adding sunburst as tags for relavant detections

This commit is contained in:
bpatel
2020-12-14 20:29:04 -08:00
parent ecc74e967e
commit 7fa41599d5
8 changed files with 8 additions and 0 deletions
@@ -17,6 +17,7 @@ tags:
analytics_story:
- Orangeworm Attack Group
- Windows Service Abuse
- Sunburst Malware
detections:
- First Time Seen Running Windows Service
deployments:
@@ -22,6 +22,7 @@ tags:
analytics_story:
- Orangeworm Attack Group
- Windows Service Abuse
- Sunburst Malware
detections:
- First Time Seen Running Windows Service
deployments:
@@ -25,6 +25,7 @@ tags:
- Suspicious Command-Line Executions
- Suspicious MSHTA Activity
- Suspicious Zoom Child Processes
- Sunburst Malware
mitre_attack_id:
- T1059.003
kill_chain_phases:
@@ -28,6 +28,7 @@ tags:
analytics_story:
- Windows Service Abuse
- Orangeworm Attack Group
- Sunburst Malware
mitre_attack_id:
- T1569.002
kill_chain_phases:
@@ -23,6 +23,7 @@ known_false_positives: System administrators may use this option, but it's not c
tags:
analytics_story:
- Malicious PowerShell
- Sunburst Malware
mitre_attack_id:
- T1027
kill_chain_phases:
@@ -23,6 +23,7 @@ tags:
- Orangeworm Attack Group
- Windows Persistence Techniques
- Disabling Security Tools
- Sunburst Malware
mitre_attack_id:
- T1543.003
kill_chain_phases:
@@ -37,6 +37,7 @@ tags:
analytics_story:
- Hidden Cobra Malware
- DHS Report TA18-074A
- Sunburst Malware
mitre_attack_id:
- T1071.002
kill_chain_phases:
+1
View File
@@ -24,6 +24,7 @@ tags:
- Prohibited Traffic Allowed or Protocol Mismatch
- Ransomware
- Command and Control
- Sunburst Malware
mitre_attack_id:
- T1071.001
kill_chain_phases: