From 7fa41599d58b1999b76fa7cdeeb5d0629efe9e77 Mon Sep 17 00:00:00 2001 From: bpatel Date: Mon, 14 Dec 2020 20:29:04 -0800 Subject: [PATCH] adding sunburst as tags for relavant detections --- baselines/previously_seen_running_windows_services.yml | 1 + baselines/previously_seen_running_windows_services_update.yml | 1 + .../endpoint/detect_prohibited_applications_spawning_cmd_exe.yml | 1 + detections/endpoint/first_time_seen_running_windows_service.yml | 1 + .../endpoint/malicious_powershell_process___encoded_command.yml | 1 + detections/endpoint/sc_exe_manipulating_windows_services.yml | 1 + detections/network/detect_outbound_smb_traffic.yml | 1 + detections/network/tor_traffic.yml | 1 + 8 files changed, 8 insertions(+) diff --git a/baselines/previously_seen_running_windows_services.yml b/baselines/previously_seen_running_windows_services.yml index 37950e87a4..2dedd1dbde 100644 --- a/baselines/previously_seen_running_windows_services.yml +++ b/baselines/previously_seen_running_windows_services.yml @@ -17,6 +17,7 @@ tags: analytics_story: - Orangeworm Attack Group - Windows Service Abuse + - Sunburst Malware detections: - First Time Seen Running Windows Service deployments: diff --git a/baselines/previously_seen_running_windows_services_update.yml b/baselines/previously_seen_running_windows_services_update.yml index 529ad04e56..83b87efc65 100644 --- a/baselines/previously_seen_running_windows_services_update.yml +++ b/baselines/previously_seen_running_windows_services_update.yml @@ -22,6 +22,7 @@ tags: analytics_story: - Orangeworm Attack Group - Windows Service Abuse + - Sunburst Malware detections: - First Time Seen Running Windows Service deployments: diff --git a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml index a7f7cbbbac..70843ce6c3 100644 --- a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml +++ b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml @@ -25,6 +25,7 @@ tags: - Suspicious Command-Line Executions - Suspicious MSHTA Activity - Suspicious Zoom Child Processes + - Sunburst Malware mitre_attack_id: - T1059.003 kill_chain_phases: diff --git a/detections/endpoint/first_time_seen_running_windows_service.yml b/detections/endpoint/first_time_seen_running_windows_service.yml index d7899b0a52..d42c148b37 100644 --- a/detections/endpoint/first_time_seen_running_windows_service.yml +++ b/detections/endpoint/first_time_seen_running_windows_service.yml @@ -28,6 +28,7 @@ tags: analytics_story: - Windows Service Abuse - Orangeworm Attack Group + - Sunburst Malware mitre_attack_id: - T1569.002 kill_chain_phases: diff --git a/detections/endpoint/malicious_powershell_process___encoded_command.yml b/detections/endpoint/malicious_powershell_process___encoded_command.yml index ad3cf74be0..ac7aebd11d 100644 --- a/detections/endpoint/malicious_powershell_process___encoded_command.yml +++ b/detections/endpoint/malicious_powershell_process___encoded_command.yml @@ -23,6 +23,7 @@ known_false_positives: System administrators may use this option, but it's not c tags: analytics_story: - Malicious PowerShell + - Sunburst Malware mitre_attack_id: - T1027 kill_chain_phases: diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index b0602294d1..05d618c672 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -23,6 +23,7 @@ tags: - Orangeworm Attack Group - Windows Persistence Techniques - Disabling Security Tools + - Sunburst Malware mitre_attack_id: - T1543.003 kill_chain_phases: diff --git a/detections/network/detect_outbound_smb_traffic.yml b/detections/network/detect_outbound_smb_traffic.yml index be0e40a9df..d663e10880 100644 --- a/detections/network/detect_outbound_smb_traffic.yml +++ b/detections/network/detect_outbound_smb_traffic.yml @@ -37,6 +37,7 @@ tags: analytics_story: - Hidden Cobra Malware - DHS Report TA18-074A + - Sunburst Malware mitre_attack_id: - T1071.002 kill_chain_phases: diff --git a/detections/network/tor_traffic.yml b/detections/network/tor_traffic.yml index 1e04bd5905..c05ee864cd 100644 --- a/detections/network/tor_traffic.yml +++ b/detections/network/tor_traffic.yml @@ -24,6 +24,7 @@ tags: - Prohibited Traffic Allowed or Protocol Mismatch - Ransomware - Command and Control + - Sunburst Malware mitre_attack_id: - T1071.001 kill_chain_phases: