mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -61,9 +61,12 @@ def outputResultsJSON(output_filename:str, data:list[dict], baseline:OrderedDict
|
||||
fail_list = [os.path.join("security_content/detections",x['detection_file'] ) for x in data_sorted if x['success'] == False]
|
||||
|
||||
if len(fail_list) > 0:
|
||||
|
||||
print("FAILURES:")
|
||||
for failed_test in fail_list:
|
||||
print(f"\t{failed_test}")
|
||||
failures_test_override = copy.deepcopy(summarization_reproduce_failure_config)
|
||||
failures_test_override.update({"detections_list": fail_list, "no_interactive_failure":False,
|
||||
#Force all tests to be interactive, even if they don't fail (because they failed on this test)
|
||||
failures_test_override.update({"detections_list": fail_list, "no_interactive_failure":False, "interactive": True,
|
||||
"num_containers":1, "branch": baseline["branch"], "commit_hash":baseline["commit_hash"],
|
||||
"mode":"selected", "show_splunk_app_password": True})
|
||||
with open(os.path.join(output_folder,failure_manifest_filename),"w") as failures:
|
||||
|
||||
@@ -34,8 +34,8 @@ class Baseline(BaseModel, SecurityContentObject):
|
||||
|
||||
@validator('name')
|
||||
def name_max_length(cls, v):
|
||||
if len(v) > 75:
|
||||
raise ValueError('name is longer then 75 chars: ' + v)
|
||||
if len(v) > 67:
|
||||
raise ValueError('name is longer then 67 chars: ' + v)
|
||||
return v
|
||||
|
||||
@validator('name')
|
||||
|
||||
@@ -52,11 +52,11 @@ class Detection(BaseModel, SecurityContentObject):
|
||||
source: str = None
|
||||
|
||||
|
||||
@validator('name')
|
||||
def name_max_length(cls, v):
|
||||
if len(v) > 75:
|
||||
raise ValueError('name is longer then 75 chars: ' + v)
|
||||
return v
|
||||
# @validator('name')
|
||||
# def name_max_length(cls, v, values):
|
||||
# if len(v) > 67:
|
||||
# raise ValueError('name is longer then 67 chars: ' + v)
|
||||
# return v
|
||||
|
||||
@validator('name')
|
||||
def name_invalid_chars(cls, v):
|
||||
@@ -112,6 +112,14 @@ class Detection(BaseModel, SecurityContentObject):
|
||||
raise ValueError('Use source macro instead of eventtype, sourcetype, source or index in detection: ' + values["name"])
|
||||
return values
|
||||
|
||||
@root_validator
|
||||
def name_max_length(cls, values):
|
||||
# Check max length only for ESCU searches, SSA does not have that constraint
|
||||
if 'ssa_' not in values['file_path']:
|
||||
if len(values["name"]) > 67:
|
||||
raise ValueError('name is longer then 67 chars: ' + values["name"])
|
||||
return values
|
||||
|
||||
|
||||
# @validator('references')
|
||||
# def references_check(cls, v, values):
|
||||
|
||||
@@ -47,6 +47,7 @@ class ObjToYmlAdapter(Adapter):
|
||||
"kill_chain_phases": True,
|
||||
"mitre_attack_id": True,
|
||||
"risk_severity": True,
|
||||
"risk_score": True,
|
||||
"security_domain": True,
|
||||
"required_fields": True
|
||||
},
|
||||
|
||||
+1
@@ -50,6 +50,7 @@ tags:
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
+1
@@ -50,6 +50,7 @@ tags:
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
+2
-2
@@ -1,4 +1,4 @@
|
||||
name: Kubernetes Azure detect most active service accounts by pod namespace
|
||||
name: Kubernetes Azure active service accounts by pod namespace
|
||||
id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72
|
||||
version: 1
|
||||
date: '2020-05-26'
|
||||
@@ -11,7 +11,7 @@ search: '`kubernetes_azure` category=kube-audit | spath input=properties.log | s
|
||||
user.groups{}=system:serviceaccounts* OR user.username=system.anonymous OR annotations.authorization.k8s.io/decision=allow |
|
||||
table sourceIPs{} user.username userAgent verb responseStatus.reason responseStatus.status
|
||||
properties.pod objectRef.namespace | top sourceIPs{} user.username verb responseStatus.status
|
||||
properties.pod objectRef.namespace |`kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace_filter`'
|
||||
properties.pod objectRef.namespace |`kubernetes_azure_active_service_accounts_by_pod_namespace_filter`'
|
||||
how_to_implement: You must install the Add-on for Microsoft Cloud Services and Configure
|
||||
Kube-Audit data diagnostics
|
||||
known_false_positives: Not all service accounts interactions are malicious. Analyst
|
||||
+2
-2
@@ -1,4 +1,4 @@
|
||||
name: Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments
|
||||
name: Suspicious Powershell Command-Line Arguments
|
||||
id: 2cdb91d2-542c-497f-b252-be495e71f38c
|
||||
version: 6
|
||||
date: '2021-01-19'
|
||||
@@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe
|
||||
by Processes.user Processes.process_name Processes.parent_process_name Processes.dest |
|
||||
`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
|
||||
search (process=*-EncodedCommand* OR process=*-enc*) process=*-Exec* | `malicious_powershell_process___multiple_suspicious_command_line_arguments_filter`'
|
||||
search (process=*-EncodedCommand* OR process=*-enc*) process=*-Exec* | `suspicious_powershell_command_line_arguments_filter`'
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts to populate the Endpoint data model in the Processes node. You must also be
|
||||
ingesting logs with both the process name and command line from your endpoints.
|
||||
+2
-2
@@ -1,4 +1,4 @@
|
||||
name: Excessive number of distinct processes created in Windows Temp folder
|
||||
name: Excessive distinct processes from Windows Temp
|
||||
id: 23587b6a-c479-11eb-b671-acde48001122
|
||||
version: 2
|
||||
date: '2022-02-28'
|
||||
@@ -16,7 +16,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_path
|
||||
= "*\\Windows\\Temp\\*" by Processes.dest Processes.user _time span=20m | where
|
||||
distinct_process_count > 37 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `excessive_number_of_distinct_processes_created_in_windows_temp_folder_filter`'
|
||||
| `security_content_ctime(lastTime)` | `excessive_distinct_processes_from_windows_temp_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the full process path in the process field of CIM's Process data model.
|
||||
If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
+2
-2
@@ -1,4 +1,4 @@
|
||||
name: PowerShell Loading DotNET into Memory via System Reflection Assembly
|
||||
name: PowerShell Loading DotNET into Memory via Reflection
|
||||
id: 85bc3f30-ca28-11eb-bd21-acde48001122
|
||||
version: 1
|
||||
date: '2021-06-10'
|
||||
@@ -22,7 +22,7 @@ description: 'The following analytic utilizes PowerShell Script Block Logging (E
|
||||
search: '`powershell` EventCode=4104 Message IN ("*[system.reflection.assembly]::load(*","*[reflection.assembly]*")
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName
|
||||
User EventCode Message | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `powershell_loading_dotnet_into_memory_via_system_reflection_assembly_filter`'
|
||||
| `powershell_loading_dotnet_into_memory_via_reflection_filter`'
|
||||
how_to_implement: To successfully implement this analytic, you will need to enable
|
||||
PowerShell Script Block Logging on some or all endpoints. Additional setup here
|
||||
https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
|
||||
+2
-2
@@ -1,4 +1,4 @@
|
||||
name: Multiple Disabled Users Failing To Authenticate From Host Using Kerberos
|
||||
name: Windows Disabled Users Failing To Authenticate Kerberos
|
||||
id: 98f22d82-9d62-11eb-9fcf-acde48001122
|
||||
version: 1
|
||||
date: '2021-04-14'
|
||||
@@ -31,7 +31,7 @@ search: '`wineventlog_security` EventCode=4768 Account_Name!="*$" Result_Code=0x
|
||||
as tried_accounts by _time, Client_Address | eventstats avg(unique_accounts) as
|
||||
comp_avg , stdev(unique_accounts) as comp_std by Client_Address | eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1 | `multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos_filter` '
|
||||
| search isOutlier=1 | `windows_disabled_users_failing_to_authenticate_kerberos_filter` '
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
|
||||
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
|
||||
+2
-2
@@ -1,4 +1,4 @@
|
||||
name: Multiple Invalid Users Failing To Authenticate From Host Using Kerberos
|
||||
name: Windows Invalid Users Failed Authentication via Kerberos
|
||||
id: 001266a6-9d5b-11eb-829b-acde48001122
|
||||
version: 1
|
||||
date: '2021-04-14'
|
||||
@@ -31,7 +31,7 @@ search: '`wineventlog_security` EventCode=4768 Result_Code=0x6 Account_Name!="*$
|
||||
as tried_accounts by _time, Client_Address | eventstats avg(unique_accounts) as
|
||||
comp_avg , stdev(unique_accounts) as comp_std by Client_Address | eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1 | `multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos_filter` '
|
||||
| search isOutlier=1 | `windows_invalid_users_failed_authentication_via_kerberos_filter` '
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
|
||||
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
|
||||
+2
-2
@@ -1,4 +1,4 @@
|
||||
name: Multiple Users Attempting To Authenticate Using Explicit Credentials
|
||||
name: Windows Users Authenticate Using Explicit Credentials
|
||||
id: e61918fa-9ca4-11eb-836c-acde48001122
|
||||
version: 1
|
||||
date: '2021-04-13'
|
||||
@@ -32,7 +32,7 @@ search: ' `wineventlog_security` EventCode=4648 | bucket span=2m _time | eval So
|
||||
tried_account by _time, ComputerName, Source_Account | eventstats avg(unique_accounts)
|
||||
as comp_avg , stdev(unique_accounts) as comp_std by ComputerName | eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1 | `multiple_users_attempting_to_authenticate_using_explicit_credentials_filter` '
|
||||
| search isOutlier=1 | `windows_users_authenticate_using_explicit_credentials_filter` '
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Windows Event Logs from domain controllers as well as member servers and workstations.
|
||||
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
|
||||
+2
-2
@@ -1,4 +1,4 @@
|
||||
name: Microsoft Exchange Mailbox Replication service writing Active Server Pages
|
||||
name: MS Exchange Mailbox Replication service writing Active Server Pages
|
||||
id: 985f322c-57a5-11ec-b9ac-acde48001122
|
||||
version: 1
|
||||
date: '2021-12-07'
|
||||
@@ -37,7 +37,7 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint
|
||||
Filesystem.file_create_time Filesystem.file_name Filesystem.file_path | `drop_dm_object_name(Filesystem)`
|
||||
| fields _time dest file_create_time file_name file_path process_name process_path
|
||||
process process_guid] | dedup file_create_time | table dest file_create_time, file_name,
|
||||
file_path, process_name | `microsoft_exchange_mailbox_replication_service_writing_active_server_pages_filter`'
|
||||
file_path, process_name | `ms_exchange_mailbox_replication_service_writing_active_server_pages_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem`
|
||||
Vendored
+1
@@ -65,6 +65,7 @@ tags:
|
||||
- dest_user_id
|
||||
- dest_device_id
|
||||
- authentication_method
|
||||
risk_score: 72
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
Vendored
+1
@@ -66,6 +66,7 @@ tags:
|
||||
- dest_user_id
|
||||
- origin_device_id
|
||||
- authentication_method
|
||||
risk_score: 64
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
@@ -63,6 +63,7 @@ tags:
|
||||
- dest_device_id
|
||||
- _time
|
||||
- process_name
|
||||
risk_score: 25
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
+6
-12
@@ -12,18 +12,11 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map
|
||||
event_id=ucast(map_get(input_event, "event_id"), "string", null) | where process_name
|
||||
IS NOT NULL AND parent_process_name IS NOT NULL | where like(process_name, "7z%")
|
||||
OR process_name="WinRAR.exe" OR like(process_name, "winzip%") | where like(parent_process_name,
|
||||
"%cmd.exe") OR like(parent_process_name, "%powershell.exe") | eval body=create_map("category_id", 101, "class_id", 101000, "detection_start_time", start_time,
|
||||
"detection_end_time", end_time, "device_entities", [create_map("uid", ucast(map_get(input_event, "enrichments.device_entities.device.uid"), "string", null), "type_id", 0)],
|
||||
"disposition_id", 1, "end_time", end_time, "event_id", 10100001, "event_time", timestamp,
|
||||
"finding", create_map("confidence", 60, "confidence_id", 2,
|
||||
"context_ids", [10, 49], "impact", 70, "impact_id", 4,
|
||||
"kill_chain_phase", Exploitation, "kill_chain_phase_id", 4,
|
||||
"risk_level", Medium, "risk_level_id", 2, "type_id", 1, "ref_event_uid", event_id),
|
||||
"message", An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading of 7zip., "metadata", create_map("log_name", Endpoint_Processes, "version",
|
||||
"1.0.0"), "observables", , "origin", create_map("product", create_map("name", "Splunk Behavioral Analytics")),
|
||||
"rule", create_map("name", "Anomalous usage of Archive Tools", "uid", "63614a58-10e2-4c6c-ae81-ea1113681439", "version", "1"), "start_time", start_time, "time", start_time,
|
||||
"user_entities", [create_map("uid", ucast(map_get(input_event, "enrichments.user_entities.user.uid"),"string", null))])
|
||||
| into write_ssa_finding_events();'
|
||||
"%cmd.exe") OR like(parent_process_name, "%powershell.exe") | eval start_time=timestamp,
|
||||
end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"),
|
||||
"string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)),
|
||||
body=create_map(["event_id", event_id, "process_name", process_name, "parent_process_name",
|
||||
parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
@@ -50,6 +43,7 @@ tags:
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -52,6 +52,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 36
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -51,6 +51,7 @@ tags:
|
||||
- process_path
|
||||
- dest_user_id
|
||||
- process
|
||||
risk_score: 36
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
risk_severity: high
|
||||
test:
|
||||
|
||||
@@ -51,6 +51,7 @@ tags:
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 90
|
||||
security_domain: endpoint
|
||||
risk_severity: high
|
||||
test:
|
||||
|
||||
+1
@@ -50,6 +50,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
- _time
|
||||
- dest_device_id
|
||||
- process
|
||||
risk_score: 70
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
- dest_device_id
|
||||
- dest_user_id
|
||||
- cmd_line
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -54,6 +54,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -51,6 +51,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -34,8 +34,8 @@ tags:
|
||||
analytic_story:
|
||||
- Suspicious DNS Traffic
|
||||
- Dynamic DNS
|
||||
- Command & Control
|
||||
- Data Exfiltration
|
||||
- Command and Control
|
||||
cis20: []
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
@@ -51,6 +51,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 72
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
+1
@@ -43,6 +43,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 54
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
- PR.IP
|
||||
required_fields:
|
||||
- _time
|
||||
risk_score: 72
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
@@ -50,6 +50,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -50,6 +50,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 64
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
@@ -59,6 +59,7 @@ tags:
|
||||
- process_id
|
||||
- process_path
|
||||
- cmd_line
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -246,6 +246,7 @@ tags:
|
||||
- _time
|
||||
- dest_user_id
|
||||
- process_path
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
+1
@@ -48,6 +48,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 35
|
||||
security_domain: network
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -48,6 +48,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 15
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -52,6 +52,7 @@ tags:
|
||||
- process_path
|
||||
- dest_user_id
|
||||
- process
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
@@ -48,6 +48,7 @@ tags:
|
||||
- process_path
|
||||
- dest_user_id
|
||||
- process
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
@@ -55,6 +55,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
@@ -59,6 +59,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -53,6 +53,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 40
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -50,6 +50,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 90
|
||||
security_domain: endpoint
|
||||
risk_severity: high
|
||||
test:
|
||||
|
||||
@@ -51,6 +51,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 90
|
||||
security_domain: endpoint
|
||||
risk_severity: high
|
||||
test:
|
||||
|
||||
@@ -62,6 +62,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
risk_severity: high
|
||||
test:
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -56,6 +56,7 @@ tags:
|
||||
- registry_value_type
|
||||
- registry_value_data
|
||||
- process_guid
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
risk_severity: high
|
||||
test:
|
||||
|
||||
@@ -53,6 +53,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
risk_severity: high
|
||||
test:
|
||||
|
||||
@@ -55,6 +55,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
risk_severity: high
|
||||
test:
|
||||
|
||||
@@ -53,6 +53,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
risk_severity: high
|
||||
test:
|
||||
|
||||
+1
@@ -62,6 +62,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -55,6 +55,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -51,6 +51,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
risk_severity: low
|
||||
test:
|
||||
|
||||
@@ -51,6 +51,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
risk_severity: high
|
||||
test:
|
||||
|
||||
@@ -56,6 +56,7 @@ tags:
|
||||
- dest_user_id
|
||||
- process
|
||||
- cmd_line
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
risk_severity: medium
|
||||
test:
|
||||
|
||||
+3
-3
@@ -1,7 +1,7 @@
|
||||
name: Excessive number of distinct processes created in Windows Temp folder Unit Test
|
||||
name: Excessive distinct processes from Windows Temp Unit Test
|
||||
tests:
|
||||
- name: Excessive number of distinct processes created in Windows Temp folder
|
||||
file: endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml
|
||||
- name: Excessive distinct processes from Windows Temp
|
||||
file: endpoint/excessive_distinct_processes_from_windows_temp.yml
|
||||
pass_condition: '| stats count | where count > 0'
|
||||
earliest_time: -24h
|
||||
latest_time: now
|
||||
+3
-3
@@ -1,7 +1,7 @@
|
||||
name: PowerShell Loading DotNET into Memory via System Reflection Assembly Unit Test
|
||||
name: PowerShell Loading DotNET into Memory via Reflection Unit Test
|
||||
tests:
|
||||
- name: PowerShell Loading DotNET into Memory via System Reflection Assembly
|
||||
file: endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml
|
||||
- name: PowerShell Loading DotNET into Memory via Reflection
|
||||
file: endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml
|
||||
pass_condition: '| stats count | where count > 0'
|
||||
earliest_time: -24h
|
||||
latest_time: now
|
||||
+3
-4
@@ -1,8 +1,7 @@
|
||||
name: Multiple Disabled Users Failing To Authenticate From Host Using Kerberos Unit
|
||||
Test
|
||||
name: Windows Disabled Users Failing To Authenticate Using Kerberos Unit Test
|
||||
tests:
|
||||
- name: Multiple Disabled Users Failing To Authenticate From Host Using Kerberos
|
||||
file: endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml
|
||||
- name: Windows Disabled Users Failing To Authenticate Using Kerberos
|
||||
file: endpoint/windows_disabled_users_failing_to_authenticate_kerberos.yml
|
||||
pass_condition: '| stats count | where count > 0'
|
||||
earliest_time: -24h
|
||||
latest_time: now
|
||||
+3
-4
@@ -1,8 +1,7 @@
|
||||
name: Multiple Invalid Users Failing To Authenticate From Host Using Kerberos Unit
|
||||
Test
|
||||
name: Windows Invalid Users Failed Authentication via Kerberos Unit Test
|
||||
tests:
|
||||
- name: Multiple Invalid Users Failing To Authenticate From Host Using Kerberos
|
||||
file: endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml
|
||||
- name: Windows Invalid Users Failed Authentication via Kerberos
|
||||
file: endpoint/windows_invalid_users_failed_authentication_via_kerberos.yml
|
||||
pass_condition: '| stats count | where count > 0'
|
||||
earliest_time: -24h
|
||||
latest_time: now
|
||||
+3
-3
@@ -1,7 +1,7 @@
|
||||
name: Multiple Users Attempting To Authenticate Using Explicit Credentials Unit Test
|
||||
name: Windows Users Authenticate Using Explicit Credentials Unit Test
|
||||
tests:
|
||||
- name: Multiple Users Attempting To Authenticate Using Explicit Credentials
|
||||
file: endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml
|
||||
- name: Windows Users Authenticate Using Explicit Credentials
|
||||
file: endpoint/windows_users_authenticate_using_explicit_credentials.yml
|
||||
pass_condition: '| stats count | where count > 0'
|
||||
earliest_time: -24h
|
||||
latest_time: now
|
||||
Reference in New Issue
Block a user