
 
 |
-[https://attack.mitre.org/techniques/T1546.003/ T1546.003]
+[https://attack.mitre.org/techniques/T1546.003/ T1546.003], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
 |
-Windows Management Instrumentation Event Subscription
+Windows Management Instrumentation Event Subscription, 
+Event Triggered Execution
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
 | TTP
@@ -5953,10 +6722,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Wmi_permanent_event_subscription_-_sysmon|WMI Permanent Event Subscription - Sysmon]]
 
 |
-[https://attack.mitre.org/techniques/T1546.003/ T1546.003]
+[https://attack.mitre.org/techniques/T1546.003/ T1546.003], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
 |
-Windows Management Instrumentation Event Subscription
+Windows Management Instrumentation Event Subscription, 
+Event Triggered Execution
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
 | TTP
@@ -6012,13 +6784,30 @@ Monitor and detect registry changes initiated from remote locations, which can b
 ! Tactic
 ! Type
 |-
+| [[Documentation:ESSOC:detections:Detections#Disable_uac_remote_restriction|Disable UAC Remote Restriction]]
+
+|
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
+|
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
+|
+Privilege Escalation, Defense Evasion, 
+Privilege Escalation, Defense Evasion
+
+| TTP
+|-
 | [[Documentation:ESSOC:detections:Detections#Disabling_remote_user_account_control|Disabling Remote User Account Control]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -6026,10 +6815,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Monitor_registry_keys_for_print_monitors|Monitor Registry Keys for Print Monitors]]
 
 |
-[https://attack.mitre.org/techniques/T1547.010/ T1547.010]
+[https://attack.mitre.org/techniques/T1547.010/ T1547.010], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Port Monitors
+Port Monitors, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -6037,10 +6829,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]]
 
 |
-[https://attack.mitre.org/techniques/T1547.001/ T1547.001]
+[https://attack.mitre.org/techniques/T1547.001/ T1547.001], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Registry Run Keys / Startup Folder
+Registry Run Keys / Startup Folder, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -6048,10 +6843,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_privilege_escalation|Registry Keys Used For Privilege Escalation]]
 
 |
-[https://attack.mitre.org/techniques/T1546.012/ T1546.012]
+[https://attack.mitre.org/techniques/T1546.012/ T1546.012], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
 |
-Image File Execution Options Injection
+Image File Execution Options Injection, 
+Event Triggered Execution
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
 | TTP
@@ -6059,10 +6857,13 @@ Privilege Escalation, Persistence
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_for_creating_shim_databases|Registry Keys for Creating SHIM Databases]]
 
 |
-[https://attack.mitre.org/techniques/T1546.011/ T1546.011]
+[https://attack.mitre.org/techniques/T1546.011/ T1546.011], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
 |
-Application Shimming
+Application Shimming, 
+Event Triggered Execution
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
 | TTP
@@ -6072,6 +6873,8 @@ Privilege Escalation, Persistence
 
 * Actions on Objectives
 
+* Exploitation
+
 
 ====Reference====
 
@@ -6108,10 +6911,13 @@ Attackers are using Zoom as an vector to increase privileges on a sytems. This s
 | [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.003/ T1059.003]
 |
+Command and Scripting Interpreter, 
 Windows Command Shell
 |
+Execution, 
 Execution
 
 | Hunting
@@ -6181,13 +6987,16 @@ Monitor and detect behaviors used by attackers who leverage trusted developer ut
 | [[Documentation:ESSOC:detections:Detections#Suspicious_microsoft_workflow_compiler_rename|Suspicious microsoft workflow compiler rename]]
 
 |
+[https://attack.mitre.org/techniques/T1036/ T1036], 
 [https://attack.mitre.org/techniques/T1127/ T1127], 
 [https://attack.mitre.org/techniques/T1036.003/ T1036.003]
 |
+Masquerading, 
 Trusted Developer Utilities Proxy Execution, 
 Rename System Utilities
 |
 Defense Evasion, 
+Defense Evasion, 
 Defense Evasion
 
 | Hunting
@@ -6243,27 +7052,50 @@ Monitor and detect techniques used by attackers who leverage the msbuild.exe pro
 ! Tactic
 ! Type
 |-
-| [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_rename|Suspicious MSBuild Rename]]
+| [[Documentation:ESSOC:detections:Detections#Msbuild_suspicious_spawned_by_script_process|MSBuild Suspicious Spawned By Script Process]]
 
 |
 [https://attack.mitre.org/techniques/T1127.001/ T1127.001], 
-[https://attack.mitre.org/techniques/T1036.003/ T1036.003]
+[https://attack.mitre.org/techniques/T1127/ T1127]
 |
 MSBuild, 
-Rename System Utilities
+Trusted Developer Utilities Proxy Execution
 |
 Defense Evasion, 
 Defense Evasion
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_rename|Suspicious MSBuild Rename]]
+
+|
+[https://attack.mitre.org/techniques/T1036/ T1036], 
+[https://attack.mitre.org/techniques/T1127/ T1127], 
+[https://attack.mitre.org/techniques/T1036.003/ T1036.003], 
+[https://attack.mitre.org/techniques/T1127.001/ T1127.001]
+|
+Masquerading, 
+Trusted Developer Utilities Proxy Execution, 
+Rename System Utilities, 
+MSBuild
+|
+Defense Evasion, 
+Defense Evasion, 
+Defense Evasion, 
+Defense Evasion
+
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_spawn|Suspicious MSBuild Spawn]]
 
 |
+[https://attack.mitre.org/techniques/T1127/ T1127], 
 [https://attack.mitre.org/techniques/T1127.001/ T1127.001]
 |
+Trusted Developer Utilities Proxy Execution, 
 MSBuild
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6271,13 +7103,19 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_path|Suspicious msbuild path]]
 
 |
-[https://attack.mitre.org/techniques/T1127.001/ T1127.001], 
-[https://attack.mitre.org/techniques/T1036.003/ T1036.003]
+[https://attack.mitre.org/techniques/T1036/ T1036], 
+[https://attack.mitre.org/techniques/T1127/ T1127], 
+[https://attack.mitre.org/techniques/T1036.003/ T1036.003], 
+[https://attack.mitre.org/techniques/T1127.001/ T1127.001]
 |
-MSBuild, 
-Rename System Utilities
+Masquerading, 
+Trusted Developer Utilities Proxy Execution, 
+Rename System Utilities, 
+MSBuild
 |
 Defense Evasion, 
+Defense Evasion, 
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6391,9 +7229,23 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of
 | [[Documentation:ESSOC:detections:Detections#Disable_registry_tool|Disable Registry Tool]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
+|
+Defense Evasion, 
+Defense Evasion
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Disable_security_logs_using_minint_registry|Disable Security Logs Using MiniNt Registry]]
+
+|
+[https://attack.mitre.org/techniques/T1112/ T1112]
+|
+Modify Registry
 |
 Defense Evasion
 
@@ -6403,23 +7255,46 @@ Defense Evasion
 
 |
 [https://attack.mitre.org/techniques/T1564.001/ T1564.001], 
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1564/ T1564], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
 Hidden Files and Directories, 
-Disable or Modify Tools
+Disable or Modify Tools, 
+Hide Artifacts, 
+Impair Defenses
 |
 Defense Evasion, 
+Defense Evasion, 
+Defense Evasion, 
 Defense Evasion
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Disable_uac_remote_restriction|Disable UAC Remote Restriction]]
+
+|
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
+|
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
+|
+Privilege Escalation, Defense Evasion, 
+Privilege Escalation, Defense Evasion
+
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Disable_windows_behavior_monitoring|Disable Windows Behavior Monitoring]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6427,10 +7302,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Disable_windows_smartscreen_protection|Disable Windows SmartScreen Protection]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6438,10 +7316,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Disabling_cmd_application|Disabling CMD Application]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6449,10 +7330,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Disabling_controlpanel|Disabling ControlPanel]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6460,10 +7344,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Disabling_firewall_with_netsh|Disabling Firewall with Netsh]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6471,10 +7358,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Disabling_folderoptions_windows_feature|Disabling FolderOptions Windows Feature]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6482,10 +7372,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Disabling_norun_windows_app|Disabling NoRun Windows App]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6493,10 +7386,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Disabling_remote_user_account_control|Disabling Remote User Account Control]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -6504,10 +7400,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Disabling_systemrestore_in_registry|Disabling SystemRestore In Registry]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6515,10 +7414,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Disabling_task_manager|Disabling Task Manager]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6526,10 +7428,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Eventvwr_uac_bypass|Eventvwr UAC Bypass]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -6537,10 +7442,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Excessive_number_of_service_control_start_as_disabled|Excessive number of service control start as disabled]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | Anomaly
@@ -6549,12 +7457,15 @@ Defense Evasion
 
 |
 [https://attack.mitre.org/techniques/T1112/ T1112], 
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
 Modify Registry, 
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
 Defense Evasion, 
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -6562,10 +7473,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Hiding_files_and_directories_with_attrib_exe|Hiding Files And Directories With Attrib exe]]
 
 |
+[https://attack.mitre.org/techniques/T1222/ T1222], 
 [https://attack.mitre.org/techniques/T1222.001/ T1222.001]
 |
+File and Directory Permissions Modification, 
 Windows File and Directory Permissions Modification
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6573,10 +7487,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Net_profiler_uac_bypass|NET Profiler UAC bypass]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -6584,10 +7501,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Slui_runas_elevated|SLUI RunAs Elevated]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -6595,10 +7515,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Slui_spawning_a_process|SLUI Spawning a Process]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -6606,10 +7529,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Sdclt_uac_bypass|Sdclt UAC Bypass]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -6617,10 +7543,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Silentcleanup_uac_bypass|SilentCleanup UAC Bypass]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -6650,10 +7579,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Uac_bypass_mmc_load_unsigned_dll|UAC Bypass MMC Load Unsigned Dll]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -6661,10 +7593,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Wsreset_uac_bypass|WSReset UAC Bypass]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -6672,10 +7607,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Windows_disableantispyware_registry|Windows DisableAntiSpyware Registry]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -6810,32 +7748,35 @@ Reconnaissance
 | [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules|Reconnaissance and Access to Operating System Elements via PowerSploit modules]]
 
 |
-[https://attack.mitre.org/techniques/T1007/ T1007], 
-[https://attack.mitre.org/techniques/T1012/ T1012], 
-[https://attack.mitre.org/techniques/T1046/ T1046], 
-[https://attack.mitre.org/techniques/T1047/ T1047], 
 [https://attack.mitre.org/techniques/T1057/ T1057], 
 [https://attack.mitre.org/techniques/T1083/ T1083], 
-[https://attack.mitre.org/techniques/T1518/ T1518], 
-[https://attack.mitre.org/techniques/T1592.002/ T1592.002]
+[https://attack.mitre.org/techniques/T1592.002/ T1592.002], 
+[https://attack.mitre.org/techniques/T1046/ T1046], 
+[https://attack.mitre.org/techniques/T1012/ T1012], 
+[https://attack.mitre.org/techniques/T1007/ T1007], 
+[https://attack.mitre.org/techniques/T1047/ T1047], 
+[https://attack.mitre.org/techniques/T1592/ T1592], 
+[https://attack.mitre.org/techniques/T1518/ T1518]
 |
-System Service Discovery, 
-Query Registry, 
-Network Service Scanning, 
-Windows Management Instrumentation, 
 Process Discovery, 
 File and Directory Discovery, 
-Software Discovery, 
-Software
+Software, 
+Network Service Scanning, 
+Query Registry, 
+System Service Discovery, 
+Windows Management Instrumentation, 
+Gather Victim Host Information, 
+Software Discovery
 |
 Discovery, 
 Discovery, 
+Reconnaissance, 
+Discovery, 
+Discovery, 
 Discovery, 
 Execution, 
-Discovery, 
-Discovery, 
-Discovery, 
-Reconnaissance
+Reconnaissance, 
+Discovery
 
 | TTP
 |-
@@ -6859,34 +7800,40 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_shared_resources_via_mimikatz_modules|Reconnaissance and Access to Shared Resources via Mimikatz modules]]
 
 |
-[https://attack.mitre.org/techniques/T1021.002/ T1021.002], 
+[https://attack.mitre.org/techniques/T1021/ T1021], 
+[https://attack.mitre.org/techniques/T1039/ T1039], 
 [https://attack.mitre.org/techniques/T1135/ T1135], 
-[https://attack.mitre.org/techniques/T1039/ T1039]
+[https://attack.mitre.org/techniques/T1021.002/ T1021.002]
 |
-SMB/Windows Admin Shares, 
+Remote Services, 
+Data from Network Shared Drive, 
 Network Share Discovery, 
-Data from Network Shared Drive
+SMB/Windows Admin Shares
 |
 Lateral Movement, 
+Collection, 
 Discovery, 
-Collection
+Lateral Movement
 
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_shared_resources_via_powersploit_modules|Reconnaissance and Access to Shared Resources via PowerSploit modules]]
 
 |
-[https://attack.mitre.org/techniques/T1021.002/ T1021.002], 
+[https://attack.mitre.org/techniques/T1021/ T1021], 
+[https://attack.mitre.org/techniques/T1039/ T1039], 
 [https://attack.mitre.org/techniques/T1135/ T1135], 
-[https://attack.mitre.org/techniques/T1039/ T1039]
+[https://attack.mitre.org/techniques/T1021.002/ T1021.002]
 |
-SMB/Windows Admin Shares, 
+Remote Services, 
+Data from Network Shared Drive, 
 Network Share Discovery, 
-Data from Network Shared Drive
+SMB/Windows Admin Shares
 |
 Lateral Movement, 
+Collection, 
 Discovery, 
-Collection
+Lateral Movement
 
 | TTP
 |-
@@ -6919,56 +7866,71 @@ Persistence, Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_connectivity_via_powersploit_modules|Reconnaissance of Connectivity via PowerSploit modules]]
 
 |
-[https://attack.mitre.org/techniques/T1021.002/ T1021.002], 
+[https://attack.mitre.org/techniques/T1021/ T1021], 
+[https://attack.mitre.org/techniques/T1039/ T1039], 
 [https://attack.mitre.org/techniques/T1135/ T1135], 
-[https://attack.mitre.org/techniques/T1039/ T1039]
+[https://attack.mitre.org/techniques/T1021.002/ T1021.002]
 |
-SMB/Windows Admin Shares, 
+Remote Services, 
+Data from Network Shared Drive, 
 Network Share Discovery, 
-Data from Network Shared Drive
+SMB/Windows Admin Shares
 |
 Lateral Movement, 
+Collection, 
 Discovery, 
-Collection
+Lateral Movement
 
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_credential_stores_and_services_via_mimikatz_modules|Reconnaissance of Credential Stores and Services via Mimikatz modules]]
 
 |
-[https://attack.mitre.org/techniques/T1589.001/ T1589.001], 
+[https://attack.mitre.org/techniques/T1098/ T1098], 
 [https://attack.mitre.org/techniques/T1590.001/ T1590.001], 
-[https://attack.mitre.org/techniques/T1590.003/ T1590.003], 
-[https://attack.mitre.org/techniques/T1068/ T1068], 
 [https://attack.mitre.org/techniques/T1078/ T1078], 
-[https://attack.mitre.org/techniques/T1098/ T1098]
+[https://attack.mitre.org/techniques/T1589.001/ T1589.001], 
+[https://attack.mitre.org/techniques/T1590/ T1590], 
+[https://attack.mitre.org/techniques/T1068/ T1068], 
+[https://attack.mitre.org/techniques/T1589/ T1589], 
+[https://attack.mitre.org/techniques/T1590.003/ T1590.003]
 |
-Credentials, 
+Account Manipulation, 
 Domain Properties, 
-Network Trust Dependencies, 
-Exploitation for Privilege Escalation, 
 Valid Accounts, 
-Account Manipulation
+Credentials, 
+Gather Victim Network Information, 
+Exploitation for Privilege Escalation, 
+Gather Victim Identity Information, 
+Network Trust Dependencies
 |
+Persistence, 
 Reconnaissance, 
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Reconnaissance, 
 Reconnaissance, 
 Privilege Escalation, 
-Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
-Persistence
+Reconnaissance, 
+Reconnaissance
 
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_defensive_tools_via_powersploit_modules|Reconnaissance of Defensive Tools via PowerSploit modules]]
 
 |
+[https://attack.mitre.org/techniques/T1592.002/ T1592.002], 
 [https://attack.mitre.org/techniques/T1595.002/ T1595.002], 
-[https://attack.mitre.org/techniques/T1592.002/ T1592.002]
+[https://attack.mitre.org/techniques/T1592/ T1592], 
+[https://attack.mitre.org/techniques/T1595/ T1595]
 |
+Software, 
 Vulnerability Scanning, 
-Software
+Gather Victim Host Information, 
+Active Scanning
 |
 Reconnaissance, 
+Reconnaissance, 
+Reconnaissance, 
 Reconnaissance
 
 | TTP
@@ -7072,10 +8034,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_event_log_service_behavior|Suspicious Event Log Service Behavior]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -7083,10 +8048,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_wevtutil_usage|Suspicious wevtutil Usage]]
 
 |
-[https://attack.mitre.org/techniques/T1070.001/ T1070.001]
+[https://attack.mitre.org/techniques/T1070.001/ T1070.001], 
+[https://attack.mitre.org/techniques/T1070/ T1070]
 |
-Clear Windows Event Logs
+Clear Windows Event Logs, 
+Indicator Removal on Host
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -7105,10 +8073,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Wevtutil_usage_to_clear_logs|WevtUtil Usage To Clear Logs]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -7116,10 +8087,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Wevtutil_usage_to_disable_logs|Wevtutil Usage To Disable Logs]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -7127,10 +8101,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Windows_event_log_cleared|Windows Event Log Cleared]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -7177,32 +8154,83 @@ Monitor for activities and techniques associated with maintaining persistence on
 ! Tactic
 ! Type
 |-
+| [[Documentation:ESSOC:detections:Detections#Active_setup_registry_autostart|Active Setup Registry Autostart]]
+
+|
+[https://attack.mitre.org/techniques/T1547.014/ T1547.014], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
+|
+Active Setup, 
+Boot or Logon Autostart Execution
+|
+Persistence, Privilege Escalation, 
+Persistence, Privilege Escalation
+
+| TTP
+|-
 | [[Documentation:ESSOC:detections:Detections#Certutil_exe_certificate_extraction|Certutil exe certificate extraction]]
 
 |
 |
 |
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Change_default_file_association|Change Default File Association]]
+
+|
+[https://attack.mitre.org/techniques/T1546.001/ T1546.001], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
+|
+Change Default File Association, 
+Event Triggered Execution
+|
+Privilege Escalation, Persistence, 
+Privilege Escalation, Persistence
+
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Detect_path_interception_by_creation_of_program_exe|Detect Path Interception By Creation Of program exe]]
 
 |
-[https://attack.mitre.org/techniques/T1574.009/ T1574.009]
+[https://attack.mitre.org/techniques/T1574.009/ T1574.009], 
+[https://attack.mitre.org/techniques/T1574/ T1574]
 |
-Path Interception by Unquoted Path
+Path Interception by Unquoted Path, 
+Hijack Execution Flow
 |
+Persistence, Privilege Escalation, Defense Evasion, 
 Persistence, Privilege Escalation, Defense Evasion
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Etw_registry_disabled|ETW Registry Disabled]]
+
+|
+[https://attack.mitre.org/techniques/T1562.006/ T1562.006], 
+[https://attack.mitre.org/techniques/T1127/ T1127], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
+|
+Indicator Blocking, 
+Trusted Developer Utilities Proxy Execution, 
+Impair Defenses
+|
+Defense Evasion, 
+Defense Evasion, 
+Defense Evasion
+
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Hiding_files_and_directories_with_attrib_exe|Hiding Files And Directories With Attrib exe]]
 
 |
+[https://attack.mitre.org/techniques/T1222/ T1222], 
 [https://attack.mitre.org/techniques/T1222.001/ T1222.001]
 |
+File and Directory Permissions Modification, 
 Windows File and Directory Permissions Modification
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -7281,15 +8309,46 @@ Execution, Persistence, Privilege Escalation,
 Defense Evasion, Privilege Escalation, 
 Privilege Escalation, Defense Evasion
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Logon_script_event_trigger_execution|Logon Script Event Trigger Execution]]
+
+|
+[https://attack.mitre.org/techniques/T1037/ T1037], 
+[https://attack.mitre.org/techniques/T1037.001/ T1037.001]
+|
+Boot or Logon Initialization Scripts, 
+Logon Script (Windows)
+|
+Persistence, Privilege Escalation, 
+Persistence, Privilege Escalation
+
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Monitor_registry_keys_for_print_monitors|Monitor Registry Keys for Print Monitors]]
 
 |
-[https://attack.mitre.org/techniques/T1547.010/ T1547.010]
+[https://attack.mitre.org/techniques/T1547.010/ T1547.010], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Port Monitors
+Port Monitors, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
+Persistence, Privilege Escalation
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Print_processor_registry_autostart|Print Processor Registry Autostart]]
+
+|
+[https://attack.mitre.org/techniques/T1547.012/ T1547.012], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
+|
+Print Processors, 
+Boot or Logon Autostart Execution
+|
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -7297,10 +8356,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Reg_exe_manipulating_windows_services_registry_keys|Reg exe Manipulating Windows Services Registry Keys]]
 
 |
-[https://attack.mitre.org/techniques/T1574.011/ T1574.011]
+[https://attack.mitre.org/techniques/T1574.011/ T1574.011], 
+[https://attack.mitre.org/techniques/T1574/ T1574]
 |
-Services Registry Permissions Weakness
+Services Registry Permissions Weakness, 
+Hijack Execution Flow
 |
+Persistence, Privilege Escalation, Defense Evasion, 
 Persistence, Privilege Escalation, Defense Evasion
 
 | TTP
@@ -7308,10 +8370,13 @@ Persistence, Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]]
 
 |
-[https://attack.mitre.org/techniques/T1547.001/ T1547.001]
+[https://attack.mitre.org/techniques/T1547.001/ T1547.001], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Registry Run Keys / Startup Folder
+Registry Run Keys / Startup Folder, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -7319,10 +8384,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_for_creating_shim_databases|Registry Keys for Creating SHIM Databases]]
 
 |
-[https://attack.mitre.org/techniques/T1546.011/ T1546.011]
+[https://attack.mitre.org/techniques/T1546.011/ T1546.011], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
 |
-Application Shimming
+Application Shimming, 
+Event Triggered Execution
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
 | TTP
@@ -7330,10 +8398,13 @@ Privilege Escalation, Persistence
 | [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]]
 
 |
-[https://attack.mitre.org/techniques/T1543.003/ T1543.003]
+[https://attack.mitre.org/techniques/T1543.003/ T1543.003], 
+[https://attack.mitre.org/techniques/T1543/ T1543]
 |
-Windows Service
+Windows Service, 
+Create or Modify System Process
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -7363,12 +8434,29 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Schtasks_used_for_forcing_a_reboot|Schtasks used for forcing a reboot]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Screensaver_event_trigger_execution|Screensaver Event Trigger Execution]]
+
+|
+[https://attack.mitre.org/techniques/T1546/ T1546], 
+[https://attack.mitre.org/techniques/T1546.002/ T1546.002]
+|
+Event Triggered Execution, 
+Screensaver
+|
+Privilege Escalation, Persistence, 
+Privilege Escalation, Persistence
+
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Setting_credentials_via_dsinternals_modules|Setting Credentials via DSInternals modules]]
@@ -7425,10 +8513,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#Shim_database_file_creation|Shim Database File Creation]]
 
 |
-[https://attack.mitre.org/techniques/T1546.011/ T1546.011]
+[https://attack.mitre.org/techniques/T1546.011/ T1546.011], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
 |
-Application Shimming
+Application Shimming, 
+Event Triggered Execution
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
 | TTP
@@ -7436,10 +8527,13 @@ Privilege Escalation, Persistence
 | [[Documentation:ESSOC:detections:Detections#Shim_database_installation_with_suspicious_parameters|Shim Database Installation With Suspicious Parameters]]
 
 |
-[https://attack.mitre.org/techniques/T1546.011/ T1546.011]
+[https://attack.mitre.org/techniques/T1546.011/ T1546.011], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
 |
-Application Shimming
+Application Shimming, 
+Event Triggered Execution
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
 | TTP
@@ -7447,21 +8541,41 @@ Privilege Escalation, Persistence
 | [[Documentation:ESSOC:detections:Detections#Suspicious_scheduled_task_from_public_directory|Suspicious Scheduled Task from Public Directory]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | Anomaly
 |-
+| [[Documentation:ESSOC:detections:Detections#Time_provider_persistence_registry|Time Provider Persistence Registry]]
+
+|
+[https://attack.mitre.org/techniques/T1547.003/ T1547.003], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
+|
+Time Providers, 
+Boot or Logon Autostart Execution
+|
+Persistence, Privilege Escalation, 
+Persistence, Privilege Escalation
+
+| TTP
+|-
 | [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -7469,10 +8583,13 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_to_spawn_shell|WinEvent Scheduled Task Created to Spawn Shell]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -7527,6 +8644,34 @@ Monitor for and investigate activities that may be associated with a Windows pri
 ! Tactic
 ! Type
 |-
+| [[Documentation:ESSOC:detections:Detections#Active_setup_registry_autostart|Active Setup Registry Autostart]]
+
+|
+[https://attack.mitre.org/techniques/T1547.014/ T1547.014], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
+|
+Active Setup, 
+Boot or Logon Autostart Execution
+|
+Persistence, Privilege Escalation, 
+Persistence, Privilege Escalation
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Change_default_file_association|Change Default File Association]]
+
+|
+[https://attack.mitre.org/techniques/T1546.001/ T1546.001], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
+|
+Change Default File Association, 
+Event Triggered Execution
+|
+Privilege Escalation, Persistence, 
+Privilege Escalation, Persistence
+
+| TTP
+|-
 | [[Documentation:ESSOC:detections:Detections#Child_processes_of_spoolsv_exe|Child Processes of Spoolsv exe]]
 
 |
@@ -7536,6 +8681,23 @@ Exploitation for Privilege Escalation
 |
 Privilege Escalation
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Etw_registry_disabled|ETW Registry Disabled]]
+
+|
+[https://attack.mitre.org/techniques/T1562.006/ T1562.006], 
+[https://attack.mitre.org/techniques/T1127/ T1127], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
+|
+Indicator Blocking, 
+Trusted Developer Utilities Proxy Execution, 
+Impair Defenses
+|
+Defense Evasion, 
+Defense Evasion, 
+Defense Evasion
+
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Illegal_privilege_elevation_via_mimikatz_modules|Illegal Privilege Elevation via Mimikatz modules]]
@@ -7550,17 +8712,48 @@ Abuse Elevation Control Mechanism
 Defense Evasion, Privilege Escalation, 
 Privilege Escalation, Defense Evasion
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Logon_script_event_trigger_execution|Logon Script Event Trigger Execution]]
+
+|
+[https://attack.mitre.org/techniques/T1037/ T1037], 
+[https://attack.mitre.org/techniques/T1037.001/ T1037.001]
+|
+Boot or Logon Initialization Scripts, 
+Logon Script (Windows)
+|
+Persistence, Privilege Escalation, 
+Persistence, Privilege Escalation
+
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Overwriting_accessibility_binaries|Overwriting Accessibility Binaries]]
 
 |
+[https://attack.mitre.org/techniques/T1546/ T1546], 
 [https://attack.mitre.org/techniques/T1546.008/ T1546.008]
 |
+Event Triggered Execution, 
 Accessibility Features
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Print_processor_registry_autostart|Print Processor Registry Autostart]]
+
+|
+[https://attack.mitre.org/techniques/T1547.012/ T1547.012], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
+|
+Print Processors, 
+Boot or Logon Autostart Execution
+|
+Persistence, Privilege Escalation, 
+Persistence, Privilege Escalation
+
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Probing_access_with_stolen_credentials_via_powersploit_modules|Probing Access with Stolen Credentials via PowerSploit modules]]
@@ -7580,12 +8773,43 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_privilege_escalation|Registry Keys Used For Privilege Escalation]]
 
 |
-[https://attack.mitre.org/techniques/T1546.012/ T1546.012]
+[https://attack.mitre.org/techniques/T1546.012/ T1546.012], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
 |
-Image File Execution Options Injection
+Image File Execution Options Injection, 
+Event Triggered Execution
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Screensaver_event_trigger_execution|Screensaver Event Trigger Execution]]
+
+|
+[https://attack.mitre.org/techniques/T1546/ T1546], 
+[https://attack.mitre.org/techniques/T1546.002/ T1546.002]
+|
+Event Triggered Execution, 
+Screensaver
+|
+Privilege Escalation, Persistence, 
+Privilege Escalation, Persistence
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Time_provider_persistence_registry|Time Provider Persistence Registry]]
+
+|
+[https://attack.mitre.org/techniques/T1547.003/ T1547.003], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
+|
+Time Providers, 
+Boot or Logon Autostart Execution
+|
+Persistence, Privilege Escalation, 
+Persistence, Privilege Escalation
+
 | TTP
 |}
 
@@ -7724,10 +8948,13 @@ Detect instances of prohibited network traffic allowed in the environment, as we
 | [[Documentation:ESSOC:detections:Detections#Allow_inbound_traffic_by_firewall_rule_registry|Allow Inbound Traffic By Firewall Rule Registry]]
 
 |
-[https://attack.mitre.org/techniques/T1021.001/ T1021.001]
+[https://attack.mitre.org/techniques/T1021.001/ T1021.001], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-Remote Desktop Protocol
+Remote Desktop Protocol, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | TTP
@@ -7735,10 +8962,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Allow_inbound_traffic_in_firewall_rule|Allow Inbound Traffic In Firewall Rule]]
 
 |
-[https://attack.mitre.org/techniques/T1021.001/ T1021.001]
+[https://attack.mitre.org/techniques/T1021.001/ T1021.001], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-Remote Desktop Protocol
+Remote Desktop Protocol, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | TTP
@@ -7779,10 +9009,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Protocol_or_port_mismatch|Protocol or Port Mismatch]]
 
 |
-[https://attack.mitre.org/techniques/T1048.003/ T1048.003]
+[https://attack.mitre.org/techniques/T1048.003/ T1048.003], 
+[https://attack.mitre.org/techniques/T1048/ T1048]
 |
-Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
+Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, 
+Exfiltration Over Alternative Protocol
 |
+Exfiltration, 
 Exfiltration
 
 | Anomaly
@@ -7790,10 +9023,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Tor_traffic|TOR Traffic]]
 
 |
+[https://attack.mitre.org/techniques/T1071/ T1071], 
 [https://attack.mitre.org/techniques/T1071.001/ T1071.001]
 |
+Application Layer Protocol, 
 Web Protocols
 |
+Command And Control, 
 Command And Control
 
 | TTP
@@ -7845,14 +9081,17 @@ Validate the security configuration of network infrastructure and verify that on
 |
 [https://attack.mitre.org/techniques/T1200/ T1200], 
 [https://attack.mitre.org/techniques/T1498/ T1498], 
+[https://attack.mitre.org/techniques/T1557/ T1557], 
 [https://attack.mitre.org/techniques/T1557.002/ T1557.002]
 |
 Hardware Additions, 
 Network Denial of Service, 
+Man-in-the-Middle, 
 ARP Cache Poisoning
 |
 Initial Access, 
 Impact, 
+Credential Access, Collection, 
 Credential Access, Collection
 
 | TTP
@@ -7862,14 +9101,17 @@ Credential Access, Collection
 |
 [https://attack.mitre.org/techniques/T1200/ T1200], 
 [https://attack.mitre.org/techniques/T1498/ T1498], 
+[https://attack.mitre.org/techniques/T1557/ T1557], 
 [https://attack.mitre.org/techniques/T1557.002/ T1557.002]
 |
 Hardware Additions, 
 Network Denial of Service, 
+Man-in-the-Middle, 
 ARP Cache Poisoning
 |
 Initial Access, 
 Impact, 
+Credential Access, Collection, 
 Credential Access, Collection
 
 | TTP
@@ -7887,14 +9129,17 @@ Credential Access, Collection
 |
 [https://attack.mitre.org/techniques/T1200/ T1200], 
 [https://attack.mitre.org/techniques/T1498/ T1498], 
+[https://attack.mitre.org/techniques/T1557/ T1557], 
 [https://attack.mitre.org/techniques/T1557.002/ T1557.002]
 |
 Hardware Additions, 
 Network Denial of Service, 
+Man-in-the-Middle, 
 ARP Cache Poisoning
 |
 Initial Access, 
 Impact, 
+Credential Access, Collection, 
 Credential Access, Collection
 
 | TTP
@@ -7919,10 +9164,13 @@ Credential Access, Collection
 | [[Documentation:ESSOC:detections:Detections#Detect_software_download_to_network_device|Detect Software Download To Network Device]]
 
 |
-[https://attack.mitre.org/techniques/T1542.005/ T1542.005]
+[https://attack.mitre.org/techniques/T1542.005/ T1542.005], 
+[https://attack.mitre.org/techniques/T1542/ T1542]
 |
-TFTP Boot
+TFTP Boot, 
+Pre-OS Boot
 |
+Defense Evasion, Persistence, 
 Defense Evasion, Persistence
 
 | TTP
@@ -7931,14 +9179,17 @@ Defense Evasion, Persistence
 
 |
 [https://attack.mitre.org/techniques/T1200/ T1200], 
+[https://attack.mitre.org/techniques/T1020/ T1020], 
 [https://attack.mitre.org/techniques/T1498/ T1498], 
 [https://attack.mitre.org/techniques/T1020.001/ T1020.001]
 |
 Hardware Additions, 
+Automated Exfiltration, 
 Network Denial of Service, 
 Traffic Duplication
 |
 Initial Access, 
+Exfiltration, 
 Impact, 
 Exfiltration
 
@@ -8133,10 +9384,13 @@ This analytic story contains detections that query your AWS Cloudtrail for activ
 | [[Documentation:ESSOC:detections:Detections#Aws_create_policy_version_to_allow_all_resources|AWS Create Policy Version to allow all resources]]
 
 |
-[https://attack.mitre.org/techniques/T1078.004/ T1078.004]
+[https://attack.mitre.org/techniques/T1078.004/ T1078.004], 
+[https://attack.mitre.org/techniques/T1078/ T1078]
 |
-Cloud Accounts
+Cloud Accounts, 
+Valid Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | TTP
@@ -8144,10 +9398,13 @@ Defense Evasion, Persistence, Privilege Escalation, Initial Access
 | [[Documentation:ESSOC:detections:Detections#Aws_createaccesskey|AWS CreateAccessKey]]
 
 |
-[https://attack.mitre.org/techniques/T1136.003/ T1136.003]
+[https://attack.mitre.org/techniques/T1136.003/ T1136.003], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Cloud Account
+Cloud Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | Hunting
@@ -8155,10 +9412,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#Aws_createloginprofile|AWS CreateLoginProfile]]
 
 |
-[https://attack.mitre.org/techniques/T1136.003/ T1136.003]
+[https://attack.mitre.org/techniques/T1136.003/ T1136.003], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Cloud Account
+Cloud Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -8203,23 +9463,29 @@ Persistence
 
 |
 [https://attack.mitre.org/techniques/T1069.003/ T1069.003], 
-[https://attack.mitre.org/techniques/T1098/ T1098]
+[https://attack.mitre.org/techniques/T1098/ T1098], 
+[https://attack.mitre.org/techniques/T1069/ T1069]
 |
 Cloud Groups, 
-Account Manipulation
+Account Manipulation, 
+Permission Groups Discovery
 |
 Discovery, 
-Persistence
+Persistence, 
+Discovery
 
 | Hunting
 |-
 | [[Documentation:ESSOC:detections:Detections#Aws_setdefaultpolicyversion|AWS SetDefaultPolicyVersion]]
 
 |
-[https://attack.mitre.org/techniques/T1078.004/ T1078.004]
+[https://attack.mitre.org/techniques/T1078.004/ T1078.004], 
+[https://attack.mitre.org/techniques/T1078/ T1078]
 |
-Cloud Accounts
+Cloud Accounts, 
+Valid Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | TTP
@@ -8227,10 +9493,13 @@ Defense Evasion, Persistence, Privilege Escalation, Initial Access
 | [[Documentation:ESSOC:detections:Detections#Aws_updateloginprofile|AWS UpdateLoginProfile]]
 
 |
-[https://attack.mitre.org/techniques/T1136.003/ T1136.003]
+[https://attack.mitre.org/techniques/T1136.003/ T1136.003], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Cloud Account
+Cloud Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -8280,10 +9549,13 @@ Monitor your AWS network infrastructure for bad configurations and malicious act
 | [[Documentation:ESSOC:detections:Detections#Aws_network_access_control_list_created_with_all_open_ports|AWS Network Access Control List Created with All Open Ports]]
 
 |
-[https://attack.mitre.org/techniques/T1562.007/ T1562.007]
+[https://attack.mitre.org/techniques/T1562.007/ T1562.007], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Cloud Firewall
+Disable or Modify Cloud Firewall, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -8291,10 +9563,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Aws_network_access_control_list_deleted|AWS Network Access Control List Deleted]]
 
 |
-[https://attack.mitre.org/techniques/T1562.007/ T1562.007]
+[https://attack.mitre.org/techniques/T1562.007/ T1562.007], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Cloud Firewall
+Disable or Modify Cloud Firewall, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | Anomaly
@@ -8449,10 +9724,13 @@ Monitor your cloud compute instances for activities related to cryptojacking/cry
 | [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_instances_launched|Abnormally High Number Of Cloud Instances Launched]]
 
 |
-[https://attack.mitre.org/techniques/T1078.004/ T1078.004]
+[https://attack.mitre.org/techniques/T1078.004/ T1078.004], 
+[https://attack.mitre.org/techniques/T1078/ T1078]
 |
-Cloud Accounts
+Cloud Accounts, 
+Valid Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | Anomaly
@@ -8460,10 +9738,13 @@ Defense Evasion, Persistence, Privilege Escalation, Initial Access
 | [[Documentation:ESSOC:detections:Detections#Cloud_compute_instance_created_by_previously_unseen_user|Cloud Compute Instance Created By Previously Unseen User]]
 
 |
-[https://attack.mitre.org/techniques/T1078.004/ T1078.004]
+[https://attack.mitre.org/techniques/T1078.004/ T1078.004], 
+[https://attack.mitre.org/techniques/T1078/ T1078]
 |
-Cloud Accounts
+Cloud Accounts, 
+Valid Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | Anomaly
@@ -8564,10 +9845,13 @@ Defense Evasion, Persistence, Privilege Escalation, Initial Access
 | [[Documentation:ESSOC:detections:Detections#Detect_mimikatz_using_loaded_images|Detect Mimikatz Using Loaded Images]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -8583,10 +9867,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#O365_add_app_role_assignment_grant_user|O365 Add App Role Assignment Grant User]]
 
 |
-[https://attack.mitre.org/techniques/T1136.003/ T1136.003]
+[https://attack.mitre.org/techniques/T1136.003/ T1136.003], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Cloud Account
+Cloud Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -8594,10 +9881,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#O365_added_service_principal|O365 Added Service Principal]]
 
 |
-[https://attack.mitre.org/techniques/T1136.003/ T1136.003]
+[https://attack.mitre.org/techniques/T1136.003/ T1136.003], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Cloud Account
+Cloud Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -8616,10 +9906,13 @@ Credential Access, Defense Evasion, Persistence
 | [[Documentation:ESSOC:detections:Detections#O365_new_federated_domain_added|O365 New Federated Domain Added]]
 
 |
-[https://attack.mitre.org/techniques/T1136.003/ T1136.003]
+[https://attack.mitre.org/techniques/T1136.003/ T1136.003], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Cloud Account
+Cloud Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -8627,10 +9920,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_privilege_escalation|Registry Keys Used For Privilege Escalation]]
 
 |
-[https://attack.mitre.org/techniques/T1546.012/ T1546.012]
+[https://attack.mitre.org/techniques/T1546.012/ T1546.012], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
 |
-Image File Execution Options Injection
+Image File Execution Options Injection, 
+Event Triggered Execution
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
 | TTP
@@ -8729,10 +10025,13 @@ This story is focused around detecting attacks on a DevSecOps lifeccycle which c
 | [[Documentation:ESSOC:detections:Detections#Aws_ecr_container_scanning_findings_high|AWS ECR Container Scanning Findings High]]
 
 |
-[https://attack.mitre.org/techniques/T1204.003/ T1204.003]
+[https://attack.mitre.org/techniques/T1204.003/ T1204.003], 
+[https://attack.mitre.org/techniques/T1204/ T1204]
 |
-Malicious Image
+Malicious Image, 
+User Execution
 |
+Execution, 
 Execution
 
 | TTP
@@ -8740,10 +10039,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Aws_ecr_container_scanning_findings_low_informational_unknown|AWS ECR Container Scanning Findings Low Informational Unknown]]
 
 |
-[https://attack.mitre.org/techniques/T1204.003/ T1204.003]
+[https://attack.mitre.org/techniques/T1204.003/ T1204.003], 
+[https://attack.mitre.org/techniques/T1204/ T1204]
 |
-Malicious Image
+Malicious Image, 
+User Execution
 |
+Execution, 
 Execution
 
 | Hunting
@@ -8751,10 +10053,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Aws_ecr_container_scanning_findings_medium|AWS ECR Container Scanning Findings Medium]]
 
 |
-[https://attack.mitre.org/techniques/T1204.003/ T1204.003]
+[https://attack.mitre.org/techniques/T1204.003/ T1204.003], 
+[https://attack.mitre.org/techniques/T1204/ T1204]
 |
-Malicious Image
+Malicious Image, 
+User Execution
 |
+Execution, 
 Execution
 
 | Anomaly
@@ -8762,10 +10067,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Aws_ecr_container_upload_outside_business_hours|AWS ECR Container Upload Outside Business Hours]]
 
 |
-[https://attack.mitre.org/techniques/T1204.003/ T1204.003]
+[https://attack.mitre.org/techniques/T1204.003/ T1204.003], 
+[https://attack.mitre.org/techniques/T1204/ T1204]
 |
-Malicious Image
+Malicious Image, 
+User Execution
 |
+Execution, 
 Execution
 
 | Anomaly
@@ -8773,10 +10081,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Aws_ecr_container_upload_unknown_user|AWS ECR Container Upload Unknown User]]
 
 |
-[https://attack.mitre.org/techniques/T1204.003/ T1204.003]
+[https://attack.mitre.org/techniques/T1204.003/ T1204.003], 
+[https://attack.mitre.org/techniques/T1204/ T1204]
 |
-Malicious Image
+Malicious Image, 
+User Execution
 |
+Execution, 
 Execution
 
 | Anomaly
@@ -8806,10 +10117,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#Correlation_by_repository_and_risk|Correlation by Repository and Risk]]
 
 |
-[https://attack.mitre.org/techniques/T1204.003/ T1204.003]
+[https://attack.mitre.org/techniques/T1204.003/ T1204.003], 
+[https://attack.mitre.org/techniques/T1204/ T1204]
 |
-Malicious Image
+Malicious Image, 
+User Execution
 |
+Execution, 
 Execution
 
 | Correlation
@@ -8817,21 +10131,41 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Correlation_by_user_and_risk|Correlation by User and Risk]]
 
 |
-[https://attack.mitre.org/techniques/T1204.003/ T1204.003]
+[https://attack.mitre.org/techniques/T1204.003/ T1204.003], 
+[https://attack.mitre.org/techniques/T1204/ T1204]
 |
-Malicious Image
+Malicious Image, 
+User Execution
 |
+Execution, 
 Execution
 
 | Correlation
 |-
+| [[Documentation:ESSOC:detections:Detections#Gsuite_email_suspicious_attachment|GSuite Email Suspicious Attachment]]
+
+|
+[https://attack.mitre.org/techniques/T1566.001/ T1566.001], 
+[https://attack.mitre.org/techniques/T1566/ T1566]
+|
+Spearphishing Attachment, 
+Phishing
+|
+Initial Access, 
+Initial Access
+
+| Anomaly
+|-
 | [[Documentation:ESSOC:detections:Detections#Github_dependabot_alert|GitHub Dependabot Alert]]
 
 |
-[https://attack.mitre.org/techniques/T1195.001/ T1195.001]
+[https://attack.mitre.org/techniques/T1195.001/ T1195.001], 
+[https://attack.mitre.org/techniques/T1195/ T1195]
 |
-Compromise Software Dependencies and Development Tools
+Compromise Software Dependencies and Development Tools, 
+Supply Chain Compromise
 |
+Initial Access, 
 Initial Access
 
 | Anomaly
@@ -8839,10 +10173,105 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Github_pull_request_from_unknown_user|GitHub Pull Request from Unknown User]]
 
 |
-[https://attack.mitre.org/techniques/T1195.001/ T1195.001]
+[https://attack.mitre.org/techniques/T1195.001/ T1195.001], 
+[https://attack.mitre.org/techniques/T1195/ T1195]
 |
-Compromise Software Dependencies and Development Tools
+Compromise Software Dependencies and Development Tools, 
+Supply Chain Compromise
 |
+Initial Access, 
+Initial Access
+
+| Anomaly
+|-
+| [[Documentation:ESSOC:detections:Detections#Github_commit_changes_in_master|Github Commit Changes In Master]]
+
+|
+[https://attack.mitre.org/techniques/T1199/ T1199]
+|
+Trusted Relationship
+|
+Initial Access
+
+| Anomaly
+|-
+| [[Documentation:ESSOC:detections:Detections#Github_commit_in_develop|Github Commit In Develop]]
+
+|
+[https://attack.mitre.org/techniques/T1199/ T1199]
+|
+Trusted Relationship
+|
+Initial Access
+
+| Anomaly
+|-
+| [[Documentation:ESSOC:detections:Detections#Gsuite_drive_share_in_external_email|Gsuite Drive Share In External Email]]
+
+|
+[https://attack.mitre.org/techniques/T1567.002/ T1567.002], 
+[https://attack.mitre.org/techniques/T1567/ T1567]
+|
+Exfiltration to Cloud Storage, 
+Exfiltration Over Web Service
+|
+Exfiltration, 
+Exfiltration
+
+| Anomaly
+|-
+| [[Documentation:ESSOC:detections:Detections#Gsuite_email_suspicious_subject_with_attachment|Gsuite Email Suspicious Subject With Attachment]]
+
+|
+[https://attack.mitre.org/techniques/T1566.001/ T1566.001], 
+[https://attack.mitre.org/techniques/T1566/ T1566]
+|
+Spearphishing Attachment, 
+Phishing
+|
+Initial Access, 
+Initial Access
+
+| Anomaly
+|-
+| [[Documentation:ESSOC:detections:Detections#Gsuite_email_with_known_abuse_web_service_link|Gsuite Email With Known Abuse Web Service Link]]
+
+|
+[https://attack.mitre.org/techniques/T1566.001/ T1566.001], 
+[https://attack.mitre.org/techniques/T1566/ T1566]
+|
+Spearphishing Attachment, 
+Phishing
+|
+Initial Access, 
+Initial Access
+
+| Anomaly
+|-
+| [[Documentation:ESSOC:detections:Detections#Gsuite_outbound_email_with_attachment_to_external_domain|Gsuite Outbound Email With Attachment To External Domain]]
+
+|
+[https://attack.mitre.org/techniques/T1048.003/ T1048.003], 
+[https://attack.mitre.org/techniques/T1048/ T1048]
+|
+Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, 
+Exfiltration Over Alternative Protocol
+|
+Exfiltration, 
+Exfiltration
+
+| Anomaly
+|-
+| [[Documentation:ESSOC:detections:Detections#Gsuite_suspicious_shared_file_name|Gsuite Suspicious Shared File Name]]
+
+|
+[https://attack.mitre.org/techniques/T1566.001/ T1566.001], 
+[https://attack.mitre.org/techniques/T1566/ T1566]
+|
+Spearphishing Attachment, 
+Phishing
+|
+Initial Access, 
 Initial Access
 
 | Anomaly
@@ -8885,6 +10314,10 @@ Discovery
 
 * Actions on Objectives
 
+* Exfiltration
+
+* Exploitation
+
 
 ====Reference====
 
@@ -9079,10 +10512,13 @@ This story is focused around detecting Office 365 Attacks.
 | [[Documentation:ESSOC:detections:Detections#High_number_of_login_failures_from_a_single_source|High Number of Login Failures from a single source]]
 
 |
-[https://attack.mitre.org/techniques/T1110.001/ T1110.001]
+[https://attack.mitre.org/techniques/T1110.001/ T1110.001], 
+[https://attack.mitre.org/techniques/T1110/ T1110]
 |
-Password Guessing
+Password Guessing, 
+Brute Force
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -9090,10 +10526,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#O365_add_app_role_assignment_grant_user|O365 Add App Role Assignment Grant User]]
 
 |
-[https://attack.mitre.org/techniques/T1136.003/ T1136.003]
+[https://attack.mitre.org/techniques/T1136.003/ T1136.003], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Cloud Account
+Cloud Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -9101,10 +10540,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#O365_added_service_principal|O365 Added Service Principal]]
 
 |
-[https://attack.mitre.org/techniques/T1136.003/ T1136.003]
+[https://attack.mitre.org/techniques/T1136.003/ T1136.003], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Cloud Account
+Cloud Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -9112,10 +10554,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#O365_bypass_mfa_via_trusted_ip|O365 Bypass MFA via Trusted IP]]
 
 |
-[https://attack.mitre.org/techniques/T1562.007/ T1562.007]
+[https://attack.mitre.org/techniques/T1562.007/ T1562.007], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Cloud Firewall
+Disable or Modify Cloud Firewall, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -9156,10 +10601,13 @@ Credential Access, Defense Evasion, Persistence
 | [[Documentation:ESSOC:detections:Detections#O365_new_federated_domain_added|O365 New Federated Domain Added]]
 
 |
-[https://attack.mitre.org/techniques/T1136.003/ T1136.003]
+[https://attack.mitre.org/techniques/T1136.003/ T1136.003], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Cloud Account
+Cloud Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -9178,10 +10626,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#O365_suspicious_admin_email_forwarding|O365 Suspicious Admin Email Forwarding]]
 
 |
-[https://attack.mitre.org/techniques/T1114.003/ T1114.003]
+[https://attack.mitre.org/techniques/T1114.003/ T1114.003], 
+[https://attack.mitre.org/techniques/T1114/ T1114]
 |
-Email Forwarding Rule
+Email Forwarding Rule, 
+Email Collection
 |
+Collection, 
 Collection
 
 | Anomaly
@@ -9189,10 +10640,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#O365_suspicious_rights_delegation|O365 Suspicious Rights Delegation]]
 
 |
-[https://attack.mitre.org/techniques/T1114.002/ T1114.002]
+[https://attack.mitre.org/techniques/T1114.002/ T1114.002], 
+[https://attack.mitre.org/techniques/T1114/ T1114]
 |
-Remote Email Collection
+Remote Email Collection, 
+Email Collection
 |
+Collection, 
 Collection
 
 | TTP
@@ -9200,10 +10654,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#O365_suspicious_user_email_forwarding|O365 Suspicious User Email Forwarding]]
 
 |
-[https://attack.mitre.org/techniques/T1114.003/ T1114.003]
+[https://attack.mitre.org/techniques/T1114.003/ T1114.003], 
+[https://attack.mitre.org/techniques/T1114/ T1114]
 |
-Email Forwarding Rule
+Email Forwarding Rule, 
+Email Collection
 |
+Collection, 
 Collection
 
 | Anomaly
@@ -9535,10 +10992,13 @@ Monitor your cloud infrastructure provisioning activities for behaviors originat
 | [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_instances_destroyed|Abnormally High Number Of Cloud Instances Destroyed]]
 
 |
-[https://attack.mitre.org/techniques/T1078.004/ T1078.004]
+[https://attack.mitre.org/techniques/T1078.004/ T1078.004], 
+[https://attack.mitre.org/techniques/T1078/ T1078]
 |
-Cloud Accounts
+Cloud Accounts, 
+Valid Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | Anomaly
@@ -9546,10 +11006,13 @@ Defense Evasion, Persistence, Privilege Escalation, Initial Access
 | [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_instances_launched|Abnormally High Number Of Cloud Instances Launched]]
 
 |
-[https://attack.mitre.org/techniques/T1078.004/ T1078.004]
+[https://attack.mitre.org/techniques/T1078.004/ T1078.004], 
+[https://attack.mitre.org/techniques/T1078/ T1078]
 |
-Cloud Accounts
+Cloud Accounts, 
+Valid Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | Anomaly
@@ -9557,10 +11020,13 @@ Defense Evasion, Persistence, Privilege Escalation, Initial Access
 | [[Documentation:ESSOC:detections:Detections#Cloud_instance_modified_by_previously_unseen_user|Cloud Instance Modified By Previously Unseen User]]
 
 |
-[https://attack.mitre.org/techniques/T1078.004/ T1078.004]
+[https://attack.mitre.org/techniques/T1078.004/ T1078.004], 
+[https://attack.mitre.org/techniques/T1078/ T1078]
 |
-Cloud Accounts
+Cloud Accounts, 
+Valid Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | Anomaly
@@ -9704,10 +11170,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_infrastructure_api_calls|Abnormally High Number Of Cloud Infrastructure API Calls]]
 
 |
-[https://attack.mitre.org/techniques/T1078.004/ T1078.004]
+[https://attack.mitre.org/techniques/T1078.004/ T1078.004], 
+[https://attack.mitre.org/techniques/T1078/ T1078]
 |
-Cloud Accounts
+Cloud Accounts, 
+Valid Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | Anomaly
@@ -9715,10 +11184,13 @@ Defense Evasion, Persistence, Privilege Escalation, Initial Access
 | [[Documentation:ESSOC:detections:Detections#Abnormally_high_number_of_cloud_security_group_api_calls|Abnormally High Number Of Cloud Security Group API Calls]]
 
 |
-[https://attack.mitre.org/techniques/T1078.004/ T1078.004]
+[https://attack.mitre.org/techniques/T1078.004/ T1078.004], 
+[https://attack.mitre.org/techniques/T1078/ T1078]
 |
-Cloud Accounts
+Cloud Accounts, 
+Valid Accounts
 |
+Defense Evasion, Persistence, Privilege Escalation, Initial Access, 
 Defense Evasion, Persistence, Privilege Escalation, Initial Access
 
 | Anomaly
@@ -9842,10 +11314,13 @@ The following analytic story identifies behaviors related PrintNightmare, or CVE
 | [[Documentation:ESSOC:detections:Detections#Print_spooler_adding_a_printer_driver|Print Spooler Adding A Printer Driver]]
 
 |
-[https://attack.mitre.org/techniques/T1547.012/ T1547.012]
+[https://attack.mitre.org/techniques/T1547.012/ T1547.012], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Print Processors
+Print Processors, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -9853,10 +11328,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Print_spooler_failed_to_load_a_plug-in|Print Spooler Failed to Load a Plug-in]]
 
 |
-[https://attack.mitre.org/techniques/T1547.012/ T1547.012]
+[https://attack.mitre.org/techniques/T1547.012/ T1547.012], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Print Processors
+Print Processors, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -9864,10 +11342,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Rundll32_with_no_command_line_arguments_with_network|Rundll32 with no Command Line Arguments with Network]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -9875,10 +11356,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Spoolsv_spawning_rundll32|Spoolsv Spawning Rundll32]]
 
 |
-[https://attack.mitre.org/techniques/T1547.012/ T1547.012]
+[https://attack.mitre.org/techniques/T1547.012/ T1547.012], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Print Processors
+Print Processors, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -9886,10 +11370,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Spoolsv_suspicious_loaded_modules|Spoolsv Suspicious Loaded Modules]]
 
 |
-[https://attack.mitre.org/techniques/T1547.012/ T1547.012]
+[https://attack.mitre.org/techniques/T1547.012/ T1547.012], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Print Processors
+Print Processors, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -9908,10 +11395,13 @@ Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Spoolsv_writing_a_dll|Spoolsv Writing a DLL]]
 
 |
-[https://attack.mitre.org/techniques/T1547.012/ T1547.012]
+[https://attack.mitre.org/techniques/T1547.012/ T1547.012], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Print Processors
+Print Processors, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -9919,10 +11409,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Spoolsv_writing_a_dll_-_sysmon|Spoolsv Writing a DLL - Sysmon]]
 
 |
-[https://attack.mitre.org/techniques/T1547.012/ T1547.012]
+[https://attack.mitre.org/techniques/T1547.012/ T1547.012], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Print Processors
+Print Processors, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -9930,10 +11423,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_no_command_line_arguments|Suspicious Rundll32 no Command Line Arguments]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -9990,10 +11486,13 @@ Leverage searches that allow you to detect and investigate unusual activities th
 | [[Documentation:ESSOC:detections:Detections#Add_defaultuser_and_password_in_registry|Add DefaultUser And Password In Registry]]
 
 |
-[https://attack.mitre.org/techniques/T1552.002/ T1552.002]
+[https://attack.mitre.org/techniques/T1552.002/ T1552.002], 
+[https://attack.mitre.org/techniques/T1552/ T1552]
 |
-Credentials in Registry
+Credentials in Registry, 
+Unsecured Credentials
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -10001,10 +11500,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Auto_admin_logon_registry_entry|Auto Admin Logon Registry Entry]]
 
 |
-[https://attack.mitre.org/techniques/T1552.002/ T1552.002]
+[https://attack.mitre.org/techniques/T1552.002/ T1552.002], 
+[https://attack.mitre.org/techniques/T1552/ T1552]
 |
-Credentials in Registry
+Credentials in Registry, 
+Unsecured Credentials
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -10153,10 +11655,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Create_service_in_suspicious_file_path|Create Service In Suspicious File Path]]
 
 |
+[https://attack.mitre.org/techniques/T1569/ T1569], 
 [https://attack.mitre.org/techniques/T1569.002/ T1569.002]
 |
+System Services, 
 Service Execution
 |
+Execution, 
 Execution
 
 | TTP
@@ -10241,10 +11746,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Suspicious_event_log_service_behavior|Suspicious Event Log Service Behavior]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -10252,10 +11760,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_wevtutil_usage|Suspicious wevtutil Usage]]
 
 |
-[https://attack.mitre.org/techniques/T1070.001/ T1070.001]
+[https://attack.mitre.org/techniques/T1070.001/ T1070.001], 
+[https://attack.mitre.org/techniques/T1070/ T1070]
 |
-Clear Windows Event Logs
+Clear Windows Event Logs, 
+Indicator Removal on Host
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -10263,10 +11774,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Wevtutil_usage_to_clear_logs|WevtUtil Usage To Clear Logs]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -10274,10 +11788,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Windows_event_log_cleared|Windows Event Log Cleared]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -10379,10 +11896,13 @@ Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA
 | [[Documentation:ESSOC:detections:Detections#Create_local_admin_accounts_using_net_exe|Create local admin accounts using net exe]]
 
 |
-[https://attack.mitre.org/techniques/T1136.001/ T1136.001]
+[https://attack.mitre.org/techniques/T1136.001/ T1136.001], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Local Account
+Local Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -10390,10 +11910,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#Detect_new_local_admin_account|Detect New Local Admin account]]
 
 |
-[https://attack.mitre.org/techniques/T1136.001/ T1136.001]
+[https://attack.mitre.org/techniques/T1136.001/ T1136.001], 
+[https://attack.mitre.org/techniques/T1136/ T1136]
 |
-Local Account
+Local Account, 
+Create Account
 |
+Persistence, 
 Persistence
 
 | TTP
@@ -10401,10 +11924,13 @@ Persistence
 | [[Documentation:ESSOC:detections:Detections#Detect_outbound_smb_traffic|Detect Outbound SMB Traffic]]
 
 |
-[https://attack.mitre.org/techniques/T1071.002/ T1071.002]
+[https://attack.mitre.org/techniques/T1071.002/ T1071.002], 
+[https://attack.mitre.org/techniques/T1071/ T1071]
 |
-File Transfer Protocols
+File Transfer Protocols, 
+Application Layer Protocol
 |
+Command And Control, 
 Command And Control
 
 | TTP
@@ -10412,10 +11938,13 @@ Command And Control
 | [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]]
 
 |
+[https://attack.mitre.org/techniques/T1021/ T1021], 
 [https://attack.mitre.org/techniques/T1021.002/ T1021.002]
 |
+Remote Services, 
 SMB/Windows Admin Shares
 |
+Lateral Movement, 
 Lateral Movement
 
 | TTP
@@ -10423,10 +11952,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]]
 
 |
+[https://attack.mitre.org/techniques/T1569/ T1569], 
 [https://attack.mitre.org/techniques/T1569.002/ T1569.002]
 |
+System Services, 
 Service Execution
 |
+Execution, 
 Execution
 
 | Hunting
@@ -10434,10 +11966,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_execution_policy_bypass|Malicious PowerShell Process - Execution Policy Bypass]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.001/ T1059.001]
 |
+Command and Scripting Interpreter, 
 PowerShell
 |
+Execution, 
 Execution
 
 | TTP
@@ -10445,10 +11980,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Processes_launching_netsh|Processes launching netsh]]
 
 |
-[https://attack.mitre.org/techniques/T1562.004/ T1562.004]
+[https://attack.mitre.org/techniques/T1562.004/ T1562.004], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify System Firewall
+Disable or Modify System Firewall, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -10456,10 +11994,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]]
 
 |
-[https://attack.mitre.org/techniques/T1547.001/ T1547.001]
+[https://attack.mitre.org/techniques/T1547.001/ T1547.001], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Registry Run Keys / Startup Folder
+Registry Run Keys / Startup Folder, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -10467,10 +12008,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike|SMB Traffic Spike]]
 
 |
-[https://attack.mitre.org/techniques/T1021.002/ T1021.002]
+[https://attack.mitre.org/techniques/T1021.002/ T1021.002], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-SMB/Windows Admin Shares
+SMB/Windows Admin Shares, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -10478,10 +12022,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike_-_mltk|SMB Traffic Spike - MLTK]]
 
 |
-[https://attack.mitre.org/techniques/T1021.002/ T1021.002]
+[https://attack.mitre.org/techniques/T1021.002/ T1021.002], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-SMB/Windows Admin Shares
+SMB/Windows Admin Shares, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -10489,10 +12036,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]]
 
 |
-[https://attack.mitre.org/techniques/T1543.003/ T1543.003]
+[https://attack.mitre.org/techniques/T1543.003/ T1543.003], 
+[https://attack.mitre.org/techniques/T1543/ T1543]
 |
-Windows Service
+Windows Service, 
+Create or Modify System Process
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -10500,10 +12050,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Scheduled_task_deleted_or_created_via_cmd|Scheduled Task Deleted Or Created via CMD]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -10511,10 +12064,13 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Single_letter_process_on_endpoint|Single Letter Process On Endpoint]]
 
 |
+[https://attack.mitre.org/techniques/T1204/ T1204], 
 [https://attack.mitre.org/techniques/T1204.002/ T1204.002]
 |
+User Execution, 
 Malicious File
 |
+Execution, 
 Execution
 
 | TTP
@@ -10579,10 +12135,13 @@ Leverage searches that allow you to detect and investigate unusual activities th
 | [[Documentation:ESSOC:detections:Detections#Attempted_credential_dump_from_registry_via_reg_exe|Attempted Credential Dump From Registry via Reg exe]]
 
 |
-[https://attack.mitre.org/techniques/T1003.002/ T1003.002]
+[https://attack.mitre.org/techniques/T1003.002/ T1003.002], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-Security Account Manager
+Security Account Manager, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -10604,10 +12163,13 @@ Command And Control
 | [[Documentation:ESSOC:detections:Detections#Cmlua_or_cmstplua_uac_bypass|CMLUA Or CMSTPLUA UAC Bypass]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.003/ T1218.003]
 |
+Signed Binary Proxy Execution, 
 CMSTP
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -10659,10 +12221,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Detect_mimikatz_using_loaded_images|Detect Mimikatz Using Loaded Images]]
 
 |
-[https://attack.mitre.org/techniques/T1003.001/ T1003.001]
+[https://attack.mitre.org/techniques/T1003.001/ T1003.001], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-LSASS Memory
+LSASS Memory, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -10670,10 +12235,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]]
 
 |
+[https://attack.mitre.org/techniques/T1021/ T1021], 
 [https://attack.mitre.org/techniques/T1021.002/ T1021.002]
 |
+Remote Services, 
 SMB/Windows Admin Shares
 |
+Lateral Movement, 
 Lateral Movement
 
 | TTP
@@ -10692,10 +12260,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]]
 
 |
+[https://attack.mitre.org/techniques/T1569/ T1569], 
 [https://attack.mitre.org/techniques/T1569.002/ T1569.002]
 |
+System Services, 
 Service Execution
 |
+Execution, 
 Execution
 
 | Hunting
@@ -10714,10 +12285,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Extraction_of_registry_hives|Extraction of Registry Hives]]
 
 |
-[https://attack.mitre.org/techniques/T1003.002/ T1003.002]
+[https://attack.mitre.org/techniques/T1003.002/ T1003.002], 
+[https://attack.mitre.org/techniques/T1003/ T1003]
 |
-Security Account Manager
+Security Account Manager, 
+OS Credential Dumping
 |
+Credential Access, 
 Credential Access
 
 | TTP
@@ -10736,10 +12310,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Slui_runas_elevated|SLUI RunAs Elevated]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -10747,10 +12324,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Slui_spawning_a_process|SLUI Spawning a Process]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -10893,10 +12473,13 @@ Detect rarely used executables, specific registry paths that may confer malware
 | [[Documentation:ESSOC:detections:Detections#Detect_use_of_cmd_exe_to_launch_script_interpreters|Detect Use of cmd exe to Launch Script Interpreters]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.003/ T1059.003]
 |
+Command and Scripting Interpreter, 
 Windows Command Shell
 |
+Execution, 
 Execution
 
 | TTP
@@ -10923,10 +12506,13 @@ Execution, Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]]
 
 |
-[https://attack.mitre.org/techniques/T1547.001/ T1547.001]
+[https://attack.mitre.org/techniques/T1547.001/ T1547.001], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Registry Run Keys / Startup Folder
+Registry Run Keys / Startup Folder, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -10934,10 +12520,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike|SMB Traffic Spike]]
 
 |
-[https://attack.mitre.org/techniques/T1021.002/ T1021.002]
+[https://attack.mitre.org/techniques/T1021.002/ T1021.002], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-SMB/Windows Admin Shares
+SMB/Windows Admin Shares, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -10945,10 +12534,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike_-_mltk|SMB Traffic Spike - MLTK]]
 
 |
-[https://attack.mitre.org/techniques/T1021.002/ T1021.002]
+[https://attack.mitre.org/techniques/T1021.002/ T1021.002], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-SMB/Windows Admin Shares
+SMB/Windows Admin Shares, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -10956,10 +12548,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Suspicious_email_attachment_extensions|Suspicious Email Attachment Extensions]]
 
 |
-[https://attack.mitre.org/techniques/T1566.001/ T1566.001]
+[https://attack.mitre.org/techniques/T1566.001/ T1566.001], 
+[https://attack.mitre.org/techniques/T1566/ T1566]
 |
-Spearphishing Attachment
+Spearphishing Attachment, 
+Phishing
 |
+Initial Access, 
 Initial Access
 
 | Anomaly
@@ -11026,10 +12621,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Cmdline_tool_not_executed_in_cmd_shell|Cmdline Tool Not Executed In CMD Shell]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.007/ T1059.007]
 |
+Command and Scripting Interpreter, 
 JavaScript
 |
+Execution, 
 Execution
 
 | TTP
@@ -11037,10 +12635,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Jscript_execution_using_cscript_app|Jscript Execution Using Cscript App]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.007/ T1059.007]
 |
+Command and Scripting Interpreter, 
 JavaScript
 |
+Execution, 
 Execution
 
 | TTP
@@ -11048,10 +12649,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Ms_scripting_process_loading_ldap_module|MS Scripting Process Loading Ldap Module]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.007/ T1059.007]
 |
+Command and Scripting Interpreter, 
 JavaScript
 |
+Execution, 
 Execution
 
 | Anomaly
@@ -11059,10 +12663,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Ms_scripting_process_loading_wmi_module|MS Scripting Process Loading WMI Module]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.007/ T1059.007]
 |
+Command and Scripting Interpreter, 
 JavaScript
 |
+Execution, 
 Execution
 
 | Anomaly
@@ -11070,10 +12677,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Non_chrome_process_accessing_chrome_default_dir|Non Chrome Process Accessing Chrome Default Dir]]
 
 |
+[https://attack.mitre.org/techniques/T1555/ T1555], 
 [https://attack.mitre.org/techniques/T1555.003/ T1555.003]
 |
+Credentials from Password Stores, 
 Credentials from Web Browsers
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -11081,10 +12691,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Non_firefox_process_access_firefox_profile_dir|Non Firefox Process Access Firefox Profile Dir]]
 
 |
+[https://attack.mitre.org/techniques/T1555/ T1555], 
 [https://attack.mitre.org/techniques/T1555.003/ T1555.003]
 |
+Credentials from Password Stores, 
 Credentials from Web Browsers
 |
+Credential Access, 
 Credential Access
 
 | Anomaly
@@ -11092,10 +12705,13 @@ Credential Access
 | [[Documentation:ESSOC:detections:Detections#Office_application_drop_executable|Office Application Drop Executable]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -11103,12 +12719,49 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_product_spawning_wmic|Office Product Spawning Wmic]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Vbscript_execution_using_wscript_app|Vbscript Execution Using Wscript App]]
+
+|
+[https://attack.mitre.org/techniques/T1059.005/ T1059.005], 
+[https://attack.mitre.org/techniques/T1059/ T1059]
+|
+Visual Basic, 
+Command and Scripting Interpreter
+|
+Execution, 
+Execution
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Wscript_or_cscript_suspicious_child_process|Wscript Or Cscript Suspicious Child Process]]
+
+|
+[https://attack.mitre.org/techniques/T1055/ T1055], 
+[https://attack.mitre.org/techniques/T1543/ T1543], 
+[https://attack.mitre.org/techniques/T1134.004/ T1134.004], 
+[https://attack.mitre.org/techniques/T1134/ T1134]
+|
+Process Injection, 
+Create or Modify System Process, 
+Parent PID Spoofing, 
+Access Token Manipulation
+|
+Defense Evasion, Privilege Escalation, 
+Persistence, Privilege Escalation, 
+Defense Evasion, Privilege Escalation, 
+Defense Evasion, Privilege Escalation
+
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Xsl_script_execution_with_wmic|XSL Script Execution With WMIC]]
@@ -11165,10 +12818,13 @@ Monitor for and investigate activities, including the creation or deletion of hi
 | [[Documentation:ESSOC:detections:Detections#Create_or_delete_windows_shares_using_net_exe|Create or delete windows shares using net exe]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.005/ T1070.005]
 |
+Indicator Removal on Host, 
 Network Share Connection Removal
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11176,10 +12832,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Dns_query_length_outliers_-_mltk|DNS Query Length Outliers - MLTK]]
 
 |
-[https://attack.mitre.org/techniques/T1071.004/ T1071.004]
+[https://attack.mitre.org/techniques/T1071.004/ T1071.004], 
+[https://attack.mitre.org/techniques/T1071/ T1071]
 |
-DNS
+DNS, 
+Application Layer Protocol
 |
+Command And Control, 
 Command And Control
 
 | Anomaly
@@ -11187,10 +12846,13 @@ Command And Control
 | [[Documentation:ESSOC:detections:Detections#Dns_query_length_with_high_standard_deviation|DNS Query Length With High Standard Deviation]]
 
 |
-[https://attack.mitre.org/techniques/T1048.003/ T1048.003]
+[https://attack.mitre.org/techniques/T1048.003/ T1048.003], 
+[https://attack.mitre.org/techniques/T1048/ T1048]
 |
-Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
+Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol, 
+Exfiltration Over Alternative Protocol
 |
+Exfiltration, 
 Exfiltration
 
 | Anomaly
@@ -11198,10 +12860,13 @@ Exfiltration
 | [[Documentation:ESSOC:detections:Detections#Detect_outbound_smb_traffic|Detect Outbound SMB Traffic]]
 
 |
-[https://attack.mitre.org/techniques/T1071.002/ T1071.002]
+[https://attack.mitre.org/techniques/T1071.002/ T1071.002], 
+[https://attack.mitre.org/techniques/T1071/ T1071]
 |
-File Transfer Protocols
+File Transfer Protocols, 
+Application Layer Protocol
 |
+Command And Control, 
 Command And Control
 
 | TTP
@@ -11209,10 +12874,13 @@ Command And Control
 | [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_traffic|Remote Desktop Network Traffic]]
 
 |
-[https://attack.mitre.org/techniques/T1021.001/ T1021.001]
+[https://attack.mitre.org/techniques/T1021.001/ T1021.001], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-Remote Desktop Protocol
+Remote Desktop Protocol, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -11220,10 +12888,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Remote_desktop_process_running_on_system|Remote Desktop Process Running On System]]
 
 |
-[https://attack.mitre.org/techniques/T1021.001/ T1021.001]
+[https://attack.mitre.org/techniques/T1021.001/ T1021.001], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-Remote Desktop Protocol
+Remote Desktop Protocol, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Hunting
@@ -11231,10 +12902,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike|SMB Traffic Spike]]
 
 |
-[https://attack.mitre.org/techniques/T1021.002/ T1021.002]
+[https://attack.mitre.org/techniques/T1021.002/ T1021.002], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-SMB/Windows Admin Shares
+SMB/Windows Admin Shares, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -11242,10 +12916,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike_-_mltk|SMB Traffic Spike - MLTK]]
 
 |
-[https://attack.mitre.org/techniques/T1021.002/ T1021.002]
+[https://attack.mitre.org/techniques/T1021.002/ T1021.002], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-SMB/Windows Admin Shares
+SMB/Windows Admin Shares, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -11293,10 +12970,13 @@ Leverage searches that allow you to detect and investigate unusual activities th
 | [[Documentation:ESSOC:detections:Detections#Account_discovery_with_net_app|Account Discovery With Net App]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -11326,10 +13006,13 @@ Defense Evasion, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Drop_icedid_license_dat|Drop IcedID License dat]]
 
 |
+[https://attack.mitre.org/techniques/T1204/ T1204], 
 [https://attack.mitre.org/techniques/T1204.002/ T1204.002]
 |
+User Execution, 
 Malicious File
 |
+Execution, 
 Execution
 
 | Hunting
@@ -11337,10 +13020,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Eventvwr_uac_bypass|Eventvwr UAC Bypass]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -11349,12 +13035,15 @@ Privilege Escalation, Defense Evasion
 
 |
 [https://attack.mitre.org/techniques/T1112/ T1112], 
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
 Modify Registry, 
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
 Defense Evasion, 
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -11362,10 +13051,13 @@ Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Icedid_exfiltrated_archived_file_creation|IcedID Exfiltrated Archived File Creation]]
 
 |
-[https://attack.mitre.org/techniques/T1560.001/ T1560.001]
+[https://attack.mitre.org/techniques/T1560.001/ T1560.001], 
+[https://attack.mitre.org/techniques/T1560/ T1560]
 |
-Archive via Utility
+Archive via Utility, 
+Archive Collected Data
 |
+Collection, 
 Collection
 
 | Hunting
@@ -11373,10 +13065,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Mshta_spawning_rundll32_or_regsvr32_process|Mshta spawning Rundll32 OR Regsvr32 Process]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.005/ T1218.005]
 |
+Signed Binary Proxy Execution, 
 Mshta
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11395,10 +13090,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Office_application_spawn_regsvr32_process|Office Application Spawn Regsvr32 process]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -11406,10 +13104,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_application_spawn_rundll32_process|Office Application Spawn rundll32 process]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -11417,10 +13118,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_document_executing_macro_code|Office Document Executing Macro Code]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -11428,10 +13132,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_product_spawning_mshta|Office Product Spawning MSHTA]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -11439,10 +13146,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]]
 
 |
-[https://attack.mitre.org/techniques/T1547.001/ T1547.001]
+[https://attack.mitre.org/techniques/T1547.001/ T1547.001], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Registry Run Keys / Startup Folder
+Registry Run Keys / Startup Folder, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -11472,10 +13182,13 @@ Defense Evasion, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Rundll32_dnsquery|Rundll32 DNSQuery]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11483,10 +13196,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Rundll32_process_creating_exe_dll_files|Rundll32 Process Creating Exe Dll Files]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11516,10 +13232,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Suspicious_icedid_regsvr32_cmdline|Suspicious IcedID Regsvr32 Cmdline]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.010/ T1218.010]
 |
+Signed Binary Proxy Execution, 
 Regsvr32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11527,10 +13246,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_icedid_rundll32_cmdline|Suspicious IcedID Rundll32 Cmdline]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11538,10 +13260,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_plugininit|Suspicious Rundll32 PluginInit]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11549,10 +13274,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -11604,10 +13332,13 @@ Detect activities and various techniques associated with the Orangeworm Attack G
 | [[Documentation:ESSOC:detections:Detections#First_time_seen_running_windows_service|First Time Seen Running Windows Service]]
 
 |
+[https://attack.mitre.org/techniques/T1569/ T1569], 
 [https://attack.mitre.org/techniques/T1569.002/ T1569.002]
 |
+System Services, 
 Service Execution
 |
+Execution, 
 Execution
 
 | Anomaly
@@ -11615,10 +13346,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]]
 
 |
-[https://attack.mitre.org/techniques/T1543.003/ T1543.003]
+[https://attack.mitre.org/techniques/T1543.003/ T1543.003], 
+[https://attack.mitre.org/techniques/T1543/ T1543]
 |
-Windows Service
+Windows Service, 
+Create or Modify System Process
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -11666,10 +13400,13 @@ Leverage searches that allow you to detect and investigate unusual activities th
 | [[Documentation:ESSOC:detections:Detections#7zip_commandline_to_smb_share_path|7zip CommandLine To SMB Share Path]]
 
 |
-[https://attack.mitre.org/techniques/T1560.001/ T1560.001]
+[https://attack.mitre.org/techniques/T1560.001/ T1560.001], 
+[https://attack.mitre.org/techniques/T1560/ T1560]
 |
-Archive via Utility
+Archive via Utility, 
+Archive Collected Data
 |
+Collection, 
 Collection
 
 | Hunting
@@ -11677,10 +13414,13 @@ Collection
 | [[Documentation:ESSOC:detections:Detections#Allow_file_and_printing_sharing_in_firewall|Allow File And Printing Sharing In Firewall]]
 
 |
-[https://attack.mitre.org/techniques/T1562.007/ T1562.007]
+[https://attack.mitre.org/techniques/T1562.007/ T1562.007], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Cloud Firewall
+Disable or Modify Cloud Firewall, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11688,10 +13428,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Allow_network_discovery_in_firewall|Allow Network Discovery In Firewall]]
 
 |
-[https://attack.mitre.org/techniques/T1562.007/ T1562.007]
+[https://attack.mitre.org/techniques/T1562.007/ T1562.007], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Cloud Firewall
+Disable or Modify Cloud Firewall, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11743,10 +13486,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Cmlua_or_cmstplua_uac_bypass|CMLUA Or CMSTPLUA UAC Bypass]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.003/ T1218.003]
 |
+Signed Binary Proxy Execution, 
 CMSTP
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11754,10 +13500,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Clear_unallocated_sector_using_cipher_app|Clear Unallocated Sector Using Cipher App]]
 
 |
-[https://attack.mitre.org/techniques/T1070.004/ T1070.004]
+[https://attack.mitre.org/techniques/T1070.004/ T1070.004], 
+[https://attack.mitre.org/techniques/T1070/ T1070]
 |
-File Deletion
+File Deletion, 
+Indicator Removal on Host
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11854,21 +13603,27 @@ Exfiltration
 
 |
 [https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
-[https://attack.mitre.org/techniques/T1087.001/ T1087.001], 
+[https://attack.mitre.org/techniques/T1069.001/ T1069.001], 
 [https://attack.mitre.org/techniques/T1482/ T1482], 
+[https://attack.mitre.org/techniques/T1087.001/ T1087.001], 
+[https://attack.mitre.org/techniques/T1087/ T1087], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002], 
-[https://attack.mitre.org/techniques/T1069.001/ T1069.001]
+[https://attack.mitre.org/techniques/T1069/ T1069]
 |
 Domain Account, 
-Local Account, 
+Local Groups, 
 Domain Trust Discovery, 
+Local Account, 
+Account Discovery, 
 Domain Groups, 
-Local Groups
+Permission Groups Discovery
 |
 Discovery, 
 Discovery, 
 Discovery, 
 Discovery, 
+Discovery, 
+Discovery, 
 Discovery
 
 | TTP
@@ -11877,21 +13632,27 @@ Discovery
 
 |
 [https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
-[https://attack.mitre.org/techniques/T1087.001/ T1087.001], 
+[https://attack.mitre.org/techniques/T1069.001/ T1069.001], 
 [https://attack.mitre.org/techniques/T1482/ T1482], 
+[https://attack.mitre.org/techniques/T1087.001/ T1087.001], 
+[https://attack.mitre.org/techniques/T1087/ T1087], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002], 
-[https://attack.mitre.org/techniques/T1069.001/ T1069.001]
+[https://attack.mitre.org/techniques/T1069/ T1069]
 |
 Domain Account, 
-Local Account, 
+Local Groups, 
 Domain Trust Discovery, 
+Local Account, 
+Account Discovery, 
 Domain Groups, 
-Local Groups
+Permission Groups Discovery
 |
 Discovery, 
 Discovery, 
 Discovery, 
 Discovery, 
+Discovery, 
+Discovery, 
 Discovery
 
 | TTP
@@ -11900,21 +13661,27 @@ Discovery
 
 |
 [https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
-[https://attack.mitre.org/techniques/T1087.001/ T1087.001], 
+[https://attack.mitre.org/techniques/T1069.001/ T1069.001], 
 [https://attack.mitre.org/techniques/T1482/ T1482], 
+[https://attack.mitre.org/techniques/T1087.001/ T1087.001], 
+[https://attack.mitre.org/techniques/T1087/ T1087], 
 [https://attack.mitre.org/techniques/T1069.002/ T1069.002], 
-[https://attack.mitre.org/techniques/T1069.001/ T1069.001]
+[https://attack.mitre.org/techniques/T1069/ T1069]
 |
 Domain Account, 
-Local Account, 
+Local Groups, 
 Domain Trust Discovery, 
+Local Account, 
+Account Discovery, 
 Domain Groups, 
-Local Groups
+Permission Groups Discovery
 |
 Discovery, 
 Discovery, 
 Discovery, 
 Discovery, 
+Discovery, 
+Discovery, 
 Discovery
 
 | TTP
@@ -11922,10 +13689,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Disable_amsi_through_registry|Disable AMSI Through Registry]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11933,10 +13703,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Disable_etw_through_registry|Disable ETW Through Registry]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11944,10 +13717,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Disable_logs_using_wevtutil|Disable Logs Using WevtUtil]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11966,10 +13742,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Disable_windows_behavior_monitoring|Disable Windows Behavior Monitoring]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -11999,10 +13778,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Excessive_usage_of_sc_service_utility|Excessive Usage Of SC Service Utility]]
 
 |
+[https://attack.mitre.org/techniques/T1569/ T1569], 
 [https://attack.mitre.org/techniques/T1569.002/ T1569.002]
 |
+System Services, 
 Service Execution
 |
+Execution, 
 Execution
 
 | Anomaly
@@ -12010,10 +13792,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Execute_javascript_with_jscript_com_clsid|Execute Javascript With Jscript COM CLSID]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.005/ T1059.005]
 |
+Command and Scripting Interpreter, 
 Visual Basic
 |
+Execution, 
 Execution
 
 | TTP
@@ -12065,10 +13850,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Msmpeng_application_dll_side_loading|Msmpeng Application DLL Side Loading]]
 
 |
-[https://attack.mitre.org/techniques/T1574.002/ T1574.002]
+[https://attack.mitre.org/techniques/T1574.002/ T1574.002], 
+[https://attack.mitre.org/techniques/T1574/ T1574]
 |
-DLL Side-Loading
+DLL Side-Loading, 
+Hijack Execution Flow
 |
+Persistence, Privilege Escalation, Defense Evasion, 
 Persistence, Privilege Escalation, Defense Evasion
 
 | TTP
@@ -12087,10 +13875,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Powershell_disable_security_monitoring|Powershell Disable Security Monitoring]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12098,10 +13889,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Powershell_enable_smb1protocol_feature|Powershell Enable SMB1Protocol Feature]]
 
 |
+[https://attack.mitre.org/techniques/T1027/ T1027], 
 [https://attack.mitre.org/techniques/T1027.005/ T1027.005]
 |
+Obfuscated Files or Information, 
 Indicator Removal from Tools
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12109,10 +13903,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Powershell_execute_com_object|Powershell Execute COM Object]]
 
 |
-[https://attack.mitre.org/techniques/T1546.015/ T1546.015]
+[https://attack.mitre.org/techniques/T1546.015/ T1546.015], 
+[https://attack.mitre.org/techniques/T1546/ T1546]
 |
-Component Object Model Hijacking
+Component Object Model Hijacking, 
+Event Triggered Execution
 |
+Privilege Escalation, Persistence, 
 Privilege Escalation, Persistence
 
 | TTP
@@ -12153,10 +13950,13 @@ Reconnaissance
 | [[Documentation:ESSOC:detections:Detections#Recursive_delete_of_directory_in_batch_cmd|Recursive Delete of Directory In Batch CMD]]
 
 |
-[https://attack.mitre.org/techniques/T1070.004/ T1070.004]
+[https://attack.mitre.org/techniques/T1070.004/ T1070.004], 
+[https://attack.mitre.org/techniques/T1070/ T1070]
 |
-File Deletion
+File Deletion, 
+Indicator Removal on Host
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12164,10 +13964,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]]
 
 |
-[https://attack.mitre.org/techniques/T1547.001/ T1547.001]
+[https://attack.mitre.org/techniques/T1547.001/ T1547.001], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Registry Run Keys / Startup Folder
+Registry Run Keys / Startup Folder, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -12219,10 +14022,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike|SMB Traffic Spike]]
 
 |
-[https://attack.mitre.org/techniques/T1021.002/ T1021.002]
+[https://attack.mitre.org/techniques/T1021.002/ T1021.002], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-SMB/Windows Admin Shares
+SMB/Windows Admin Shares, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -12230,10 +14036,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike_-_mltk|SMB Traffic Spike - MLTK]]
 
 |
-[https://attack.mitre.org/techniques/T1021.002/ T1021.002]
+[https://attack.mitre.org/techniques/T1021.002/ T1021.002], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-SMB/Windows Admin Shares
+SMB/Windows Admin Shares, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -12241,10 +14050,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Schtasks_used_for_forcing_a_reboot|Schtasks used for forcing a reboot]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -12260,10 +14072,13 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Start_up_during_safe_mode_boot|Start Up During Safe Mode Boot]]
 
 |
-[https://attack.mitre.org/techniques/T1547.001/ T1547.001]
+[https://attack.mitre.org/techniques/T1547.001/ T1547.001], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Registry Run Keys / Startup Folder
+Registry Run Keys / Startup Folder, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -12271,10 +14086,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Suspicious_event_log_service_behavior|Suspicious Event Log Service Behavior]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12282,10 +14100,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Suspicious_scheduled_task_from_public_directory|Suspicious Scheduled Task from Public Directory]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | Anomaly
@@ -12293,10 +14114,13 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Suspicious_wevtutil_usage|Suspicious wevtutil Usage]]
 
 |
-[https://attack.mitre.org/techniques/T1070.001/ T1070.001]
+[https://attack.mitre.org/techniques/T1070.001/ T1070.001], 
+[https://attack.mitre.org/techniques/T1070/ T1070]
 |
-Clear Windows Event Logs
+Clear Windows Event Logs, 
+Indicator Removal on Host
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12304,10 +14128,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#System_processes_run_from_unexpected_locations|System Processes Run From Unexpected Locations]]
 
 |
+[https://attack.mitre.org/techniques/T1036/ T1036], 
 [https://attack.mitre.org/techniques/T1036.003/ T1036.003]
 |
+Masquerading, 
 Rename System Utilities
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12315,10 +14142,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Tor_traffic|TOR Traffic]]
 
 |
+[https://attack.mitre.org/techniques/T1071/ T1071], 
 [https://attack.mitre.org/techniques/T1071.001/ T1071.001]
 |
+Application Layer Protocol, 
 Web Protocols
 |
+Command And Control, 
 Command And Control
 
 | TTP
@@ -12326,10 +14156,13 @@ Command And Control
 | [[Documentation:ESSOC:detections:Detections#Uac_bypass_with_colorui_com_object|UAC Bypass With Colorui COM Object]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.003/ T1218.003]
 |
+Signed Binary Proxy Execution, 
 CMSTP
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12348,10 +14181,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Uninstall_app_using_msiexec|Uninstall App Using MsiExec]]
 
 |
-[https://attack.mitre.org/techniques/T1218.007/ T1218.007]
+[https://attack.mitre.org/techniques/T1218.007/ T1218.007], 
+[https://attack.mitre.org/techniques/T1218/ T1218]
 |
-Msiexec
+Msiexec, 
+Signed Binary Proxy Execution
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12386,10 +14222,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Wbemprox_com_object_execution|Wbemprox COM Object Execution]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.003/ T1218.003]
 |
+Signed Binary Proxy Execution, 
 CMSTP
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12397,10 +14236,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Wevtutil_usage_to_clear_logs|WevtUtil Usage To Clear Logs]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12408,10 +14250,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Wevtutil_usage_to_disable_logs|Wevtutil Usage To Disable Logs]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12419,10 +14264,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -12430,10 +14278,13 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_to_spawn_shell|WinEvent Scheduled Task Created to Spawn Shell]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -12441,10 +14292,13 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Windows_event_log_cleared|Windows Event Log Cleared]]
 
 |
+[https://attack.mitre.org/techniques/T1070/ T1070], 
 [https://attack.mitre.org/techniques/T1070.001/ T1070.001]
 |
+Indicator Removal on Host, 
 Clear Windows Event Logs
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12562,10 +14416,13 @@ Leverage searches that allow you to detect and investigate unusual activities th
 | [[Documentation:ESSOC:detections:Detections#Disabling_remote_user_account_control|Disabling Remote User Account Control]]
 
 |
-[https://attack.mitre.org/techniques/T1548.002/ T1548.002]
+[https://attack.mitre.org/techniques/T1548.002/ T1548.002], 
+[https://attack.mitre.org/techniques/T1548/ T1548]
 |
-Bypass User Account Control
+Bypass User Account Control, 
+Abuse Elevation Control Mechanism
 |
+Privilege Escalation, Defense Evasion, 
 Privilege Escalation, Defense Evasion
 
 | TTP
@@ -12579,6 +14436,20 @@ Masquerading
 |
 Defense Evasion
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Malicious_inprocserver32_modification|Malicious InProcServer32 Modification]]
+
+|
+[https://attack.mitre.org/techniques/T1218.010/ T1218.010], 
+[https://attack.mitre.org/techniques/T1112/ T1112]
+|
+Regsvr32, 
+Modify Registry
+|
+Defense Evasion, 
+Defense Evasion
+
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Process_deleting_its_process_file_path|Process Deleting Its Process File Path]]
@@ -12592,13 +14463,30 @@ Defense Evasion
 
 | TTP
 |-
+| [[Documentation:ESSOC:detections:Detections#Process_writing_dynamicwrapperx|Process Writing DynamicWrapperX]]
+
+|
+[https://attack.mitre.org/techniques/T1059/ T1059], 
+[https://attack.mitre.org/techniques/T1559.001/ T1559.001]
+|
+Command and Scripting Interpreter, 
+Component Object Model
+|
+Execution, 
+Execution
+
+| Hunting
+|-
 | [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]]
 
 |
-[https://attack.mitre.org/techniques/T1547.001/ T1547.001]
+[https://attack.mitre.org/techniques/T1547.001/ T1547.001], 
+[https://attack.mitre.org/techniques/T1547/ T1547]
 |
-Registry Run Keys / Startup Folder
+Registry Run Keys / Startup Folder, 
+Boot or Logon Autostart Execution
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -12656,6 +14544,51 @@ Screen Capture
 |
 Collection
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Vbscript_execution_using_wscript_app|Vbscript Execution Using Wscript App]]
+
+|
+[https://attack.mitre.org/techniques/T1059.005/ T1059.005], 
+[https://attack.mitre.org/techniques/T1059/ T1059]
+|
+Visual Basic, 
+Command and Scripting Interpreter
+|
+Execution, 
+Execution
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Winhlp32_spawning_a_process|Winhlp32 Spawning a Process]]
+
+|
+[https://attack.mitre.org/techniques/T1055/ T1055]
+|
+Process Injection
+|
+Defense Evasion, Privilege Escalation
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Wscript_or_cscript_suspicious_child_process|Wscript Or Cscript Suspicious Child Process]]
+
+|
+[https://attack.mitre.org/techniques/T1055/ T1055], 
+[https://attack.mitre.org/techniques/T1543/ T1543], 
+[https://attack.mitre.org/techniques/T1134.004/ T1134.004], 
+[https://attack.mitre.org/techniques/T1134/ T1134]
+|
+Process Injection, 
+Create or Modify System Process, 
+Parent PID Spoofing, 
+Access Token Manipulation
+|
+Defense Evasion, Privilege Escalation, 
+Persistence, Privilege Escalation, 
+Defense Evasion, Privilege Escalation, 
+Defense Evasion, Privilege Escalation
+
 | TTP
 |}
 
@@ -12703,10 +14636,13 @@ Leverage searches that allow you to detect and investigate unusual activities th
 | [[Documentation:ESSOC:detections:Detections#Allow_network_discovery_in_firewall|Allow Network Discovery In Firewall]]
 
 |
-[https://attack.mitre.org/techniques/T1562.007/ T1562.007]
+[https://attack.mitre.org/techniques/T1562.007/ T1562.007], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Cloud Firewall
+Disable or Modify Cloud Firewall, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12725,10 +14661,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Disable_windows_behavior_monitoring|Disable Windows Behavior Monitoring]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12747,10 +14686,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Msmpeng_application_dll_side_loading|Msmpeng Application DLL Side Loading]]
 
 |
-[https://attack.mitre.org/techniques/T1574.002/ T1574.002]
+[https://attack.mitre.org/techniques/T1574.002/ T1574.002], 
+[https://attack.mitre.org/techniques/T1574/ T1574]
 |
-DLL Side-Loading
+DLL Side-Loading, 
+Hijack Execution Flow
 |
+Persistence, Privilege Escalation, Defense Evasion, 
 Persistence, Privilege Escalation, Defense Evasion
 
 | TTP
@@ -12758,10 +14700,13 @@ Persistence, Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Powershell_disable_security_monitoring|Powershell Disable Security Monitoring]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12791,10 +14736,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Wbemprox_com_object_execution|Wbemprox COM Object Execution]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.003/ T1218.003]
 |
+Signed Binary Proxy Execution, 
 CMSTP
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -12884,10 +14832,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_bruteforce|Remote Desktop Network Bruteforce]]
 
 |
-[https://attack.mitre.org/techniques/T1021.001/ T1021.001]
+[https://attack.mitre.org/techniques/T1021.001/ T1021.001], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-Remote Desktop Protocol
+Remote Desktop Protocol, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | TTP
@@ -12895,10 +14846,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_traffic|Remote Desktop Network Traffic]]
 
 |
-[https://attack.mitre.org/techniques/T1021.001/ T1021.001]
+[https://attack.mitre.org/techniques/T1021.001/ T1021.001], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-Remote Desktop Protocol
+Remote Desktop Protocol, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -12917,10 +14871,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Ryuk_wake_on_lan_command|Ryuk Wake on LAN Command]]
 
 |
+[https://attack.mitre.org/techniques/T1059/ T1059], 
 [https://attack.mitre.org/techniques/T1059.003/ T1059.003]
 |
+Command and Scripting Interpreter, 
 Windows Command Shell
 |
+Execution, 
 Execution
 
 | TTP
@@ -12936,10 +14893,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Suspicious_scheduled_task_from_public_directory|Suspicious Scheduled Task from Public Directory]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | Anomaly
@@ -12958,10 +14918,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -12969,10 +14932,13 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_to_spawn_shell|WinEvent Scheduled Task Created to Spawn Shell]]
 
 |
-[https://attack.mitre.org/techniques/T1053.005/ T1053.005]
+[https://attack.mitre.org/techniques/T1053.005/ T1053.005], 
+[https://attack.mitre.org/techniques/T1053/ T1053]
 |
-Scheduled Task
+Scheduled Task, 
+Scheduled Task/Job
 |
+Execution, Persistence, Privilege Escalation, 
 Execution, Persistence, Privilege Escalation
 
 | TTP
@@ -12980,10 +14946,13 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Windows_disableantispyware_registry|Windows DisableAntiSpyware Registry]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -13053,26 +15022,32 @@ Leverage searches that allow you to detect and investigate unusual activities th
 
 |
 [https://attack.mitre.org/techniques/T1036.005/ T1036.005], 
-[https://attack.mitre.org/techniques/T1595/ T1595], 
-[https://attack.mitre.org/techniques/T1003/ T1003]
+[https://attack.mitre.org/techniques/T1036/ T1036], 
+[https://attack.mitre.org/techniques/T1003/ T1003], 
+[https://attack.mitre.org/techniques/T1595/ T1595]
 |
 Match Legitimate Name or Location, 
-Active Scanning, 
-OS Credential Dumping
+Masquerading, 
+OS Credential Dumping, 
+Active Scanning
 |
 Defense Evasion, 
-Reconnaissance, 
-Credential Access
+Defense Evasion, 
+Credential Access, 
+Reconnaissance
 
 | TTP
 |-
 | [[Documentation:ESSOC:detections:Detections#Batch_file_write_to_system32|Batch File Write to System32]]
 
 |
+[https://attack.mitre.org/techniques/T1204/ T1204], 
 [https://attack.mitre.org/techniques/T1204.002/ T1204.002]
 |
+User Execution, 
 Malicious File
 |
+Execution, 
 Execution
 
 | TTP
@@ -13113,10 +15088,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]]
 
 |
+[https://attack.mitre.org/techniques/T1021/ T1021], 
 [https://attack.mitre.org/techniques/T1021.002/ T1021.002]
 |
+Remote Services, 
 SMB/Windows Admin Shares
 |
+Lateral Movement, 
 Lateral Movement
 
 | TTP
@@ -13124,10 +15102,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]]
 
 |
+[https://attack.mitre.org/techniques/T1569/ T1569], 
 [https://attack.mitre.org/techniques/T1569.002/ T1569.002]
 |
+System Services, 
 Service Execution
 |
+Execution, 
 Execution
 
 | Hunting
@@ -13162,10 +15143,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_bruteforce|Remote Desktop Network Bruteforce]]
 
 |
-[https://attack.mitre.org/techniques/T1021.001/ T1021.001]
+[https://attack.mitre.org/techniques/T1021.001/ T1021.001], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-Remote Desktop Protocol
+Remote Desktop Protocol, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | TTP
@@ -13173,10 +15157,13 @@ Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_traffic|Remote Desktop Network Traffic]]
 
 |
-[https://attack.mitre.org/techniques/T1021.001/ T1021.001]
+[https://attack.mitre.org/techniques/T1021.001/ T1021.001], 
+[https://attack.mitre.org/techniques/T1021/ T1021]
 |
-Remote Desktop Protocol
+Remote Desktop Protocol, 
+Remote Services
 |
+Lateral Movement, 
 Lateral Movement
 
 | Anomaly
@@ -13257,10 +15244,13 @@ Leverage searches that allow you to detect and investigate unusual activities th
 | [[Documentation:ESSOC:detections:Detections#Account_discovery_with_net_app|Account Discovery With Net App]]
 
 |
-[https://attack.mitre.org/techniques/T1087.002/ T1087.002]
+[https://attack.mitre.org/techniques/T1087.002/ T1087.002], 
+[https://attack.mitre.org/techniques/T1087/ T1087]
 |
-Domain Account
+Domain Account, 
+Account Discovery
 |
+Discovery, 
 Discovery
 
 | TTP
@@ -13268,10 +15258,13 @@ Discovery
 | [[Documentation:ESSOC:detections:Detections#Attempt_to_stop_security_service|Attempt To Stop Security Service]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -13290,10 +15283,13 @@ Defense Evasion, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Mshta_spawning_rundll32_or_regsvr32_process|Mshta spawning Rundll32 OR Regsvr32 Process]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.005/ T1218.005]
 |
+Signed Binary Proxy Execution, 
 Mshta
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -13301,10 +15297,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Office_application_spawn_rundll32_process|Office Application Spawn rundll32 process]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -13312,10 +15311,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_document_executing_macro_code|Office Document Executing Macro Code]]
 
 |
+[https://attack.mitre.org/techniques/T1566/ T1566], 
 [https://attack.mitre.org/techniques/T1566.001/ T1566.001]
 |
+Phishing, 
 Spearphishing Attachment
 |
+Initial Access, 
 Initial Access
 
 | TTP
@@ -13323,10 +15325,13 @@ Initial Access
 | [[Documentation:ESSOC:detections:Detections#Office_product_spawn_cmd_process|Office Product Spawn CMD Process]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.005/ T1218.005]
 |
+Signed Binary Proxy Execution, 
 Mshta
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -13356,10 +15361,13 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_startw|Suspicious Rundll32 StartW]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -13378,10 +15386,13 @@ Defense Evasion, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Wermgr_process_connecting_to_ip_check_web_services|Wermgr Process Connecting To IP Check Web Services]]
 
 |
+[https://attack.mitre.org/techniques/T1590/ T1590], 
 [https://attack.mitre.org/techniques/T1590.005/ T1590.005]
 |
+Gather Victim Network Information, 
 IP Addresses
 |
+Reconnaissance, 
 Reconnaissance
 
 | TTP
@@ -13411,10 +15422,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Write_executable_in_smb_share|Write Executable in SMB Share]]
 
 |
+[https://attack.mitre.org/techniques/T1021/ T1021], 
 [https://attack.mitre.org/techniques/T1021.002/ T1021.002]
 |
+Remote Services, 
 SMB/Windows Admin Shares
 |
+Lateral Movement, 
 Lateral Movement
 
 | TTP
@@ -13469,16 +15483,19 @@ Quickly identify systems running new or unusual processes in your environment th
 
 |
 [https://attack.mitre.org/techniques/T1036.005/ T1036.005], 
-[https://attack.mitre.org/techniques/T1595/ T1595], 
-[https://attack.mitre.org/techniques/T1003/ T1003]
+[https://attack.mitre.org/techniques/T1036/ T1036], 
+[https://attack.mitre.org/techniques/T1003/ T1003], 
+[https://attack.mitre.org/techniques/T1595/ T1595]
 |
 Match Legitimate Name or Location, 
-Active Scanning, 
-OS Credential Dumping
+Masquerading, 
+OS Credential Dumping, 
+Active Scanning
 |
 Defense Evasion, 
-Reconnaissance, 
-Credential Access
+Defense Evasion, 
+Credential Access, 
+Reconnaissance
 
 | TTP
 |-
@@ -13610,10 +15627,38 @@ Execution, Lateral Movement
 | [[Documentation:ESSOC:detections:Detections#Rundll_loading_dll_by_ordinal|RunDLL Loading DLL By Ordinal]]
 
 |
+[https://attack.mitre.org/techniques/T1218/ T1218], 
 [https://attack.mitre.org/techniques/T1218.011/ T1218.011]
 |
+Signed Binary Proxy Execution, 
 Rundll32
 |
+Defense Evasion, 
+Defense Evasion
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Rundll32_shimcache_flush|Rundll32 Shimcache Flush]]
+
+|
+[https://attack.mitre.org/techniques/T1112/ T1112]
+|
+Modify Registry
+|
+Defense Evasion
+
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Suspicious_copy_on_system32|Suspicious Copy on System32]]
+
+|
+[https://attack.mitre.org/techniques/T1036.003/ T1036.003], 
+[https://attack.mitre.org/techniques/T1036/ T1036]
+|
+Rename System Utilities, 
+Masquerading
+|
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -13621,10 +15666,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#System_processes_run_from_unexpected_locations|System Processes Run From Unexpected Locations]]
 
 |
+[https://attack.mitre.org/techniques/T1036/ T1036], 
 [https://attack.mitre.org/techniques/T1036.003/ T1036.003]
 |
+Masquerading, 
 Rename System Utilities
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -13653,6 +15701,20 @@ Defense Evasion
 
 | Anomaly
 |-
+| [[Documentation:ESSOC:detections:Detections#Verclsid_clsid_execution|Verclsid CLSID Execution]]
+
+|
+[https://attack.mitre.org/techniques/T1218.012/ T1218.012], 
+[https://attack.mitre.org/techniques/T1218/ T1218]
+|
+Verclsid, 
+Signed Binary Proxy Execution
+|
+Defense Evasion, 
+Defense Evasion
+
+| Hunting
+|-
 | [[Documentation:ESSOC:detections:Detections#Winrm_spawning_a_process|WinRM Spawning a Process]]
 
 |
@@ -13662,6 +15724,26 @@ Exploit Public-Facing Application
 |
 Initial Access
 
+| TTP
+|-
+| [[Documentation:ESSOC:detections:Detections#Wscript_or_cscript_suspicious_child_process|Wscript Or Cscript Suspicious Child Process]]
+
+|
+[https://attack.mitre.org/techniques/T1055/ T1055], 
+[https://attack.mitre.org/techniques/T1543/ T1543], 
+[https://attack.mitre.org/techniques/T1134.004/ T1134.004], 
+[https://attack.mitre.org/techniques/T1134/ T1134]
+|
+Process Injection, 
+Create or Modify System Process, 
+Parent PID Spoofing, 
+Access Token Manipulation
+|
+Defense Evasion, Privilege Escalation, 
+Persistence, Privilege Escalation, 
+Defense Evasion, Privilege Escalation, 
+Defense Evasion, Privilege Escalation
+
 | TTP
 |}
 
@@ -13717,10 +15799,13 @@ Detect and investigate suspected abuse of file extensions and Windows file assoc
 | [[Documentation:ESSOC:detections:Detections#Execution_of_file_with_multiple_extensions|Execution of File with Multiple Extensions]]
 
 |
+[https://attack.mitre.org/techniques/T1036/ T1036], 
 [https://attack.mitre.org/techniques/T1036.003/ T1036.003]
 |
+Masquerading, 
 Rename System Utilities
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -13766,10 +15851,13 @@ Windows services are often used by attackers for persistence and the ability to
 | [[Documentation:ESSOC:detections:Detections#First_time_seen_running_windows_service|First Time Seen Running Windows Service]]
 
 |
+[https://attack.mitre.org/techniques/T1569/ T1569], 
 [https://attack.mitre.org/techniques/T1569.002/ T1569.002]
 |
+System Services, 
 Service Execution
 |
+Execution, 
 Execution
 
 | Anomaly
@@ -13811,10 +15899,13 @@ Execution
 | [[Documentation:ESSOC:detections:Detections#Reg_exe_manipulating_windows_services_registry_keys|Reg exe Manipulating Windows Services Registry Keys]]
 
 |
-[https://attack.mitre.org/techniques/T1574.011/ T1574.011]
+[https://attack.mitre.org/techniques/T1574.011/ T1574.011], 
+[https://attack.mitre.org/techniques/T1574/ T1574]
 |
-Services Registry Permissions Weakness
+Services Registry Permissions Weakness, 
+Hijack Execution Flow
 |
+Persistence, Privilege Escalation, Defense Evasion, 
 Persistence, Privilege Escalation, Defense Evasion
 
 | TTP
@@ -13822,10 +15913,13 @@ Persistence, Privilege Escalation, Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]]
 
 |
-[https://attack.mitre.org/techniques/T1543.003/ T1543.003]
+[https://attack.mitre.org/techniques/T1543.003/ T1543.003], 
+[https://attack.mitre.org/techniques/T1543/ T1543]
 |
-Windows Service
+Windows Service, 
+Create or Modify System Process
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -13874,16 +15968,19 @@ Leverage searches that allow you to detect and investigate unusual activities th
 
 |
 [https://attack.mitre.org/techniques/T1036.005/ T1036.005], 
-[https://attack.mitre.org/techniques/T1595/ T1595], 
-[https://attack.mitre.org/techniques/T1003/ T1003]
+[https://attack.mitre.org/techniques/T1036/ T1036], 
+[https://attack.mitre.org/techniques/T1003/ T1003], 
+[https://attack.mitre.org/techniques/T1595/ T1595]
 |
 Match Legitimate Name or Location, 
-Active Scanning, 
-OS Credential Dumping
+Masquerading, 
+OS Credential Dumping, 
+Active Scanning
 |
 Defense Evasion, 
-Reconnaissance, 
-Credential Access
+Defense Evasion, 
+Credential Access, 
+Reconnaissance
 
 | TTP
 |-
@@ -13956,10 +16053,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Disable_windows_app_hotkeys|Disable Windows App Hotkeys]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -14044,10 +16144,13 @@ Impact
 | [[Documentation:ESSOC:detections:Detections#Excessive_usage_of_taskkill|Excessive Usage Of Taskkill]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | Anomaly
@@ -14077,10 +16180,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Hide_user_account_from_sign-in_screen|Hide User Account From Sign-In Screen]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -14132,10 +16238,13 @@ Defense Evasion
 | [[Documentation:ESSOC:detections:Detections#Process_kill_base_on_file_path|Process Kill Base On File Path]]
 
 |
-[https://attack.mitre.org/techniques/T1562.001/ T1562.001]
+[https://attack.mitre.org/techniques/T1562.001/ T1562.001], 
+[https://attack.mitre.org/techniques/T1562/ T1562]
 |
-Disable or Modify Tools
+Disable or Modify Tools, 
+Impair Defenses
 |
+Defense Evasion, 
 Defense Evasion
 
 | TTP
@@ -14154,10 +16263,13 @@ Execution, Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Suspicious_driver_loaded_path|Suspicious Driver Loaded Path]]
 
 |
-[https://attack.mitre.org/techniques/T1543.003/ T1543.003]
+[https://attack.mitre.org/techniques/T1543.003/ T1543.003], 
+[https://attack.mitre.org/techniques/T1543/ T1543]
 |
-Windows Service
+Windows Service, 
+Create or Modify System Process
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -14176,10 +16288,13 @@ Persistence, Privilege Escalation
 | [[Documentation:ESSOC:detections:Detections#Xmrig_driver_loaded|XMRIG Driver Loaded]]
 
 |
-[https://attack.mitre.org/techniques/T1543.003/ T1543.003]
+[https://attack.mitre.org/techniques/T1543.003/ T1543.003], 
+[https://attack.mitre.org/techniques/T1543/ T1543]
 |
-Windows Service
+Windows Service, 
+Create or Modify System Process
 |
+Persistence, Privilege Escalation, 
 Persistence, Privilege Escalation
 
 | TTP
@@ -14348,7 +16463,7 @@ Discovery
 
 #############
 # Automatically generated by doc_gen.py in https://github.com/splunk/security_content
-# On Date: 2021-10-14 15:40:37.356079 UTC
+# On Date: 2021-10-22 23:24:28.217163 UTC
 # Author: Splunk Security Research
 # Contact: research@splunk.com
 #############