mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -7,4 +7,4 @@ class JsonWriter():
|
||||
def writeJsonObject(file_path : str, obj) -> None:
|
||||
|
||||
with open(file_path, 'w') as outfile:
|
||||
json.dump(obj, outfile, ensure_ascii=False, indent=4)
|
||||
json.dump(obj, outfile, ensure_ascii=False)
|
||||
+63
-75
@@ -30,14 +30,14 @@ T1608.003,Install Digital Certificate,Resource Development,no
|
||||
T1608.002,Upload Tool,Resource Development,Threat Group-3390
|
||||
T1608.001,Upload Malware,Resource Development,TeamTNT|APT32
|
||||
T1608,Stage Capabilities,Resource Development,no
|
||||
T1016.001,Internet Connection Discovery,Discovery,APT29|UNC2452|Turla
|
||||
T1016.001,Internet Connection Discovery,Discovery,APT29|Turla
|
||||
T1553.005,Mark-of-the-Web Bypass,Defense Evasion,TA505
|
||||
T1555.005,Password Managers,Credential Access,Fox Kitten|Operation Wocao
|
||||
T1484.002,Domain Trust Modification,Defense Evasion|Privilege Escalation,APT29|UNC2452
|
||||
T1484.002,Domain Trust Modification,Defense Evasion|Privilege Escalation,APT29
|
||||
T1484.001,Group Policy Modification,Defense Evasion|Privilege Escalation,Indrik Spider
|
||||
T1547.014,Active Setup,Persistence|Privilege Escalation,no
|
||||
T1606.002,SAML Tokens,Credential Access,APT29|UNC2452
|
||||
T1606.001,Web Cookies,Credential Access,APT29|UNC2452
|
||||
T1606.002,SAML Tokens,Credential Access,APT29
|
||||
T1606.001,Web Cookies,Credential Access,APT29
|
||||
T1606,Forge Web Credentials,Credential Access,no
|
||||
T1555.004,Windows Credential Manager,Credential Access,Stealth Falcon|OilRig|Turla
|
||||
T1059.008,Network Device CLI,Execution,no
|
||||
@@ -111,7 +111,7 @@ T1588,Obtain Capabilities,Resource Development,no
|
||||
T1587.004,Exploits,Resource Development,no
|
||||
T1587.003,Digital Certificates,Resource Development,APT29|PROMETHIUM
|
||||
T1587.002,Code Signing Certificates,Resource Development,PROMETHIUM|Patchwork
|
||||
T1587.001,Malware,Resource Development,TeamTNT|APT29|Lazarus Group|UNC2452|Sandworm Team|Turla|FIN7|Night Dragon|Cleaver
|
||||
T1587.001,Malware,Resource Development,TeamTNT|APT29|Lazarus Group|Sandworm Team|Turla|FIN7|Night Dragon|Cleaver
|
||||
T1587,Develop Capabilities,Resource Development,Kimsuky
|
||||
T1586.002,Email Accounts,Resource Development,IndigoZebra|Leviathan|Magic Hound|Kimsuky
|
||||
T1586.001,Social Media Accounts,Resource Development,Leviathan
|
||||
@@ -124,14 +124,14 @@ T1584.005,Botnet,Resource Development,no
|
||||
T1584.004,Server,Resource Development,Indrik Spider|Turla|APT16
|
||||
T1584.003,Virtual Private Server,Resource Development,Turla
|
||||
T1584.002,DNS Server,Resource Development,no
|
||||
T1584.001,Domains,Resource Development,Transparent Tribe|Magic Hound|APT29|UNC2452|APT1
|
||||
T1584.001,Domains,Resource Development,Transparent Tribe|Magic Hound|APT29|APT1
|
||||
T1583.006,Web Services,Resource Development,IndigoZebra|ZIRCONIUM|MuddyWater|HAFNIUM|Lazarus Group|Turla|APT32|APT17|APT29
|
||||
T1583.005,Botnet,Resource Development,no
|
||||
T1583.004,Server,Resource Development,GALLIUM|Sandworm Team
|
||||
T1583.003,Virtual Private Server,Resource Development,HAFNIUM|TEMP.Veles
|
||||
T1583.002,DNS Server,Resource Development,no
|
||||
T1584,Compromise Infrastructure,Resource Development,no
|
||||
T1583.001,Domains,Resource Development,IndigoZebra|TeamTNT|Ferocious Kitten|FIN7|Transparent Tribe|Leviathan|Magic Hound|APT29|Mustang Panda|ZIRCONIUM|UNC2452|Lazarus Group|Silent Librarian|menuPass|Sandworm Team|APT32|Kimsuky|APT1|APT28
|
||||
T1583.001,Domains,Resource Development,IndigoZebra|TeamTNT|Ferocious Kitten|FIN7|Transparent Tribe|Leviathan|Magic Hound|APT29|Mustang Panda|ZIRCONIUM|Lazarus Group|Silent Librarian|menuPass|Sandworm Team|APT32|Kimsuky|APT1|APT28
|
||||
T1583,Acquire Infrastructure,Resource Development,no
|
||||
T1564.007,VBA Stomping,Defense Evasion,no
|
||||
T1558.004,AS-REP Roasting,Credential Access,no
|
||||
@@ -162,10 +162,10 @@ T1546.015,Component Object Model Hijacking,Privilege Escalation|Persistence,APT2
|
||||
T1071.004,DNS,Command And Control,Chimera|APT39|Tropic Trooper|OilRig|Ke3chang|Cobalt Group|APT18|APT41|FIN7
|
||||
T1071.003,Mail Protocols,Command And Control,Turla|Kimsuky|APT32|SilverTerrier|APT28
|
||||
T1071.002,File Transfer Protocols,Command And Control,Kimsuky|APT41|SilverTerrier|Honeybee
|
||||
T1071.001,Web Protocols,Command And Control,TeamTNT|FIN8|APT29|Mustang Panda|Windshift|TA551|Higaisa|HAFNIUM|Sidewinder|Chimera|UNC2452|Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Rancor|Ke3chang|Orangeworm|APT37|APT19|Cobalt Group|Threat Group-3390|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|Magic Hound|APT32|OilRig|Gamaredon Group|Stealth Falcon
|
||||
T1071.001,Web Protocols,Command And Control,TeamTNT|FIN8|APT29|Mustang Panda|Windshift|TA551|Higaisa|HAFNIUM|Sidewinder|Chimera|Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Rancor|Ke3chang|Orangeworm|APT37|APT19|Cobalt Group|Threat Group-3390|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|Magic Hound|APT32|OilRig|Gamaredon Group|Stealth Falcon
|
||||
T1572,Protocol Tunneling,Command And Control,Leviathan|CostaRicto|Chimera|Fox Kitten|OilRig|Cobalt Group|FIN6
|
||||
T1048.003,Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol,Exfiltration,Wizard Spider|FIN6|APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group
|
||||
T1048.002,Exfiltration Over Asymmetric Encrypted Non-C2 Protocol,Exfiltration,APT28|APT29|UNC2452
|
||||
T1048.002,Exfiltration Over Asymmetric Encrypted Non-C2 Protocol,Exfiltration,APT28|APT29
|
||||
T1048.001,Exfiltration Over Symmetric Encrypted Non-C2 Protocol,Exfiltration,no
|
||||
T1001.003,Protocol Impersonation,Command And Control,Higaisa|Lazarus Group
|
||||
T1001.002,Steganography,Command And Control,APT29|Axiom
|
||||
@@ -175,17 +175,17 @@ T1132.001,Standard Encoding,Command And Control,HAFNIUM|TA551|Sandworm Team|Trop
|
||||
T1090.004,Domain Fronting,Command And Control,APT29
|
||||
T1090.003,Multi-hop Proxy,Command And Control,Leviathan|CostaRicto|APT28|Operation Wocao|Inception|FIN4|APT29
|
||||
T1090.002,External Proxy,Command And Control,Tonto Team|APT39|Silence|GALLIUM|MuddyWater|APT3|FIN5|Lazarus Group|menuPass|APT28
|
||||
T1090.001,Internal Proxy,Command And Control,APT29|Higaisa|UNC2452|Operation Wocao|APT39|Strider
|
||||
T1090.001,Internal Proxy,Command And Control,APT29|Higaisa|Operation Wocao|APT39|Strider
|
||||
T1102.003,One-Way Communication,Command And Control,Leviathan
|
||||
T1102.002,Bidirectional Communication,Command And Control,ZIRCONIUM|MuddyWater|APT28|APT29|Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak
|
||||
T1102.001,Dead Drop Resolver,Command And Control,Rocke|APT41|BRONZE BUTLER|RTM|Patchwork
|
||||
T1571,Non-Standard Port,Command And Control,Sandworm Team|Rocke|DarkVishnya|Silence|APT-C-36|Magic Hound|APT33|APT32|TEMP.Veles|Lazarus Group|FIN7
|
||||
T1074.002,Remote Data Staging,Collection,Leviathan|APT28|APT29|Chimera|UNC2452|Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8
|
||||
T1074.002,Remote Data Staging,Collection,Leviathan|APT28|APT29|Chimera|Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8
|
||||
T1074.001,Local Data Staging,Collection,Indrik Spider|BackdoorDiplomacy|Mustang Panda|Sidewinder|Chimera|Kimsuky|APT39|Operation Wocao|GALLIUM|TEMP.Veles|Patchwork|Honeybee|Dragonfly 2.0|Leviathan|APT3|FIN5|menuPass|Lazarus Group|Threat Group-3390|APT28
|
||||
T1078.004,Cloud Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,APT28|APT33
|
||||
T1564.004,NTFS File Attributes,Defense Evasion,APT32
|
||||
T1564.003,Hidden Window,Defense Evasion,Nomadic Octopus|Higaisa|Gorgon Group|Deep Panda|DarkHydrus|CopyKittens|APT19|APT32|APT28|APT3|Magic Hound
|
||||
T1078.003,Local Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Kimsuky|HAFNIUM|Turla|Operation Wocao|PROMETHIUM|Tropic Trooper|FIN10|Stolen Pencil|APT32
|
||||
T1078.003,Local Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Kimsuky|HAFNIUM|Turla|Operation Wocao|PROMETHIUM|Tropic Trooper|FIN10|APT32
|
||||
T1078.002,Domain Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Naikon|Indrik Spider|Chimera|Operation Wocao|Sandworm Team|Wizard Spider|APT29|TA505|APT3|Threat Group-1314
|
||||
T1078.001,Default Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,no
|
||||
T1564.002,Hidden Users,Defense Evasion,Dragonfly 2.0
|
||||
@@ -205,7 +205,7 @@ T1568.003,DNS Calculation,Command And Control,APT12
|
||||
T1204.002,Malicious File,Execution,Nomadic Octopus|Indrik Spider|APT38|Andariel|Ferocious Kitten|IndigoZebra|Transparent Tribe|Tonto Team|Magic Hound|Ajax Security Team|Mustang Panda|TA551|Higaisa|Sidewinder|Kimsuky|FIN6|PROMETHIUM|APT30|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Dragonfly 2.0|FIN7|BRONZE BUTLER|Gorgon Group|OilRig|Dark Caracal|Cobalt Group|DarkHydrus|Rancor|Patchwork|APT32|APT19|MuddyWater|Lazarus Group|menuPass|APT37|Leviathan|TA459|APT29|APT28|FIN8|PLATINUM|Elderwood
|
||||
T1204.001,Malicious Link,Execution,FIN7|Transparent Tribe|APT3|Magic Hound|APT28|APT29|Mustang Panda|Sidewinder|ZIRCONIUM|MuddyWater|Evilnum|Sandworm Team|Wizard Spider|Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|Turla|APT33
|
||||
T1195.003,Compromise Hardware Supply Chain,Initial Access,no
|
||||
T1195.002,Compromise Software Supply Chain,Initial Access,APT29|UNC2452|Cobalt Group|GOLD SOUTHFIELD|Dragonfly|Sandworm Team|APT41
|
||||
T1195.002,Compromise Software Supply Chain,Initial Access,APT29|Cobalt Group|GOLD SOUTHFIELD|Dragonfly|Sandworm Team|APT41
|
||||
T1195.001,Compromise Software Dependencies and Development Tools,Initial Access,no
|
||||
T1568.001,Fast Flux DNS,Command And Control,menuPass|TA505
|
||||
T1052.001,Exfiltration over USB,Exfiltration,Mustang Panda|Tropic Trooper
|
||||
@@ -213,16 +213,16 @@ T1569.002,Service Execution,Execution,APT38|Chimera|Operation Wocao|Wizard Spide
|
||||
T1569.001,Launchctl,Execution,no
|
||||
T1569,System Services,Execution,no
|
||||
T1568.002,Domain Generation Algorithms,Command And Control,TA551|APT41
|
||||
T1568,Dynamic Resolution,Command And Control,Transparent Tribe|APT29|UNC2452
|
||||
T1568,Dynamic Resolution,Command And Control,Transparent Tribe|APT29
|
||||
T1011.001,Exfiltration Over Bluetooth,Exfiltration,no
|
||||
T1567.002,Exfiltration to Cloud Storage,Exfiltration,FIN7|ZIRCONIUM|HAFNIUM|Chimera|Leviathan|Turla
|
||||
T1567.001,Exfiltration to Code Repository,Exfiltration,no
|
||||
T1059.006,Python,Execution,Tonto Team|APT37|ZIRCONIUM|MuddyWater|Turla|Operation Wocao|Kimsuky|APT29|Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete
|
||||
T1059.005,Visual Basic,Execution,OilRig|APT38|Transparent Tribe|APT29|Mustang Panda|Windshift|Higaisa|Sidewinder|APT39|Machete|Operation Wocao|Kimsuky|APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Cobalt Group|Gorgon Group|Leviathan|TA459|Magic Hound
|
||||
T1059.004,Unix Shell,Execution,TeamTNT|Rocke|APT41
|
||||
T1059.003,Windows Command Shell,Execution,Sandworm Team|Nomadic Octopus|TeamTNT|APT29|Mustang Panda|ZIRCONIUM|TA551|Higaisa|Indrik Spider|Chimera|UNC2452|Fox Kitten|Machete|Operation Wocao|Wizard Spider|FIN6|TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|GALLIUM|Turla|Silence|APT32|Darkhotel|MuddyWater|APT18|APT38|Gorgon Group|Dark Caracal|Ke3chang|Dragonfly 2.0|Rancor|FIN8|APT28|APT37|Magic Hound|BRONZE BUTLER|Sowbug|menuPass|FIN10|Threat Group-3390|Gamaredon Group|Patchwork|Suckfly|Threat Group-1314|APT3|admin@338|APT1
|
||||
T1059.003,Windows Command Shell,Execution,Sandworm Team|Nomadic Octopus|TeamTNT|APT29|Mustang Panda|ZIRCONIUM|TA551|Higaisa|Indrik Spider|Chimera|Fox Kitten|Machete|Operation Wocao|Wizard Spider|FIN6|TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|GALLIUM|Turla|Silence|APT32|Darkhotel|MuddyWater|APT18|APT38|Gorgon Group|Dark Caracal|Ke3chang|Dragonfly 2.0|Rancor|FIN8|APT28|APT37|Magic Hound|BRONZE BUTLER|Sowbug|menuPass|FIN10|Threat Group-3390|Gamaredon Group|Patchwork|Suckfly|Threat Group-1314|APT3|admin@338|APT1
|
||||
T1059.002,AppleScript,Execution,no
|
||||
T1059.001,PowerShell,Execution,Nomadic Octopus|TeamTNT|APT38|Tonto Team|Mustang Panda|Indrik Spider|HAFNIUM|Sidewinder|UNC2452|Fox Kitten|GOLD SOUTHFIELD|Sandworm Team|Operation Wocao|Chimera|Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|GALLIUM|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|Thrip|Cobalt Group|APT28|DarkHydrus|Dragonfly 2.0|APT19|Gorgon Group|TA459|Leviathan|MuddyWater|FIN8|CopyKittens|OilRig|Magic Hound|BRONZE BUTLER|FIN7|APT32|menuPass|FIN10|Threat Group-3390|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda
|
||||
T1059.001,PowerShell,Execution,Nomadic Octopus|TeamTNT|APT38|Tonto Team|Mustang Panda|Indrik Spider|HAFNIUM|Sidewinder|Fox Kitten|GOLD SOUTHFIELD|Sandworm Team|Operation Wocao|Chimera|Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|GALLIUM|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|Thrip|Cobalt Group|APT28|DarkHydrus|Dragonfly 2.0|APT19|Gorgon Group|TA459|Leviathan|MuddyWater|FIN8|CopyKittens|OilRig|Magic Hound|BRONZE BUTLER|FIN7|APT32|menuPass|FIN10|Threat Group-3390|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda
|
||||
T1567,Exfiltration Over Web Service,Exfiltration,APT28
|
||||
T1497.003,Time Based Evasion,Defense Evasion|Discovery,no
|
||||
T1497.002,User Activity Based Checks,Defense Evasion|Discovery,Darkhotel|FIN7
|
||||
@@ -230,7 +230,7 @@ T1497.001,System Checks,Defense Evasion|Discovery,OilRig|Darkhotel|Evilnum|Frank
|
||||
T1498.002,Reflection Amplification,Impact,no
|
||||
T1498.001,Direct Network Flood,Impact,no
|
||||
T1566.003,Spearphishing via Service,Initial Access,APT29|Ajax Security Team|Magic Hound|Windshift|FIN6|OilRig|Dark Caracal
|
||||
T1566.002,Spearphishing Link,Initial Access,Transparent Tribe|FIN7|APT3|Mustang Panda|ZIRCONIUM|MuddyWater|Sidewinder|Evilnum|Sandworm Team|Wizard Spider|APT1|Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|APT28|Cobalt Group|Turla|Dragonfly 2.0|OilRig|Elderwood|APT33|APT29|Leviathan|FIN8|Patchwork|Magic Hound
|
||||
T1566.002,Spearphishing Link,Initial Access,Transparent Tribe|FIN7|APT3|Mustang Panda|ZIRCONIUM|MuddyWater|Sidewinder|Evilnum|Sandworm Team|Wizard Spider|APT1|Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|APT39|FIN4|APT32|Night Dragon|APT28|Cobalt Group|Turla|Dragonfly 2.0|OilRig|Elderwood|APT33|APT29|Leviathan|FIN8|Patchwork|Magic Hound
|
||||
T1566.001,Spearphishing Attachment,Initial Access,APT38|Andariel|Ferocious Kitten|IndigoZebra|Transparent Tribe|Nomadic Octopus|Tonto Team|Ajax Security Team|Mustang Panda|TA551|Higaisa|Sidewinder|APT1|FIN6|APT30|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|DarkHydrus|Lazarus Group|Gorgon Group|OilRig|BRONZE BUTLER|APT19|APT32|Cobalt Group|Rancor|FIN7|Dragonfly 2.0|MuddyWater|APT28|TA459|APT29|APT37|Leviathan|FIN8|Patchwork|menuPass|Elderwood|PLATINUM
|
||||
T1566,Phishing,Initial Access,GOLD SOUTHFIELD|Dragonfly
|
||||
T1565.003,Runtime Data Manipulation,Impact,APT38
|
||||
@@ -250,10 +250,10 @@ T1087.003,Email Account,Discovery,Sandworm Team|TA505
|
||||
T1087.002,Domain Account,Discovery,MuddyWater|Fox Kitten|Operation Wocao|Wizard Spider|Chimera|Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang
|
||||
T1087.001,Local Account,Discovery,Chimera|Fox Kitten|Turla|Poseidon Group|OilRig|Ke3chang|APT32|APT1|Threat Group-3390|APT3|admin@338
|
||||
T1553.004,Install Root Certificate,Defense Evasion,no
|
||||
T1562.004,Disable or Modify System Firewall,Defense Evasion,TeamTNT|APT38|APT29|UNC2452|Operation Wocao|Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak
|
||||
T1562.004,Disable or Modify System Firewall,Defense Evasion,TeamTNT|APT38|APT29|Operation Wocao|Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak
|
||||
T1562.003,Impair Command History Logging,Defense Evasion,APT38
|
||||
T1562.002,Disable Windows Event Logging,Defense Evasion,Sandworm Team|APT29|UNC2452|Threat Group-3390
|
||||
T1562.001,Disable or Modify Tools,Defense Evasion,TeamTNT|Indrik Spider|APT29|MuddyWater|UNC2452|Wizard Spider|FIN6|Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda
|
||||
T1562.002,Disable Windows Event Logging,Defense Evasion,Sandworm Team|APT29|Threat Group-3390
|
||||
T1562.001,Disable or Modify Tools,Defense Evasion,TeamTNT|Indrik Spider|APT29|MuddyWater|Wizard Spider|FIN6|Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda
|
||||
T1562,Impair Defenses,Defense Evasion,no
|
||||
T1003.004,LSA Secrets,Credential Access,OilRig|MuddyWater|menuPass|Leafminer|Ke3chang|Dragonfly 2.0|APT33|Threat Group-3390
|
||||
T1003.005,Cached Domain Credentials,Credential Access,OilRig|MuddyWater|Leafminer|APT33
|
||||
@@ -262,7 +262,7 @@ T1561.001,Disk Content Wipe,Impact,Lazarus Group
|
||||
T1561,Disk Wipe,Impact,no
|
||||
T1560.003,Archive via Custom Method,Collection,Mustang Panda|Lazarus Group|Kimsuky|CopyKittens|FIN6
|
||||
T1560.002,Archive via Library,Collection,Lazarus Group|Threat Group-3390
|
||||
T1560.001,Archive via Utility,Collection,APT28|APT29|Mustang Panda|HAFNIUM|UNC2452|Fox Kitten|Operation Wocao|Chimera|APT41|GALLIUM|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|Sowbug|APT3|menuPass|APT1|Ke3chang
|
||||
T1560.001,Archive via Utility,Collection,APT28|APT29|Mustang Panda|HAFNIUM|Fox Kitten|Operation Wocao|Chimera|APT41|GALLIUM|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|Sowbug|APT3|menuPass|APT1|Ke3chang
|
||||
T1560,Archive Collected Data,Collection,Leviathan|menuPass|APT32|Honeybee|Patchwork|APT28|Dragonfly 2.0|FIN6|Lazarus Group|Ke3chang
|
||||
T1499.004,Application or System Exploitation,Impact,no
|
||||
T1499.003,Application Exhaustion Flood,Impact,no
|
||||
@@ -271,7 +271,7 @@ T1499.001,OS Exhaustion Flood,Impact,no
|
||||
T1491.002,External Defacement,Impact,Sandworm Team
|
||||
T1491.001,Internal Defacement,Impact,Lazarus Group
|
||||
T1114.003,Email Forwarding Rule,Collection,Silent Librarian|Kimsuky
|
||||
T1114.002,Remote Email Collection,Collection,APT29|HAFNIUM|Chimera|UNC2452|APT1|FIN4|Ke3chang|Leafminer|Dragonfly 2.0|APT28
|
||||
T1114.002,Remote Email Collection,Collection,APT29|HAFNIUM|Chimera|APT1|FIN4|Ke3chang|Leafminer|Dragonfly 2.0|APT28
|
||||
T1114.001,Local Email Collection,Collection,Chimera|Magic Hound|APT1
|
||||
T1134.005,SID-History Injection,Defense Evasion|Privilege Escalation,no
|
||||
T1134.004,Parent PID Spoofing,Defense Evasion|Privilege Escalation,no
|
||||
@@ -280,7 +280,7 @@ T1134.002,Create Process with Token,Defense Evasion|Privilege Escalation,Turla|L
|
||||
T1134.001,Token Impersonation/Theft,Defense Evasion|Privilege Escalation,FIN8|APT28
|
||||
T1213.002,Sharepoint,Collection,Chimera|Ke3chang|APT28
|
||||
T1213.001,Confluence,Collection,no
|
||||
T1555.003,Credentials from Web Browsers,Credential Access,Ajax Security Team|ZIRCONIUM|FIN6|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats
|
||||
T1555.003,Credentials from Web Browsers,Credential Access,Ajax Security Team|ZIRCONIUM|FIN6|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|MuddyWater|APT37|Patchwork|Molerats
|
||||
T1555.002,Securityd Memory,Credential Access,no
|
||||
T1555.001,Keychain,Credential Access,no
|
||||
T1559.002,Dynamic Data Exchange,Execution,Leviathan|Sidewinder|Sharpshooter|TA505|MuddyWater|Gallmaker|Patchwork|Cobalt Group|APT37|FIN7|APT28
|
||||
@@ -297,36 +297,36 @@ T1556,Modify Authentication Process,Credential Access|Defense Evasion|Persistenc
|
||||
T1056.004,Credential API Hooking,Collection|Credential Access,PLATINUM
|
||||
T1056.003,Web Portal Capture,Collection|Credential Access,no
|
||||
T1056.002,GUI Input Capture,Collection|Credential Access,FIN4
|
||||
T1056.001,Keylogging,Collection|Credential Access,Tonto Team|Ajax Security Team|Operation Wocao|APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|OilRig|Ke3chang|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28
|
||||
T1555,Credentials from Password Stores,Credential Access,APT29|Evilnum|UNC2452|FIN6|APT39|OilRig|MuddyWater|Leafminer|APT33|Stealth Falcon
|
||||
T1056.001,Keylogging,Collection|Credential Access,Tonto Team|Ajax Security Team|Operation Wocao|APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|FIN4|APT38|OilRig|Ke3chang|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28
|
||||
T1555,Credentials from Password Stores,Credential Access,APT29|Evilnum|FIN6|APT39|OilRig|MuddyWater|Leafminer|APT33|Stealth Falcon
|
||||
T1552.005,Cloud Instance Metadata API,Credential Access,TeamTNT
|
||||
T1003.008,/etc/passwd and /etc/shadow,Credential Access,no
|
||||
T1003.007,Proc Filesystem,Credential Access,no
|
||||
T1003.006,DCSync,Credential Access,APT29|UNC2452|Operation Wocao
|
||||
T1558.003,Kerberoasting,Credential Access,FIN7|APT29|UNC2452|Operation Wocao|Wizard Spider
|
||||
T1003.006,DCSync,Credential Access,APT29|Operation Wocao
|
||||
T1558.003,Kerberoasting,Credential Access,FIN7|APT29|Operation Wocao|Wizard Spider
|
||||
T1552.006,Group Policy Preferences,Credential Access,APT33
|
||||
T1003.003,NTDS,Credential Access,APT28|Mustang Panda|HAFNIUM|Fox Kitten|menuPass|Wizard Spider|Chimera|FIN6|Dragonfly 2.0
|
||||
T1003.002,Security Account Manager,Credential Access,Wizard Spider|Threat Group-3390|Ke3chang|GALLIUM|Night Dragon|Dragonfly 2.0|menuPass
|
||||
T1003.001,LSASS Memory,Credential Access,Indrik Spider|HAFNIUM|Fox Kitten|Operation Wocao|Kimsuky|Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|GALLIUM|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Leafminer|Magic Hound|FIN8|PLATINUM|MuddyWater|OilRig|BRONZE BUTLER|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver
|
||||
T1003.001,LSASS Memory,Credential Access,Indrik Spider|HAFNIUM|Fox Kitten|Operation Wocao|Kimsuky|Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|GALLIUM|TEMP.Veles|APT33|APT39|APT32|Leafminer|Magic Hound|FIN8|PLATINUM|MuddyWater|OilRig|BRONZE BUTLER|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver
|
||||
T1110.004,Credential Stuffing,Credential Access,Chimera
|
||||
T1110.003,Password Spraying,Credential Access,Sandworm Team|APT29|Silent Librarian|Chimera|APT28|APT33|Leafminer|Lazarus Group
|
||||
T1110.002,Password Cracking,Credential Access,FIN6|APT41|Dragonfly 2.0|APT3
|
||||
T1110.001,Password Guessing,Credential Access,APT28
|
||||
T1021.006,Windows Remote Management,Lateral Movement,APT29|UNC2452|Chimera|Wizard Spider|Threat Group-3390
|
||||
T1021.006,Windows Remote Management,Lateral Movement,APT29|Chimera|Wizard Spider|Threat Group-3390
|
||||
T1021.005,VNC,Lateral Movement,FIN7|Fox Kitten|GCMAN
|
||||
T1021.004,SSH,Lateral Movement,TeamTNT|FIN7|Fox Kitten|Rocke|TEMP.Veles|Leviathan|APT39|OilRig|menuPass|GCMAN
|
||||
T1021.003,Distributed Component Object Model,Lateral Movement,no
|
||||
T1021.002,SMB/Windows Admin Shares,Lateral Movement,Sandworm Team|APT28|Fox Kitten|APT41|Operation Wocao|Wizard Spider|Chimera|Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang
|
||||
T1021.001,Remote Desktop Protocol,Lateral Movement,Kimsuky|FIN7|Fox Kitten|Chimera|Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|FIN10|menuPass|Patchwork|FIN6|Lazarus Group|APT1|Axiom
|
||||
T1021.001,Remote Desktop Protocol,Lateral Movement,Kimsuky|FIN7|Fox Kitten|Chimera|Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|FIN10|menuPass|Patchwork|FIN6|Lazarus Group|APT1|Axiom
|
||||
T1554,Compromise Client Software Binary,Persistence,no
|
||||
T1036.006,Space after Filename,Defense Evasion,no
|
||||
T1036.005,Match Legitimate Name or Location,Defense Evasion,APT28|Ferocious Kitten|FIN7|BackdoorDiplomacy|Transparent Tribe|Naikon|APT29|Mustang Panda|Sidewinder|Darkhotel|Lazarus Group|Indrik Spider|UNC2452|Fox Kitten|Machete|Chimera|PROMETHIUM|Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|Sowbug|BRONZE BUTLER|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1
|
||||
T1036.004,Masquerade Task or Service,Defense Evasion,BackdoorDiplomacy|APT41|Naikon|ZIRCONIUM|APT29|Higaisa|UNC2452|Fox Kitten|Kimsuky|PROMETHIUM|Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7
|
||||
T1036.005,Match Legitimate Name or Location,Defense Evasion,APT28|Ferocious Kitten|FIN7|BackdoorDiplomacy|Transparent Tribe|Naikon|APT29|Mustang Panda|Sidewinder|Darkhotel|Lazarus Group|Indrik Spider|Fox Kitten|Machete|Chimera|PROMETHIUM|Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|Sowbug|BRONZE BUTLER|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1
|
||||
T1036.004,Masquerade Task or Service,Defense Evasion,BackdoorDiplomacy|APT41|Naikon|ZIRCONIUM|APT29|Higaisa|Fox Kitten|Kimsuky|PROMETHIUM|Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7
|
||||
T1036.003,Rename System Utilities,Defense Evasion,menuPass|APT32|GALLIUM
|
||||
T1036.002,Right-to-Left Override,Defense Evasion,Ferocious Kitten|BRONZE BUTLER|BlackTech|Ke3chang|Scarlet Mimic
|
||||
T1036.001,Invalid Code Signature,Defense Evasion,Windshift|APT37
|
||||
T1553.003,SIP and Trust Provider Hijacking,Defense Evasion,no
|
||||
T1553.002,Code Signing,Defense Evasion,menuPass|APT29|GALLIUM|UNC2452|Wizard Spider|Kimsuky|PROMETHIUM|Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel
|
||||
T1553.002,Code Signing,Defense Evasion,menuPass|APT29|GALLIUM|Wizard Spider|Kimsuky|PROMETHIUM|Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel
|
||||
T1553.001,Gatekeeper Bypass,Defense Evasion,no
|
||||
T1553,Subvert Trust Controls,Defense Evasion,no
|
||||
T1027.003,Steganography,Defense Evasion,Andariel|Leviathan|TA551|BRONZE BUTLER|Tropic Trooper|MuddyWater|APT37
|
||||
@@ -334,21 +334,21 @@ T1027.002,Software Packing,Defense Evasion,Sandworm Team|Kimsuky|TeamTNT|ZIRCONI
|
||||
T1027.001,Binary Padding,Defense Evasion,APT29|Mustang Panda|Higaisa|Gamaredon Group|Patchwork|APT32|Leviathan|BRONZE BUTLER|Moafee
|
||||
T1222.002,Linux and Mac File and Directory Permissions Modification,Defense Evasion,TeamTNT|Rocke|APT32
|
||||
T1222.001,Windows File and Directory Permissions Modification,Defense Evasion,Wizard Spider
|
||||
T1552.004,Private Keys,Credential Access,TeamTNT|APT29|UNC2452|Operation Wocao|Rocke
|
||||
T1552.004,Private Keys,Credential Access,TeamTNT|APT29|Operation Wocao|Rocke
|
||||
T1552.003,Bash History,Credential Access,no
|
||||
T1552.002,Credentials in Registry,Credential Access,APT32
|
||||
T1552.001,Credentials In Files,Credential Access,TeamTNT|Kimsuky|Fox Kitten|Leafminer|APT33|OilRig|TA505|Stolen Pencil|MuddyWater|APT3
|
||||
T1552.001,Credentials In Files,Credential Access,TeamTNT|Kimsuky|Fox Kitten|Leafminer|APT33|OilRig|TA505|MuddyWater|APT3
|
||||
T1552,Unsecured Credentials,Credential Access,no
|
||||
T1216.001,PubPrn,Defense Evasion,APT32
|
||||
T1070.006,Timestomp,Defense Evasion,APT38|APT29|UNC2452|Chimera|Kimsuky|Rocke|TEMP.Veles|APT32|Lazarus Group|APT28
|
||||
T1070.006,Timestomp,Defense Evasion,APT38|APT29|Chimera|Kimsuky|Rocke|TEMP.Veles|APT32|Lazarus Group|APT28
|
||||
T1070.005,Network Share Connection Removal,Defense Evasion,Threat Group-3390
|
||||
T1070.004,File Deletion,Defense Evasion,TeamTNT|APT39|Mustang Panda|Chimera|Evilnum|UNC2452|Operation Wocao|FIN6|Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Cobalt Group|Dragonfly 2.0|Honeybee|Patchwork|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|APT3|Magic Hound|Threat Group-3390|APT28|FIN10|Group5|Lazarus Group|APT18|APT29
|
||||
T1070.004,File Deletion,Defense Evasion,TeamTNT|APT39|Mustang Panda|Chimera|Evilnum|Operation Wocao|FIN6|Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Cobalt Group|Dragonfly 2.0|Honeybee|Patchwork|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|APT3|Magic Hound|Threat Group-3390|APT28|FIN10|Group5|Lazarus Group|APT18|APT29
|
||||
T1070.003,Clear Command History,Defense Evasion,TeamTNT|menuPass|APT41
|
||||
T1550.004,Web Session Cookie,Defense Evasion|Lateral Movement,APT29|UNC2452
|
||||
T1550.004,Web Session Cookie,Defense Evasion|Lateral Movement,APT29
|
||||
T1550.001,Application Access Token,Defense Evasion|Lateral Movement,APT28
|
||||
T1550.003,Pass the Ticket,Defense Evasion|Lateral Movement,APT32|BRONZE BUTLER|APT29
|
||||
T1550.002,Pass the Hash,Defense Evasion|Lateral Movement,Chimera|Kimsuky|GALLIUM|APT32|Night Dragon|APT28|APT1
|
||||
T1550,Use Alternate Authentication Material,Defense Evasion|Lateral Movement,APT29|UNC2452
|
||||
T1550,Use Alternate Authentication Material,Defense Evasion|Lateral Movement,APT29
|
||||
T1548.004,Elevated Execution with Prompt,Privilege Escalation|Defense Evasion,no
|
||||
T1548.003,Sudo and Sudo Caching,Privilege Escalation|Defense Evasion,no
|
||||
T1548.002,Bypass User Account Control,Privilege Escalation|Defense Evasion,Evilnum|APT37|MuddyWater|Threat Group-3390|Honeybee|Cobalt Group|BRONZE BUTLER|Patchwork|APT29
|
||||
@@ -382,7 +382,7 @@ T1546.007,Netsh Helper DLL,Privilege Escalation|Persistence,no
|
||||
T1546.006,LC_LOAD_DYLIB Addition,Privilege Escalation|Persistence,no
|
||||
T1546.005,Trap,Privilege Escalation|Persistence,no
|
||||
T1546.004,Unix Shell Configuration Modification,Privilege Escalation|Persistence,no
|
||||
T1546.003,Windows Management Instrumentation Event Subscription,Privilege Escalation|Persistence,FIN8|Mustang Panda|UNC2452|APT33|Blue Mockingbird|Turla|Leviathan|APT29
|
||||
T1546.003,Windows Management Instrumentation Event Subscription,Privilege Escalation|Persistence,FIN8|Mustang Panda|APT33|Blue Mockingbird|Turla|Leviathan|APT29
|
||||
T1546.002,Screensaver,Privilege Escalation|Persistence,no
|
||||
T1546.001,Change Default File Association,Privilege Escalation|Persistence,Kimsuky
|
||||
T1547.001,Registry Run Keys / Startup Folder,Persistence|Privilege Escalation,TeamTNT|Naikon|Windshift|Mustang Panda|ZIRCONIUM|Higaisa|Sidewinder|APT28|Wizard Spider|PROMETHIUM|Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Kimsuky|APT33|APT39|APT32|APT18|Dark Caracal|Threat Group-3390|Honeybee|Turla|Cobalt Group|Ke3chang|Dragonfly 2.0|APT19|Gorgon Group|MuddyWater|APT37|Leviathan|BRONZE BUTLER|APT3|Magic Hound|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel
|
||||
@@ -393,12 +393,12 @@ T1218.005,Mshta,Defense Evasion,Mustang Panda|TA551|Sidewinder|Inception|Kimsuky
|
||||
T1218.004,InstallUtil,Defense Evasion,Mustang Panda|menuPass
|
||||
T1218.001,Compiled HTML File,Defense Evasion,APT41|Silence|Dark Caracal|OilRig|Lazarus Group
|
||||
T1218.003,CMSTP,Defense Evasion,Cobalt Group|MuddyWater
|
||||
T1218.011,Rundll32,Defense Evasion,APT38|HAFNIUM|TA551|UNC2452|APT41|Gamaredon Group|APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28
|
||||
T1218.011,Rundll32,Defense Evasion,APT38|HAFNIUM|TA551|APT41|Gamaredon Group|APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28
|
||||
T1547,Boot or Logon Autostart Execution,Persistence|Privilege Escalation,no
|
||||
T1546,Event Triggered Execution,Privilege Escalation|Persistence,no
|
||||
T1098.003,Add Office 365 Global Administrator Role,Persistence,no
|
||||
T1098.002,Exchange Email Delegate Permissions,Persistence,APT28|APT29|UNC2452|Magic Hound
|
||||
T1098.001,Additional Cloud Credentials,Persistence,APT29|UNC2452
|
||||
T1098.002,Exchange Email Delegate Permissions,Persistence,APT28|APT29|Magic Hound
|
||||
T1098.001,Additional Cloud Credentials,Persistence,APT29
|
||||
T1543.004,Launch Daemon,Persistence|Privilege Escalation,no
|
||||
T1543.003,Windows Service,Persistence|Privilege Escalation,TeamTNT|APT38|PROMETHIUM|Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Cobalt Group|Ke3chang|FIN7|APT19|Threat Group-3390|Honeybee|APT3|Lazarus Group|Carbanak
|
||||
T1543.002,Systemd Service,Persistence|Privilege Escalation,TeamTNT|Rocke
|
||||
@@ -427,9 +427,8 @@ T1505.003,Web Shell,Persistence,BackdoorDiplomacy|APT38|APT29|APT28|Tonto Team|S
|
||||
T1505.002,Transport Agent,Persistence,no
|
||||
T1505.001,SQL Stored Procedures,Persistence,Sandworm Team
|
||||
T1053.003,Cron,Execution|Persistence|Privilege Escalation,APT38|Rocke
|
||||
T1053.004,Launchd,Execution|Persistence|Privilege Escalation,no
|
||||
T1053.001,At (Linux),Execution|Persistence|Privilege Escalation,no
|
||||
T1053.005,Scheduled Task,Execution|Persistence|Privilege Escalation,APT37|APT38|Naikon|CostaRicto|Mustang Panda|Higaisa|UNC2452|Fox Kitten|Molerats|Machete|Operation Wocao|Chimera|Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|GALLIUM|Silence|TEMP.Veles|APT33|APT39|Rancor|OilRig|Patchwork|Dragonfly 2.0|Cobalt Group|FIN8|menuPass|FIN10|FIN7|APT32|Stealth Falcon|FIN6|APT3|APT29
|
||||
T1053.005,Scheduled Task,Execution|Persistence|Privilege Escalation,APT37|APT38|Naikon|CostaRicto|Mustang Panda|Higaisa|Fox Kitten|Molerats|Machete|Operation Wocao|Chimera|Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|GALLIUM|Silence|TEMP.Veles|APT33|APT39|Rancor|OilRig|Patchwork|Dragonfly 2.0|Cobalt Group|FIN8|menuPass|FIN10|FIN7|APT32|Stealth Falcon|FIN6|APT3|APT29
|
||||
T1053.002,At (Windows),Execution|Persistence|Privilege Escalation,BRONZE BUTLER|Threat Group-3390|APT18
|
||||
T1542,Pre-OS Boot,Defense Evasion|Persistence,no
|
||||
T1137.001,Office Template Macros,Persistence,MuddyWater
|
||||
@@ -464,7 +463,7 @@ T1489,Service Stop,Impact,Indrik Spider|Wizard Spider|Lazarus Group
|
||||
T1486,Data Encrypted for Impact,Impact,FIN7|Indrik Spider|APT41|TA505|APT38
|
||||
T1485,Data Destruction,Impact,Sandworm Team|Lazarus Group|APT38
|
||||
T1484,Domain Policy Modification,Defense Evasion|Privilege Escalation,no
|
||||
T1482,Domain Trust Discovery,Discovery,FIN8|APT29|Chimera|UNC2452
|
||||
T1482,Domain Trust Discovery,Discovery,FIN8|APT29|Chimera
|
||||
T1480,Execution Guardrails,Defense Evasion,no
|
||||
T1221,Template Injection,Defense Evasion,Gamaredon Group|Frankenstein|Inception|APT28|Tropic Trooper|DarkHydrus|Dragonfly 2.0
|
||||
T1222,File and Directory Permissions Modification,Defense Evasion,no
|
||||
@@ -481,7 +480,7 @@ T1199,Trusted Relationship,Initial Access,APT29|Sandworm Team|GOLD SOUTHFIELD|AP
|
||||
T1218,Signed Binary Proxy Execution,Defense Evasion,no
|
||||
T1204,User Execution,Execution,no
|
||||
T1213,Data from Information Repositories,Collection,APT28|Fox Kitten|FIN6|Turla
|
||||
T1190,Exploit Public-Facing Application,Initial Access,BackdoorDiplomacy|menuPass|Volatile Cedar|UNC2452|Fox Kitten|Operation Wocao|APT28|APT29|GOLD SOUTHFIELD|Blue Mockingbird|Rocke|APT39|BlackTech|APT41|GALLIUM|Night Dragon|Axiom
|
||||
T1190,Exploit Public-Facing Application,Initial Access,BackdoorDiplomacy|menuPass|Volatile Cedar|Fox Kitten|Operation Wocao|APT28|APT29|GOLD SOUTHFIELD|Blue Mockingbird|Rocke|APT39|BlackTech|APT41|GALLIUM|Night Dragon|Axiom
|
||||
T1210,Exploitation of Remote Services,Lateral Movement,Tonto Team|FIN7|Fox Kitten|menuPass|Wizard Spider|Threat Group-3390|APT28
|
||||
T1200,Hardware Additions,Initial Access,DarkVishnya
|
||||
T1202,Indirect Command Execution,Defense Evasion,no
|
||||
@@ -489,18 +488,15 @@ T1219,Remote Access Software,Command And Control,TeamTNT|Mustang Panda|MuddyWate
|
||||
T1207,Rogue Domain Controller,Defense Evasion,no
|
||||
T1216,Signed Script Proxy Execution,Defense Evasion,no
|
||||
T1205,Traffic Signaling,Defense Evasion|Persistence|Command And Control,no
|
||||
T1176,Browser Extensions,Persistence,Kimsuky|Stolen Pencil
|
||||
T1176,Browser Extensions,Persistence,Kimsuky
|
||||
T1187,Forced Authentication,Credential Access,DarkHydrus|Dragonfly 2.0
|
||||
T1175,Component Object Model and Distributed COM,Lateral Movement|Execution,no
|
||||
T1185,Browser Session Hijacking,Collection,no
|
||||
T1140,Deobfuscate/Decode Files or Information,Defense Evasion,APT39|APT29|ZIRCONIUM|Higaisa|UNC2452|Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|Honeybee|Gorgon Group|Threat Group-3390|menuPass|APT19|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER
|
||||
T1140,Deobfuscate/Decode Files or Information,Defense Evasion,APT39|APT29|ZIRCONIUM|Higaisa|Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|Honeybee|Gorgon Group|Threat Group-3390|menuPass|APT19|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER
|
||||
T1134,Access Token Manipulation,Defense Evasion|Privilege Escalation,FIN6|Blue Mockingbird
|
||||
T1149,LC_MAIN Hijacking,Defense Evasion,no
|
||||
T1136,Create Account,Persistence,Sandworm Team|Indrik Spider
|
||||
T1135,Network Share Discovery,Discovery,Tonto Team|APT38|Chimera|Operation Wocao|Wizard Spider|APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug
|
||||
T1137,Office Application Startup,Persistence,Gamaredon Group|APT32
|
||||
T1153,Source,Execution,no
|
||||
T1133,External Remote Services,Persistence|Initial Access,TeamTNT|Leviathan|APT28|APT29|UNC2452|Operation Wocao|Wizard Spider|Kimsuky|GOLD SOUTHFIELD|Chimera|Sandworm Team|APT41|GALLIUM|TEMP.Veles|Night Dragon|Ke3chang|OilRig|Dragonfly 2.0|FIN5|Threat Group-3390|APT18
|
||||
T1133,External Remote Services,Persistence|Initial Access,TeamTNT|Leviathan|APT28|APT29|Operation Wocao|Wizard Spider|Kimsuky|GOLD SOUTHFIELD|Chimera|Sandworm Team|APT41|GALLIUM|TEMP.Veles|Night Dragon|Ke3chang|OilRig|Dragonfly 2.0|FIN5|Threat Group-3390|APT18
|
||||
T1132,Data Encoding,Command And Control,no
|
||||
T1129,Shared Modules,Execution,no
|
||||
T1127,Trusted Developer Utilities Proxy Execution,Defense Evasion,no
|
||||
@@ -515,9 +511,8 @@ T1113,Screen Capture,Collection,GOLD SOUTHFIELD|Gamaredon Group|APT39|Silence|Mu
|
||||
T1112,Modify Registry,Defense Evasion,Operation Wocao|Kimsuky|Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Patchwork|Gorgon Group|Threat Group-3390|Dragonfly 2.0|APT19|Honeybee|FIN8
|
||||
T1111,Two-Factor Authentication Interception,Credential Access,Chimera|Operation Wocao
|
||||
T1110,Brute Force,Credential Access,APT38|APT28|Fox Kitten|DarkVishnya|APT39|OilRig|FIN5|Turla
|
||||
T1108,Redundant Access,Defense Evasion|Persistence,no
|
||||
T1106,Native API,Execution,APT38|Higaisa|menuPass|Operation Wocao|Chimera|Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|APT37|Gorgon Group
|
||||
T1105,Ingress Tool Transfer,Command And Control,TeamTNT|Nomadic Octopus|IndigoZebra|Andariel|BackdoorDiplomacy|Tonto Team|HAFNIUM|APT29|Ajax Security Team|Mustang Panda|Windshift|Darkhotel|ZIRCONIUM|TA551|Volatile Cedar|Indrik Spider|Evilnum|Sidewinder|UNC2452|Fox Kitten|Kimsuky|Operation Wocao|Chimera|Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|GALLIUM|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Gorgon Group|OilRig|Turla|Cobalt Group|Dragonfly 2.0|FIN8|PLATINUM|APT37|Elderwood|Leviathan|APT32|Magic Hound|BRONZE BUTLER|APT3|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28
|
||||
T1105,Ingress Tool Transfer,Command And Control,TeamTNT|Nomadic Octopus|IndigoZebra|Andariel|BackdoorDiplomacy|Tonto Team|HAFNIUM|APT29|Ajax Security Team|Mustang Panda|Windshift|Darkhotel|ZIRCONIUM|TA551|Volatile Cedar|Indrik Spider|Evilnum|Sidewinder|Fox Kitten|Kimsuky|Operation Wocao|Chimera|Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|GALLIUM|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Gorgon Group|OilRig|Turla|Cobalt Group|Dragonfly 2.0|FIN8|PLATINUM|APT37|Elderwood|Leviathan|APT32|Magic Hound|BRONZE BUTLER|APT3|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28
|
||||
T1104,Multi-Stage Channels,Command And Control,APT41|MuddyWater|APT3
|
||||
T1102,Web Service,Command And Control,TeamTNT|FIN8|Fox Kitten|Turla|APT32|Gamaredon Group|Rocke|Inception|FIN6
|
||||
T1098,Account Manipulation,Persistence,Sandworm Team|APT3|Dragonfly 2.0|Lazarus Group
|
||||
@@ -525,47 +520,40 @@ T1095,Non-Application Layer Protocol,Command And Control,BackdoorDiplomacy|HAFNI
|
||||
T1092,Communication Through Removable Media,Command And Control,APT28
|
||||
T1091,Replication Through Removable Media,Lateral Movement|Initial Access,Mustang Panda|Tropic Trooper|Darkhotel|APT28
|
||||
T1090,Proxy,Command And Control,Windigo|Fox Kitten|Operation Wocao|Sandworm Team|Blue Mockingbird|APT41|Turla
|
||||
T1087,Account Discovery,Discovery,APT29|UNC2452
|
||||
T1083,File and Directory Discovery,Discovery,APT38|APT29|Mustang Panda|Darkhotel|Windigo|Sidewinder|Chimera|UNC2452|Fox Kitten|menuPass|APT39|Sandworm Team|Operation Wocao|Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|APT3|Sowbug|Magic Hound|BRONZE BUTLER|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang
|
||||
T1082,System Information Discovery,Discovery,TeamTNT|APT38|APT29|Mustang Panda|Windshift|ZIRCONIUM|Higaisa|Windigo|Sidewinder|UNC2452|Chimera|Operation Wocao|Wizard Spider|Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|APT32|APT37|Honeybee|APT19|Magic Hound|Sowbug|OilRig|APT3|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang
|
||||
T1087,Account Discovery,Discovery,APT29
|
||||
T1083,File and Directory Discovery,Discovery,APT38|APT29|Mustang Panda|Darkhotel|Windigo|Sidewinder|Chimera|Fox Kitten|menuPass|APT39|Sandworm Team|Operation Wocao|Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|APT3|Sowbug|Magic Hound|BRONZE BUTLER|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang
|
||||
T1082,System Information Discovery,Discovery,TeamTNT|APT38|APT29|Mustang Panda|Windshift|ZIRCONIUM|Higaisa|Windigo|Sidewinder|Chimera|Operation Wocao|Wizard Spider|Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|APT32|APT37|Honeybee|APT19|Magic Hound|Sowbug|OilRig|APT3|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang
|
||||
T1080,Taint Shared Content,Lateral Movement,Gamaredon Group|BRONZE BUTLER|Darkhotel
|
||||
T1078,Valid Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,FIN7|Leviathan|APT29|Silent Librarian|UNC2452|Fox Kitten|Operation Wocao|Chimera|Sandworm Team|Wizard Spider|Silence|APT41|GALLIUM|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|APT33|FIN5|OilRig|APT28|menuPass|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak
|
||||
T1078,Valid Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,FIN7|Leviathan|APT29|Silent Librarian|Fox Kitten|Operation Wocao|Chimera|Sandworm Team|Wizard Spider|Silence|APT41|GALLIUM|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|APT33|FIN5|OilRig|APT28|menuPass|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak
|
||||
T1074,Data Staged,Collection,Wizard Spider
|
||||
T1072,Software Deployment Tools,Execution|Lateral Movement,Silence|APT32|Threat Group-1314
|
||||
T1071,Application Layer Protocol,Command And Control,TeamTNT|Rocke|Magic Hound|Dragonfly 2.0
|
||||
T1070,Indicator Removal on Host,Defense Evasion,APT29|UNC2452
|
||||
T1069,Permission Groups Discovery,Discovery,APT29|UNC2452|TA505|APT3
|
||||
T1070,Indicator Removal on Host,Defense Evasion,APT29
|
||||
T1069,Permission Groups Discovery,Discovery,APT29|TA505|APT3
|
||||
T1068,Exploitation for Privilege Escalation,Privilege Escalation,Tonto Team|ZIRCONIUM|Turla|Whitefly|APT33|Cobalt Group|PLATINUM|FIN8|APT32|Threat Group-3390|FIN6|APT28
|
||||
T1064,Scripting,Defense Evasion|Execution,no
|
||||
T1062,Hypervisor,Persistence,no
|
||||
T1061,Graphical User Interface,Execution,no
|
||||
T1059,Command and Scripting Interpreter,Execution,APT37|Windigo|Fox Kitten|APT32|Whitefly|APT39|Dragonfly 2.0|FIN7|APT19|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang
|
||||
T1057,Process Discovery,Discovery,TeamTNT|Andariel|APT29|Mustang Panda|Windshift|Higaisa|Sidewinder|Chimera|UNC2452|Operation Wocao|Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang
|
||||
T1057,Process Discovery,Discovery,TeamTNT|Andariel|APT29|Mustang Panda|Windshift|Higaisa|Sidewinder|Chimera|Operation Wocao|Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang
|
||||
T1056,Input Capture,Collection|Credential Access,APT39
|
||||
T1055,Process Injection,Defense Evasion|Privilege Escalation,Operation Wocao|APT32|Sharpshooter|Silence|APT41|Kimsuky|Cobalt Group|Turla|APT37|Honeybee|PLATINUM
|
||||
T1053,Scheduled Task/Job,Execution|Persistence|Privilege Escalation,no
|
||||
T1052,Exfiltration Over Physical Medium,Exfiltration,no
|
||||
T1051,Shared Webroot,Lateral Movement,no
|
||||
T1049,System Network Connections Discovery,Discovery,TeamTNT|Andariel|BackdoorDiplomacy|Mustang Panda|MuddyWater|Chimera|Sandworm Team|Operation Wocao|Tropic Trooper|APT41|APT38|GALLIUM|APT32|APT1|OilRig|APT3|menuPass|Threat Group-3390|Poseidon Group|admin@338|Turla|Ke3chang
|
||||
T1048,Exfiltration Over Alternative Protocol,Exfiltration,no
|
||||
T1047,Windows Management Instrumentation,Execution,Sandworm Team|FIN7|Indrik Spider|Naikon|Mustang Panda|Windshift|UNC2452|Operation Wocao|Chimera|Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|GALLIUM|APT32|MuddyWater|Threat Group-3390|OilRig|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda
|
||||
T1047,Windows Management Instrumentation,Execution,Sandworm Team|FIN7|Indrik Spider|Naikon|Mustang Panda|Windshift|Operation Wocao|Chimera|Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|GALLIUM|APT32|MuddyWater|Threat Group-3390|OilRig|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda
|
||||
T1046,Network Service Scanning,Discovery,TeamTNT|BackdoorDiplomacy|Naikon|CostaRicto|Chimera|Fox Kitten|Operation Wocao|Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|OilRig|Cobalt Group|Leafminer|menuPass|Suckfly|FIN6|Threat Group-3390
|
||||
T1043,Commonly Used Port,Command And Control,OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|FIN7|APT19|Dragonfly 2.0|FIN8|APT37|APT3|Magic Hound|Lazarus Group|Threat Group-3390
|
||||
T1041,Exfiltration Over C2 Channel,Exfiltration,Leviathan|ZIRCONIUM|Higaisa|Chimera|APT39|Operation Wocao|Sandworm Team|MuddyWater|Wizard Spider|Frankenstein|Kimsuky|GALLIUM|APT32|APT3|Gamaredon Group|Stealth Falcon|Lazarus Group|Ke3chang
|
||||
T1040,Network Sniffing,Credential Access|Discovery,Kimsuky|Sandworm Team|DarkVishnya|APT33|Stolen Pencil|APT28
|
||||
T1040,Network Sniffing,Credential Access|Discovery,Kimsuky|Sandworm Team|DarkVishnya|APT33|APT28
|
||||
T1039,Data from Network Shared Drive,Collection,APT28|Chimera|Fox Kitten|Gamaredon Group|BRONZE BUTLER|Sowbug|menuPass
|
||||
T1037,Boot or Logon Initialization Scripts,Persistence|Privilege Escalation,Rocke
|
||||
T1036,Masquerading,Defense Evasion,APT28|Nomadic Octopus|OilRig|APT29|ZIRCONIUM|TA551|UNC2452|Windshift|APT32|BRONZE BUTLER|menuPass|PLATINUM|Dragonfly 2.0
|
||||
T1034,Path Interception,Persistence|Privilege Escalation,no
|
||||
T1036,Masquerading,Defense Evasion,APT28|Nomadic Octopus|OilRig|APT29|ZIRCONIUM|TA551|Windshift|APT32|BRONZE BUTLER|menuPass|PLATINUM|Dragonfly 2.0
|
||||
T1033,System Owner/User Discovery,Discovery,APT38|Windshift|ZIRCONIUM|Sidewinder|Chimera|Sandworm Team|Operation Wocao|Wizard Spider|Frankenstein|APT41|GALLIUM|Tropic Trooper|APT39|MuddyWater|APT37|Dragonfly 2.0|APT19|APT32|Magic Hound|OilRig|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3
|
||||
T1030,Data Transfer Size Limits,Exfiltration,APT28|Threat Group-3390
|
||||
T1029,Scheduled Transfer,Exfiltration,Higaisa
|
||||
T1027,Obfuscated Files or Information,Defense Evasion,TeamTNT|BackdoorDiplomacy|Transparent Tribe|APT39|Mustang Panda|Windshift|TA551|Higaisa|Sidewinder|UNC2452|Fox Kitten|GOLD SOUTHFIELD|Operation Wocao|Kimsuky|FIN6|Chimera|Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|GALLIUM|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Patchwork|menuPass|APT37|Threat Group-3390|Cobalt Group|Dark Caracal|Leafminer|Honeybee|APT19|BlackOasis|Leviathan|FIN8|MuddyWater|FIN7|Elderwood|OilRig|Magic Hound|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28
|
||||
T1026,Multiband Communication,Command And Control,Lazarus Group
|
||||
T1027,Obfuscated Files or Information,Defense Evasion,TeamTNT|BackdoorDiplomacy|Transparent Tribe|APT39|Mustang Panda|Windshift|TA551|Higaisa|Sidewinder|Fox Kitten|GOLD SOUTHFIELD|Operation Wocao|Kimsuky|FIN6|Chimera|Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|GALLIUM|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Patchwork|menuPass|APT37|Threat Group-3390|Cobalt Group|Dark Caracal|Leafminer|Honeybee|APT19|BlackOasis|Leviathan|FIN8|MuddyWater|FIN7|Elderwood|OilRig|Magic Hound|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28
|
||||
T1025,Data from Removable Media,Collection,Turla|Gamaredon Group|APT28
|
||||
T1021,Remote Services,Lateral Movement,no
|
||||
T1020,Automated Exfiltration,Exfiltration,Sidewinder|Gamaredon Group|Tropic Trooper|Frankenstein|Honeybee
|
||||
T1018,Remote System Discovery,Discovery,Indrik Spider|Naikon|APT29|UNC2452|Chimera|Fox Kitten|Operation Wocao|Sandworm Team|Rocke|Wizard Spider|Silence|GALLIUM|APT39|APT32|Deep Panda|Ke3chang|Threat Group-3390|Dragonfly 2.0|Leafminer|FIN8|FIN5|APT3|BRONZE BUTLER|menuPass|FIN6|Turla
|
||||
T1018,Remote System Discovery,Discovery,Indrik Spider|Naikon|APT29|Chimera|Fox Kitten|Operation Wocao|Sandworm Team|Rocke|Wizard Spider|Silence|GALLIUM|APT39|APT32|Deep Panda|Ke3chang|Threat Group-3390|Dragonfly 2.0|Leafminer|FIN8|FIN5|APT3|BRONZE BUTLER|menuPass|FIN6|Turla
|
||||
T1016,System Network Configuration Discovery,Discovery,TeamTNT|ZIRCONIUM|Mustang Panda|Higaisa|Sidewinder|Chimera|Operation Wocao|Wizard Spider|Sandworm Team|Tropic Trooper|Frankenstein|APT41|GALLIUM|APT32|Darkhotel|MuddyWater|APT1|APT19|Dragonfly 2.0|Magic Hound|OilRig|Threat Group-3390|menuPass|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang
|
||||
T1014,Rootkit,Defense Evasion,TeamTNT|Rocke|APT41|APT28|Winnti Group
|
||||
T1012,Query Registry,Discovery,ZIRCONIUM|Chimera|Fox Kitten|APT39|Operation Wocao|APT32|Dragonfly 2.0|Threat Group-3390|OilRig|Stealth Falcon|Lazarus Group|Turla
|
||||
@@ -574,6 +562,6 @@ T1010,Application Window Discovery,Discovery,Lazarus Group
|
||||
T1008,Fallback Channels,Command And Control,FIN7|APT41|OilRig|Lazarus Group
|
||||
T1007,System Service Discovery,Discovery,Indrik Spider|Chimera|Operation Wocao|BRONZE BUTLER|APT1|OilRig|Poseidon Group|admin@338|Turla|Ke3chang
|
||||
T1006,Direct Volume Access,Defense Evasion,no
|
||||
T1005,Data from Local System,Collection,FIN7|APT41|APT38|Andariel|APT29|Windigo|UNC2452|Fox Kitten|Sandworm Team|Operation Wocao|FIN6|Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|GALLIUM|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang
|
||||
T1005,Data from Local System,Collection,FIN7|APT41|APT38|Andariel|APT29|Windigo|Fox Kitten|Sandworm Team|Operation Wocao|FIN6|Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|GALLIUM|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang
|
||||
T1003,OS Credential Dumping,Credential Access,Tonto Team|APT39|Frankenstein|APT32|APT28|Leviathan|Sowbug|Suckfly|Poseidon Group|Axiom
|
||||
T1001,Data Obfuscation,Command And Control,Operation Wocao|Axiom
|
||||
|
||||
|
+1
-48
@@ -1,48 +1 @@
|
||||
{
|
||||
"baselines": [
|
||||
{
|
||||
"name": "Previously Seen Users In CloudTrail - Update",
|
||||
"id": "66ff71c2-7e01-47dd-a041-906688c9d322",
|
||||
"version": 1,
|
||||
"date": "2020-05-28",
|
||||
"author": "Rico Valdez, Splunk",
|
||||
"type": "Baseline",
|
||||
"datamodel": [
|
||||
"Authentication"
|
||||
],
|
||||
"description": "This search looks for CloudTrail events where a user logs into the console, then updates the baseline of the latest and earliest times, City, Region, and Country we have encountered this user in our dataset, grouped by user, within the last hour.",
|
||||
"search": "| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src | iplocation Authentication.src | rename Authentication.user as user Authentication.src as src | table user src City Region Country firstTime lastTime | inputlookup append=t previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime) as lastTime by user src City Region Country | outputlookup previously_seen_users_console_logins",
|
||||
"how_to_implement": "You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Validate the user name entries in `previously_seen_users_console_logins`, which is a lookup file created by this support search.",
|
||||
"known_false_positives": "none",
|
||||
"references": [],
|
||||
"tags": {
|
||||
"analytic_story": [
|
||||
"Suspicious Cloud Authentication Activities"
|
||||
],
|
||||
"deployments": [
|
||||
"Daily Cache Updates"
|
||||
],
|
||||
"detections": [
|
||||
"Detect AWS Console Login by User from New Country",
|
||||
"Detect AWS Console Login by User from New Region",
|
||||
"Detect AWS Console Login by User from New City",
|
||||
"Detect AWS Console Login by New User",
|
||||
"Attempted Credential Dump From Registry via Reg exe"
|
||||
],
|
||||
"product": [
|
||||
"Splunk Security Analytics for AWS",
|
||||
"Splunk Enterprise",
|
||||
"Splunk Enterprise Security",
|
||||
"Splunk Cloud"
|
||||
],
|
||||
"required_fields": [
|
||||
"_time",
|
||||
"Authentication.signature",
|
||||
"Authentication.user",
|
||||
"Authentication.src"
|
||||
],
|
||||
"security_domain": "network"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
{"baselines": [{"name": "Previously Seen Users In CloudTrail - Update", "id": "66ff71c2-7e01-47dd-a041-906688c9d322", "version": 1, "date": "2020-05-28", "author": "Rico Valdez, Splunk", "type": "Baseline", "datamodel": ["Authentication"], "description": "This search looks for CloudTrail events where a user logs into the console, then updates the baseline of the latest and earliest times, City, Region, and Country we have encountered this user in our dataset, grouped by user, within the last hour.", "search": "| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src | iplocation Authentication.src | rename Authentication.user as user Authentication.src as src | table user src City Region Country firstTime lastTime | inputlookup append=t previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime) as lastTime by user src City Region Country | outputlookup previously_seen_users_console_logins", "how_to_implement": "You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Validate the user name entries in `previously_seen_users_console_logins`, which is a lookup file created by this support search.", "known_false_positives": "none", "references": [], "tags": {"analytic_story": ["Suspicious Cloud Authentication Activities"], "deployments": ["Daily Cache Updates"], "detections": ["Detect AWS Console Login by User from New Country", "Detect AWS Console Login by User from New Region", "Detect AWS Console Login by User from New City", "Detect AWS Console Login by New User", "Attempted Credential Dump From Registry via Reg exe"], "product": ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "required_fields": ["_time", "Authentication.signature", "Authentication.user", "Authentication.src"], "security_domain": "network"}}]}
|
||||
+1
-48
@@ -1,48 +1 @@
|
||||
{
|
||||
"baselines": [
|
||||
{
|
||||
"name": "Previously Seen Users In CloudTrail - Update",
|
||||
"id": "66ff71c2-7e01-47dd-a041-906688c9d322",
|
||||
"version": 1,
|
||||
"date": "2020-05-28",
|
||||
"author": "Rico Valdez, Splunk",
|
||||
"type": "Baseline",
|
||||
"datamodel": [
|
||||
"Authentication"
|
||||
],
|
||||
"description": "This search looks for CloudTrail events where a user logs into the console, then updates the baseline of the latest and earliest times, City, Region, and Country we have encountered this user in our dataset, grouped by user, within the last hour.",
|
||||
"search": "| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src | iplocation Authentication.src | rename Authentication.user as user Authentication.src as src | table user src City Region Country firstTime lastTime | inputlookup append=t previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime) as lastTime by user src City Region Country | outputlookup previously_seen_users_console_logins",
|
||||
"how_to_implement": "You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Validate the user name entries in `previously_seen_users_console_logins`, which is a lookup file created by this support search.",
|
||||
"known_false_positives": "none",
|
||||
"references": [],
|
||||
"tags": {
|
||||
"analytic_story": [
|
||||
"Suspicious Cloud Authentication Activities"
|
||||
],
|
||||
"deployments": [
|
||||
"Daily Cache Updates"
|
||||
],
|
||||
"detections": [
|
||||
"Detect AWS Console Login by User from New Country",
|
||||
"Detect AWS Console Login by User from New Region",
|
||||
"Detect AWS Console Login by User from New City",
|
||||
"Detect AWS Console Login by New User",
|
||||
"Attempted Credential Dump From Registry via Reg exe"
|
||||
],
|
||||
"product": [
|
||||
"Splunk Security Analytics for AWS",
|
||||
"Splunk Enterprise",
|
||||
"Splunk Enterprise Security",
|
||||
"Splunk Cloud"
|
||||
],
|
||||
"required_fields": [
|
||||
"_time",
|
||||
"Authentication.signature",
|
||||
"Authentication.user",
|
||||
"Authentication.src"
|
||||
],
|
||||
"security_domain": "network"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
{"baselines": [{"name": "Previously Seen Users In CloudTrail - Update", "id": "66ff71c2-7e01-47dd-a041-906688c9d322", "version": 1, "date": "2020-05-28", "author": "Rico Valdez, Splunk", "type": "Baseline", "datamodel": ["Authentication"], "description": "This search looks for CloudTrail events where a user logs into the console, then updates the baseline of the latest and earliest times, City, Region, and Country we have encountered this user in our dataset, grouped by user, within the last hour.", "search": "| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src | iplocation Authentication.src | rename Authentication.user as user Authentication.src as src | table user src City Region Country firstTime lastTime | inputlookup append=t previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime) as lastTime by user src City Region Country | outputlookup previously_seen_users_console_logins", "how_to_implement": "You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Validate the user name entries in `previously_seen_users_console_logins`, which is a lookup file created by this support search.", "known_false_positives": "none", "references": [], "tags": {"analytic_story": ["Suspicious Cloud Authentication Activities"], "deployments": ["Daily Cache Updates"], "detections": ["Detect AWS Console Login by User from New Country", "Detect AWS Console Login by User from New Region", "Detect AWS Console Login by User from New City", "Detect AWS Console Login by New User", "Attempted Credential Dump From Registry via Reg exe"], "product": ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "required_fields": ["_time", "Authentication.signature", "Authentication.user", "Authentication.src"], "security_domain": "network"}}]}
|
||||
+1
-20
@@ -1,20 +1 @@
|
||||
{
|
||||
"deployments": [
|
||||
{
|
||||
"name": "ESCU Default Configuration Baseline",
|
||||
"id": "0f7ee854-1aad-4bef-89c5-5c402b488510",
|
||||
"date": "2021-12-21",
|
||||
"author": "Patrick Bareiss",
|
||||
"description": "This configuration file applies to all detections of type baseline.",
|
||||
"scheduling": {
|
||||
"cron_schedule": "0 * * * *",
|
||||
"earliest_time": "-70m@m",
|
||||
"latest_time": "-10m@m",
|
||||
"schedule_window": "auto"
|
||||
},
|
||||
"tags": {
|
||||
"type": "Baseline"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
{"deployments": [{"name": "ESCU Default Configuration Baseline", "id": "0f7ee854-1aad-4bef-89c5-5c402b488510", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type baseline.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "tags": {"type": "Baseline"}}]}
|
||||
+1
-20
@@ -1,20 +1 @@
|
||||
{
|
||||
"deployments": [
|
||||
{
|
||||
"name": "ESCU Default Configuration Baseline",
|
||||
"id": "0f7ee854-1aad-4bef-89c5-5c402b488510",
|
||||
"date": "2021-12-21",
|
||||
"author": "Patrick Bareiss",
|
||||
"description": "This configuration file applies to all detections of type baseline.",
|
||||
"scheduling": {
|
||||
"cron_schedule": "0 * * * *",
|
||||
"earliest_time": "-70m@m",
|
||||
"latest_time": "-10m@m",
|
||||
"schedule_window": "auto"
|
||||
},
|
||||
"tags": {
|
||||
"type": "Baseline"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
{"deployments": [{"name": "ESCU Default Configuration Baseline", "id": "0f7ee854-1aad-4bef-89c5-5c402b488510", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type baseline.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "tags": {"type": "Baseline"}}]}
|
||||
+1
-170
@@ -1,170 +1 @@
|
||||
{
|
||||
"detections": [
|
||||
{
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911",
|
||||
"version": 6,
|
||||
"date": "2021-09-16",
|
||||
"author": "Patrick Bareiss, Splunk",
|
||||
"type": "TTP",
|
||||
"datamodel": [
|
||||
"Endpoint"
|
||||
],
|
||||
"description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.",
|
||||
"search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`",
|
||||
"how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.",
|
||||
"known_false_positives": "None identified.",
|
||||
"references": [
|
||||
"https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"
|
||||
],
|
||||
"tags": {
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"analytic_story": [
|
||||
"Credential Dumping",
|
||||
"DarkSide Ransomware"
|
||||
],
|
||||
"asset_type": "Endpoint",
|
||||
"automated_detection_testing": "passed",
|
||||
"cis20": [
|
||||
"CIS 3",
|
||||
"CIS 5",
|
||||
"CIS 16"
|
||||
],
|
||||
"confidence": 100,
|
||||
"context": [
|
||||
"Source:Endpoint",
|
||||
"Stage:Credential Access"
|
||||
],
|
||||
"dataset": [
|
||||
"https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"
|
||||
],
|
||||
"impact": 90,
|
||||
"kill_chain_phases": [
|
||||
"Actions on Objectives"
|
||||
],
|
||||
"message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.",
|
||||
"mitre_attack_id": [
|
||||
"T1003.002",
|
||||
"T1003"
|
||||
],
|
||||
"nist": [
|
||||
"DE.CM"
|
||||
],
|
||||
"observable": [
|
||||
{
|
||||
"name": "user",
|
||||
"type": "User",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "dest",
|
||||
"type": "Hostname",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "parent_process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Parent Process"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Child Process"
|
||||
]
|
||||
}
|
||||
],
|
||||
"product": [
|
||||
"Splunk Enterprise",
|
||||
"Splunk Enterprise Security",
|
||||
"Splunk Cloud"
|
||||
],
|
||||
"required_fields": [
|
||||
"_time",
|
||||
"Processes.dest",
|
||||
"Processes.user",
|
||||
"Processes.parent_process_name",
|
||||
"Processes.parent_process",
|
||||
"Processes.original_file_name",
|
||||
"Processes.process_name",
|
||||
"Processes.process",
|
||||
"Processes.process_id",
|
||||
"Processes.parent_process_path",
|
||||
"Processes.process_path",
|
||||
"Processes.parent_process_id"
|
||||
],
|
||||
"risk_score": 90,
|
||||
"security_domain": "endpoint",
|
||||
"risk_severity": "high",
|
||||
"supported_tas": [
|
||||
"Splunk_TA_microsoft_sysmon"
|
||||
],
|
||||
"mitre_attack_enrichments": [
|
||||
{
|
||||
"mitre_attack_id": "T1003.002",
|
||||
"mitre_attack_technique": "Security Account Manager",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"Dragonfly 2.0",
|
||||
"GALLIUM",
|
||||
"Ke3chang",
|
||||
"Night Dragon",
|
||||
"Threat Group-3390",
|
||||
"Wizard Spider",
|
||||
"menuPass"
|
||||
]
|
||||
},
|
||||
{
|
||||
"mitre_attack_id": "T1003",
|
||||
"mitre_attack_technique": "OS Credential Dumping",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"APT28",
|
||||
"APT32",
|
||||
"APT39",
|
||||
"Axiom",
|
||||
"Frankenstein",
|
||||
"Leviathan",
|
||||
"Poseidon Group",
|
||||
"Sowbug",
|
||||
"Suckfly",
|
||||
"Tonto Team"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"macros": [
|
||||
{
|
||||
"name": "process_reg",
|
||||
"definition": "(Processes.process_name=reg.exe OR Processes.original_file_name=reg.exe)",
|
||||
"description": "Matches the process with its original file name, data for this macro came from https://strontic.github.io/"
|
||||
},
|
||||
{
|
||||
"name": "attempted_credential_dump_from_registry_via_reg_exe_filter",
|
||||
"definition": "search *",
|
||||
"description": "Update this macro to limit the output results to filter out false positives."
|
||||
}
|
||||
],
|
||||
"lookups": [],
|
||||
"cve_enrichment": [],
|
||||
"splunk_app_enrichment": [
|
||||
{
|
||||
"name": "Splunk Add-on for Sysmon",
|
||||
"url": "https://splunkbase.splunk.com/app/5709"
|
||||
}
|
||||
],
|
||||
"file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml",
|
||||
"source": "detection"
|
||||
}
|
||||
]
|
||||
}
|
||||
{"detections": [{"name": "Attempted Credential Dump From Registry via Reg exe", "id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911", "version": 6, "date": "2021-09-16", "author": "Patrick Bareiss, Splunk", "type": "TTP", "datamodel": ["Endpoint"], "description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.", "search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`", "how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.", "known_false_positives": "None identified.", "references": ["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"], "tags": {"name": "Attempted Credential Dump From Registry via Reg exe", "analytic_story": ["Credential Dumping", "DarkSide Ransomware"], "asset_type": "Endpoint", "automated_detection_testing": "passed", "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Credential Access"], "dataset": ["https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"], "impact": 90, "kill_chain_phases": ["Actions on Objectives"], "message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.", "mitre_attack_id": ["T1003.002", "T1003"], "nist": ["DE.CM"], "observable": [{"name": "user", "type": "User", "role": ["Victim"]}, {"name": "dest", "type": "Hostname", "role": ["Victim"]}, {"name": "parent_process_name", "type": "Process", "role": ["Parent Process"]}, {"name": "process_name", "type": "Process", "role": ["Child Process"]}], "product": ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "required_fields": ["_time", "Processes.dest", "Processes.user", "Processes.parent_process_name", "Processes.parent_process", "Processes.original_file_name", "Processes.process_name", "Processes.process", "Processes.process_id", "Processes.parent_process_path", "Processes.process_path", "Processes.parent_process_id"], "risk_score": 90, "security_domain": "endpoint", "risk_severity": "high", "supported_tas": ["Splunk_TA_microsoft_sysmon"], "mitre_attack_enrichments": [{"mitre_attack_id": "T1003.002", "mitre_attack_technique": "Security Account Manager", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["Dragonfly 2.0", "GALLIUM", "Ke3chang", "Night Dragon", "Threat Group-3390", "Wizard Spider", "menuPass"]}, {"mitre_attack_id": "T1003", "mitre_attack_technique": "OS Credential Dumping", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["APT28", "APT32", "APT39", "Axiom", "Frankenstein", "Leviathan", "Poseidon Group", "Sowbug", "Suckfly", "Tonto Team"]}]}, "macros": [{"name": "process_reg", "definition": "(Processes.process_name=reg.exe OR Processes.original_file_name=reg.exe)", "description": "Matches the process with its original file name, data for this macro came from https://strontic.github.io/"}, {"name": "attempted_credential_dump_from_registry_via_reg_exe_filter", "definition": "search *", "description": "Update this macro to limit the output results to filter out false positives."}], "lookups": [], "cve_enrichment": [], "splunk_app_enrichment": [{"name": "Splunk Add-on for Sysmon", "url": "https://splunkbase.splunk.com/app/5709"}], "file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml", "source": "detection"}]}
|
||||
+1
-168
@@ -1,168 +1 @@
|
||||
{
|
||||
"detections": [
|
||||
{
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911",
|
||||
"version": 6,
|
||||
"date": "2021-09-16",
|
||||
"author": "Patrick Bareiss, Splunk",
|
||||
"type": "TTP",
|
||||
"datamodel": [
|
||||
"Endpoint"
|
||||
],
|
||||
"description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.",
|
||||
"search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`",
|
||||
"how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.",
|
||||
"known_false_positives": "None identified.",
|
||||
"references": [
|
||||
"https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"
|
||||
],
|
||||
"tags": {
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"analytic_story": [
|
||||
"Credential Dumping",
|
||||
"DarkSide Ransomware"
|
||||
],
|
||||
"asset_type": "Endpoint",
|
||||
"automated_detection_testing": "passed",
|
||||
"cis20": [
|
||||
"CIS 3",
|
||||
"CIS 5",
|
||||
"CIS 16"
|
||||
],
|
||||
"confidence": 100,
|
||||
"context": [
|
||||
"Source:Endpoint",
|
||||
"Stage:Credential Access"
|
||||
],
|
||||
"dataset": [
|
||||
"https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"
|
||||
],
|
||||
"impact": 90,
|
||||
"kill_chain_phases": [
|
||||
"Actions on Objectives"
|
||||
],
|
||||
"message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.",
|
||||
"mitre_attack_id": [
|
||||
"T1003.002",
|
||||
"T1003"
|
||||
],
|
||||
"nist": [
|
||||
"DE.CM"
|
||||
],
|
||||
"observable": [
|
||||
{
|
||||
"name": "user",
|
||||
"type": "User",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "dest",
|
||||
"type": "Hostname",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "parent_process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Parent Process"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Child Process"
|
||||
]
|
||||
}
|
||||
],
|
||||
"product": [
|
||||
"Splunk Enterprise",
|
||||
"Splunk Enterprise Security",
|
||||
"Splunk Cloud"
|
||||
],
|
||||
"required_fields": [
|
||||
"_time",
|
||||
"Processes.dest",
|
||||
"Processes.user",
|
||||
"Processes.parent_process_name",
|
||||
"Processes.parent_process",
|
||||
"Processes.original_file_name",
|
||||
"Processes.process_name",
|
||||
"Processes.process",
|
||||
"Processes.process_id",
|
||||
"Processes.parent_process_path",
|
||||
"Processes.process_path",
|
||||
"Processes.parent_process_id"
|
||||
],
|
||||
"risk_score": 90,
|
||||
"security_domain": "endpoint",
|
||||
"risk_severity": "high",
|
||||
"supported_tas": [
|
||||
"Splunk_TA_microsoft_sysmon"
|
||||
],
|
||||
"mitre_attack_enrichments": [
|
||||
{
|
||||
"mitre_attack_id": "T1003.002",
|
||||
"mitre_attack_technique": "Security Account Manager",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"Dragonfly 2.0",
|
||||
"Ke3chang",
|
||||
"Night Dragon",
|
||||
"Soft Cell",
|
||||
"Threat Group-3390",
|
||||
"menuPass"
|
||||
]
|
||||
},
|
||||
{
|
||||
"mitre_attack_id": "T1003",
|
||||
"mitre_attack_technique": "OS Credential Dumping",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"APT28",
|
||||
"APT32",
|
||||
"APT39",
|
||||
"Axiom",
|
||||
"Frankenstein",
|
||||
"Leviathan",
|
||||
"Poseidon Group",
|
||||
"Sowbug",
|
||||
"Suckfly"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"macros": [
|
||||
{
|
||||
"name": "process_reg",
|
||||
"definition": "(Processes.process_name=reg.exe OR Processes.original_file_name=reg.exe)",
|
||||
"description": "Matches the process with its original file name, data for this macro came from https://strontic.github.io/"
|
||||
},
|
||||
{
|
||||
"name": "attempted_credential_dump_from_registry_via_reg_exe_filter",
|
||||
"definition": "search *",
|
||||
"description": "Update this macro to limit the output results to filter out false positives."
|
||||
}
|
||||
],
|
||||
"lookups": [],
|
||||
"cve_enrichment": [],
|
||||
"splunk_app_enrichment": [
|
||||
{
|
||||
"name": "Splunk Add-on for Sysmon",
|
||||
"url": "https://splunkbase.splunk.com/app/5709"
|
||||
}
|
||||
],
|
||||
"file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml",
|
||||
"source": "detection"
|
||||
}
|
||||
]
|
||||
}
|
||||
{"detections": [{"name": "Attempted Credential Dump From Registry via Reg exe", "id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911", "version": 6, "date": "2021-09-16", "author": "Patrick Bareiss, Splunk", "type": "TTP", "datamodel": ["Endpoint"], "description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.", "search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`", "how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.", "known_false_positives": "None identified.", "references": ["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"], "tags": {"name": "Attempted Credential Dump From Registry via Reg exe", "analytic_story": ["Credential Dumping", "DarkSide Ransomware"], "asset_type": "Endpoint", "automated_detection_testing": "passed", "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Credential Access"], "dataset": ["https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"], "impact": 90, "kill_chain_phases": ["Actions on Objectives"], "message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.", "mitre_attack_id": ["T1003.002", "T1003"], "nist": ["DE.CM"], "observable": [{"name": "user", "type": "User", "role": ["Victim"]}, {"name": "dest", "type": "Hostname", "role": ["Victim"]}, {"name": "parent_process_name", "type": "Process", "role": ["Parent Process"]}, {"name": "process_name", "type": "Process", "role": ["Child Process"]}], "product": ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "required_fields": ["_time", "Processes.dest", "Processes.user", "Processes.parent_process_name", "Processes.parent_process", "Processes.original_file_name", "Processes.process_name", "Processes.process", "Processes.process_id", "Processes.parent_process_path", "Processes.process_path", "Processes.parent_process_id"], "risk_score": 90, "security_domain": "endpoint", "risk_severity": "high", "supported_tas": ["Splunk_TA_microsoft_sysmon"], "mitre_attack_enrichments": [{"mitre_attack_id": "T1003.002", "mitre_attack_technique": "Security Account Manager", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["Dragonfly 2.0", "GALLIUM", "Ke3chang", "Night Dragon", "Threat Group-3390", "Wizard Spider", "menuPass"]}, {"mitre_attack_id": "T1003", "mitre_attack_technique": "OS Credential Dumping", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["APT28", "APT32", "APT39", "Axiom", "Frankenstein", "Leviathan", "Poseidon Group", "Sowbug", "Suckfly", "Tonto Team"]}]}, "macros": [{"name": "process_reg", "definition": "(Processes.process_name=reg.exe OR Processes.original_file_name=reg.exe)", "description": "Matches the process with its original file name, data for this macro came from https://strontic.github.io/"}, {"name": "attempted_credential_dump_from_registry_via_reg_exe_filter", "definition": "search *", "description": "Update this macro to limit the output results to filter out false positives."}], "lookups": [], "cve_enrichment": [], "splunk_app_enrichment": [{"name": "Splunk Add-on for Sysmon", "url": "https://splunkbase.splunk.com/app/5709"}], "file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml", "source": "detection"}]}
|
||||
+1
-11
@@ -1,11 +1 @@
|
||||
{
|
||||
"lookups": [
|
||||
{
|
||||
"name": "previously_seen_aws_regions",
|
||||
"description": "A place holder for a list of used AWS regions",
|
||||
"filename": "previously_seen_aws_regions.csv",
|
||||
"default_match": "false",
|
||||
"min_matches": 1
|
||||
}
|
||||
]
|
||||
}
|
||||
{"lookups": [{"name": "previously_seen_aws_regions", "description": "A place holder for a list of used AWS regions", "filename": "previously_seen_aws_regions.csv", "default_match": "false", "min_matches": 1}]}
|
||||
+1
-11
@@ -1,11 +1 @@
|
||||
{
|
||||
"lookups": [
|
||||
{
|
||||
"name": "previously_seen_aws_regions",
|
||||
"description": "A place holder for a list of used AWS regions",
|
||||
"filename": "previously_seen_aws_regions.csv",
|
||||
"default_match": "false",
|
||||
"min_matches": 1
|
||||
}
|
||||
]
|
||||
}
|
||||
{"lookups": [{"name": "previously_seen_aws_regions", "description": "A place holder for a list of used AWS regions", "filename": "previously_seen_aws_regions.csv", "default_match": "false", "min_matches": 1}]}
|
||||
+1
-9
@@ -1,9 +1 @@
|
||||
{
|
||||
"macros": [
|
||||
{
|
||||
"name": "powershell",
|
||||
"definition": "(source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source=\"XmlWinEventLog:Microsoft-Windows-PowerShell/Operational\")",
|
||||
"description": "customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent."
|
||||
}
|
||||
]
|
||||
}
|
||||
{"macros": [{"name": "powershell", "definition": "(source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source=\"XmlWinEventLog:Microsoft-Windows-PowerShell/Operational\")", "description": "customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent."}]}
|
||||
+1
-9
@@ -1,9 +1 @@
|
||||
{
|
||||
"macros": [
|
||||
{
|
||||
"name": "powershell",
|
||||
"definition": "(source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source=\"XmlWinEventLog:Microsoft-Windows-PowerShell/Operational\")",
|
||||
"description": "customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent."
|
||||
}
|
||||
]
|
||||
}
|
||||
{"macros": [{"name": "powershell", "definition": "(source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source=\"XmlWinEventLog:Microsoft-Windows-PowerShell/Operational\")", "description": "customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent."}]}
|
||||
+1
-69
@@ -1,69 +1 @@
|
||||
{
|
||||
"response_tasks": [
|
||||
{
|
||||
"name": "Get Parent Process Info",
|
||||
"id": "fecf2918-670d-4f1c-872b-3d7317a41bf9",
|
||||
"version": 2,
|
||||
"date": "2019-02-28",
|
||||
"author": "Bhavin Patel, Splunk",
|
||||
"type": "Investigation",
|
||||
"datamodel": [
|
||||
"Endpoint"
|
||||
],
|
||||
"description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest",
|
||||
"search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`",
|
||||
"how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.",
|
||||
"known_false_positives": "",
|
||||
"references": [],
|
||||
"inputs": [
|
||||
"parent_process_name",
|
||||
"dest"
|
||||
],
|
||||
"tags": {
|
||||
"analytic_story": [
|
||||
"Collection and Staging",
|
||||
"Command and Control",
|
||||
"DHS Report TA18-074A",
|
||||
"Disabling Security Tools",
|
||||
"Emotet Malware DHS Report TA18-201A ",
|
||||
"Hidden Cobra Malware",
|
||||
"Lateral Movement",
|
||||
"Malicious PowerShell",
|
||||
"Monitor for Unauthorized Software",
|
||||
"Netsh Abuse",
|
||||
"Orangeworm Attack Group",
|
||||
"Phishing Payloads",
|
||||
"Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns",
|
||||
"Prohibited Traffic Allowed or Protocol Mismatch",
|
||||
"Ransomware",
|
||||
"SamSam Ransomware",
|
||||
"Suspicious Command-Line Executions",
|
||||
"Suspicious DNS Traffic",
|
||||
"Suspicious MSHTA Activity",
|
||||
"Suspicious WMI Use",
|
||||
"Suspicious Windows Registry Activities",
|
||||
"Unusual Processes",
|
||||
"Windows Defense Evasion Tactics",
|
||||
"Windows File Extension and Association Abuse",
|
||||
"Windows Log Manipulation",
|
||||
"Windows Persistence Techniques",
|
||||
"Windows Privilege Escalation",
|
||||
"Windows Service Abuse",
|
||||
"DarkSide Ransomware"
|
||||
],
|
||||
"product": [
|
||||
"Splunk Phantom"
|
||||
],
|
||||
"required_fields": [
|
||||
"_time",
|
||||
"Processes.user",
|
||||
"Processes.parent_process_name",
|
||||
"Processes.process_name",
|
||||
"Processes.dest"
|
||||
],
|
||||
"security_domain": "endpoint"
|
||||
},
|
||||
"lowercase_name": "get_parent_process_info"
|
||||
}
|
||||
]
|
||||
}
|
||||
{"response_tasks": [{"name": "Get Parent Process Info", "id": "fecf2918-670d-4f1c-872b-3d7317a41bf9", "version": 2, "date": "2019-02-28", "author": "Bhavin Patel, Splunk", "type": "Investigation", "datamodel": ["Endpoint"], "description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest", "search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`", "how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.", "known_false_positives": "", "references": [], "inputs": ["parent_process_name", "dest"], "tags": {"analytic_story": ["Collection and Staging", "Command and Control", "DHS Report TA18-074A", "Disabling Security Tools", "Emotet Malware DHS Report TA18-201A ", "Hidden Cobra Malware", "Lateral Movement", "Malicious PowerShell", "Monitor for Unauthorized Software", "Netsh Abuse", "Orangeworm Attack Group", "Phishing Payloads", "Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns", "Prohibited Traffic Allowed or Protocol Mismatch", "Ransomware", "SamSam Ransomware", "Suspicious Command-Line Executions", "Suspicious DNS Traffic", "Suspicious MSHTA Activity", "Suspicious WMI Use", "Suspicious Windows Registry Activities", "Unusual Processes", "Windows Defense Evasion Tactics", "Windows File Extension and Association Abuse", "Windows Log Manipulation", "Windows Persistence Techniques", "Windows Privilege Escalation", "Windows Service Abuse", "DarkSide Ransomware"], "product": ["Splunk Phantom"], "required_fields": ["_time", "Processes.user", "Processes.parent_process_name", "Processes.process_name", "Processes.dest"], "security_domain": "endpoint"}, "lowercase_name": "get_parent_process_info"}]}
|
||||
+1
-69
@@ -1,69 +1 @@
|
||||
{
|
||||
"response_tasks": [
|
||||
{
|
||||
"name": "Get Parent Process Info",
|
||||
"id": "fecf2918-670d-4f1c-872b-3d7317a41bf9",
|
||||
"version": 2,
|
||||
"date": "2019-02-28",
|
||||
"author": "Bhavin Patel, Splunk",
|
||||
"type": "Investigation",
|
||||
"datamodel": [
|
||||
"Endpoint"
|
||||
],
|
||||
"description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest",
|
||||
"search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`",
|
||||
"how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.",
|
||||
"known_false_positives": "",
|
||||
"references": [],
|
||||
"inputs": [
|
||||
"parent_process_name",
|
||||
"dest"
|
||||
],
|
||||
"tags": {
|
||||
"analytic_story": [
|
||||
"Collection and Staging",
|
||||
"Command and Control",
|
||||
"DHS Report TA18-074A",
|
||||
"Disabling Security Tools",
|
||||
"Emotet Malware DHS Report TA18-201A ",
|
||||
"Hidden Cobra Malware",
|
||||
"Lateral Movement",
|
||||
"Malicious PowerShell",
|
||||
"Monitor for Unauthorized Software",
|
||||
"Netsh Abuse",
|
||||
"Orangeworm Attack Group",
|
||||
"Phishing Payloads",
|
||||
"Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns",
|
||||
"Prohibited Traffic Allowed or Protocol Mismatch",
|
||||
"Ransomware",
|
||||
"SamSam Ransomware",
|
||||
"Suspicious Command-Line Executions",
|
||||
"Suspicious DNS Traffic",
|
||||
"Suspicious MSHTA Activity",
|
||||
"Suspicious WMI Use",
|
||||
"Suspicious Windows Registry Activities",
|
||||
"Unusual Processes",
|
||||
"Windows Defense Evasion Tactics",
|
||||
"Windows File Extension and Association Abuse",
|
||||
"Windows Log Manipulation",
|
||||
"Windows Persistence Techniques",
|
||||
"Windows Privilege Escalation",
|
||||
"Windows Service Abuse",
|
||||
"DarkSide Ransomware"
|
||||
],
|
||||
"product": [
|
||||
"Splunk Phantom"
|
||||
],
|
||||
"required_fields": [
|
||||
"_time",
|
||||
"Processes.user",
|
||||
"Processes.parent_process_name",
|
||||
"Processes.process_name",
|
||||
"Processes.dest"
|
||||
],
|
||||
"security_domain": "endpoint"
|
||||
},
|
||||
"lowercase_name": "get_parent_process_info"
|
||||
}
|
||||
]
|
||||
}
|
||||
{"response_tasks": [{"name": "Get Parent Process Info", "id": "fecf2918-670d-4f1c-872b-3d7317a41bf9", "version": 2, "date": "2019-02-28", "author": "Bhavin Patel, Splunk", "type": "Investigation", "datamodel": ["Endpoint"], "description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest", "search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`", "how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.", "known_false_positives": "", "references": [], "inputs": ["parent_process_name", "dest"], "tags": {"analytic_story": ["Collection and Staging", "Command and Control", "DHS Report TA18-074A", "Disabling Security Tools", "Emotet Malware DHS Report TA18-201A ", "Hidden Cobra Malware", "Lateral Movement", "Malicious PowerShell", "Monitor for Unauthorized Software", "Netsh Abuse", "Orangeworm Attack Group", "Phishing Payloads", "Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns", "Prohibited Traffic Allowed or Protocol Mismatch", "Ransomware", "SamSam Ransomware", "Suspicious Command-Line Executions", "Suspicious DNS Traffic", "Suspicious MSHTA Activity", "Suspicious WMI Use", "Suspicious Windows Registry Activities", "Unusual Processes", "Windows Defense Evasion Tactics", "Windows File Extension and Association Abuse", "Windows Log Manipulation", "Windows Persistence Techniques", "Windows Privilege Escalation", "Windows Service Abuse", "DarkSide Ransomware"], "product": ["Splunk Phantom"], "required_fields": ["_time", "Processes.user", "Processes.parent_process_name", "Processes.process_name", "Processes.dest"], "security_domain": "endpoint"}, "lowercase_name": "get_parent_process_info"}]}
|
||||
+1
-508
@@ -1,508 +1 @@
|
||||
{
|
||||
"stories": [
|
||||
{
|
||||
"name": "DarkSide Ransomware",
|
||||
"id": "507edc74-13d5-4339-878e-b9114ded1f35",
|
||||
"version": 1,
|
||||
"date": "2021-05-12",
|
||||
"author": "Bhavin Patel, Splunk",
|
||||
"description": "Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware",
|
||||
"narrative": "This story addresses Darkside ransomware. This ransomware payload has many similarities to common ransomware however there are certain items particular to it. The creation of a .TXT log that shows every item being encrypted as well as the creation of ransomware notes and files adding a machine ID created based on CRC32 checksum algorithm. This ransomware payload leaves machines in minimal operation level,enough to browse the attackers websites. A customized URI with leaked information is presented to each victim.This is the ransomware payload that shut down the Colonial pipeline. The story is composed of several detection searches covering similar items to other ransomware payloads and those particular to Darkside payload.",
|
||||
"references": [
|
||||
"https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/",
|
||||
"https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html"
|
||||
],
|
||||
"tags": {
|
||||
"name": "DarkSide Ransomware",
|
||||
"analytic_story": "DarkSide Ransomware",
|
||||
"category": [
|
||||
"Malware"
|
||||
],
|
||||
"product": [
|
||||
"Splunk Enterprise",
|
||||
"Splunk Enterprise Security",
|
||||
"Splunk Cloud"
|
||||
],
|
||||
"usecase": "Advanced Threat Detection",
|
||||
"mitre_attack_enrichments": [
|
||||
{
|
||||
"mitre_attack_id": "T1003.002",
|
||||
"mitre_attack_technique": "Security Account Manager",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"Dragonfly 2.0",
|
||||
"GALLIUM",
|
||||
"Ke3chang",
|
||||
"Night Dragon",
|
||||
"Threat Group-3390",
|
||||
"Wizard Spider",
|
||||
"menuPass"
|
||||
]
|
||||
},
|
||||
{
|
||||
"mitre_attack_id": "T1003",
|
||||
"mitre_attack_technique": "OS Credential Dumping",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"APT28",
|
||||
"APT32",
|
||||
"APT39",
|
||||
"Axiom",
|
||||
"Frankenstein",
|
||||
"Leviathan",
|
||||
"Poseidon Group",
|
||||
"Sowbug",
|
||||
"Suckfly",
|
||||
"Tonto Team"
|
||||
]
|
||||
}
|
||||
],
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"datamodels": [
|
||||
"Endpoint"
|
||||
],
|
||||
"kill_chain_phases": [
|
||||
"Actions on Objectives"
|
||||
]
|
||||
},
|
||||
"detection_names": [
|
||||
"ESCU - Attempted Credential Dump From Registry via Reg exe - Rule"
|
||||
],
|
||||
"investigation_names": [
|
||||
"ESCU - Get Parent Process Info - Response Task"
|
||||
],
|
||||
"baseline_names": [
|
||||
"ESCU - Baseline Of Cloud Instances Launched"
|
||||
],
|
||||
"author_company": "Splunk",
|
||||
"author_name": "Bhavin Patel",
|
||||
"detections": [
|
||||
{
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911",
|
||||
"version": 6,
|
||||
"date": "2021-09-16",
|
||||
"author": "Patrick Bareiss, Splunk",
|
||||
"type": "TTP",
|
||||
"datamodel": [
|
||||
"Endpoint"
|
||||
],
|
||||
"description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.",
|
||||
"search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`",
|
||||
"how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.",
|
||||
"known_false_positives": "None identified.",
|
||||
"references": [
|
||||
"https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"
|
||||
],
|
||||
"tags": {
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"analytic_story": [
|
||||
"Credential Dumping",
|
||||
"DarkSide Ransomware"
|
||||
],
|
||||
"asset_type": "Endpoint",
|
||||
"automated_detection_testing": "passed",
|
||||
"cis20": [
|
||||
"CIS 3",
|
||||
"CIS 5",
|
||||
"CIS 16"
|
||||
],
|
||||
"confidence": 100,
|
||||
"context": [
|
||||
"Source:Endpoint",
|
||||
"Stage:Credential Access"
|
||||
],
|
||||
"dataset": [
|
||||
"https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"
|
||||
],
|
||||
"impact": 90,
|
||||
"kill_chain_phases": [
|
||||
"Actions on Objectives"
|
||||
],
|
||||
"message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.",
|
||||
"mitre_attack_id": [
|
||||
"T1003.002",
|
||||
"T1003"
|
||||
],
|
||||
"nist": [
|
||||
"DE.CM"
|
||||
],
|
||||
"observable": [
|
||||
{
|
||||
"name": "user",
|
||||
"type": "User",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "dest",
|
||||
"type": "Hostname",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "parent_process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Parent Process"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Child Process"
|
||||
]
|
||||
}
|
||||
],
|
||||
"product": [
|
||||
"Splunk Enterprise",
|
||||
"Splunk Enterprise Security",
|
||||
"Splunk Cloud"
|
||||
],
|
||||
"required_fields": [
|
||||
"_time",
|
||||
"Processes.dest",
|
||||
"Processes.user",
|
||||
"Processes.parent_process_name",
|
||||
"Processes.parent_process",
|
||||
"Processes.original_file_name",
|
||||
"Processes.process_name",
|
||||
"Processes.process",
|
||||
"Processes.process_id",
|
||||
"Processes.parent_process_path",
|
||||
"Processes.process_path",
|
||||
"Processes.parent_process_id"
|
||||
],
|
||||
"risk_score": 90,
|
||||
"security_domain": "endpoint",
|
||||
"risk_severity": "high",
|
||||
"supported_tas": [
|
||||
"Splunk_TA_microsoft_sysmon"
|
||||
],
|
||||
"mitre_attack_enrichments": [
|
||||
{
|
||||
"mitre_attack_id": "T1003.002",
|
||||
"mitre_attack_technique": "Security Account Manager",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"Dragonfly 2.0",
|
||||
"GALLIUM",
|
||||
"Ke3chang",
|
||||
"Night Dragon",
|
||||
"Threat Group-3390",
|
||||
"Wizard Spider",
|
||||
"menuPass"
|
||||
]
|
||||
},
|
||||
{
|
||||
"mitre_attack_id": "T1003",
|
||||
"mitre_attack_technique": "OS Credential Dumping",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"APT28",
|
||||
"APT32",
|
||||
"APT39",
|
||||
"Axiom",
|
||||
"Frankenstein",
|
||||
"Leviathan",
|
||||
"Poseidon Group",
|
||||
"Sowbug",
|
||||
"Suckfly",
|
||||
"Tonto Team"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"deprecated": false,
|
||||
"experimental": false,
|
||||
"deployment": {
|
||||
"name": "ESCU Default Configuration TTP",
|
||||
"id": "b81cd059-a3e8-4c03-96ca-e168c50ff70b",
|
||||
"date": "2021-12-21",
|
||||
"author": "Patrick Bareiss",
|
||||
"description": "This configuration file applies to all detections of type TTP. These detections will use Risk Based Alerting and generate Notable Events.",
|
||||
"scheduling": {
|
||||
"cron_schedule": "0 * * * *",
|
||||
"earliest_time": "-70m@m",
|
||||
"latest_time": "-10m@m",
|
||||
"schedule_window": "auto"
|
||||
},
|
||||
"notable": {
|
||||
"rule_description": "%description%",
|
||||
"rule_title": "%name%",
|
||||
"nes_fields": [
|
||||
"user",
|
||||
"dest"
|
||||
]
|
||||
},
|
||||
"rba": {
|
||||
"enabled": "true"
|
||||
},
|
||||
"tags": {
|
||||
"type": "TTP"
|
||||
}
|
||||
},
|
||||
"annotations": {
|
||||
"mitre_attack": [
|
||||
"T1003.002",
|
||||
"T1003"
|
||||
],
|
||||
"kill_chain_phases": [
|
||||
"Actions on Objectives"
|
||||
],
|
||||
"cis20": [
|
||||
"CIS 3",
|
||||
"CIS 5",
|
||||
"CIS 16"
|
||||
],
|
||||
"nist": [
|
||||
"DE.CM"
|
||||
],
|
||||
"analytic_story": [
|
||||
"Credential Dumping",
|
||||
"DarkSide Ransomware"
|
||||
],
|
||||
"observable": [
|
||||
{
|
||||
"name": "user",
|
||||
"type": "User",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "dest",
|
||||
"type": "Hostname",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "parent_process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Parent Process"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Child Process"
|
||||
]
|
||||
}
|
||||
],
|
||||
"context": [
|
||||
"Source:Endpoint",
|
||||
"Stage:Credential Access"
|
||||
],
|
||||
"impact": 90,
|
||||
"confidence": 100
|
||||
},
|
||||
"risk": [
|
||||
{
|
||||
"risk_object_type": "user",
|
||||
"risk_object_field": "user",
|
||||
"risk_score": 90
|
||||
},
|
||||
{
|
||||
"risk_object_type": "system",
|
||||
"risk_object_field": "dest",
|
||||
"risk_score": 90
|
||||
},
|
||||
{
|
||||
"threat_object_field": "parent_process_name",
|
||||
"threat_object_type": "process"
|
||||
},
|
||||
{
|
||||
"threat_object_field": "process_name",
|
||||
"threat_object_type": "process"
|
||||
}
|
||||
],
|
||||
"playbooks": [
|
||||
{
|
||||
"name": "Ransomware Investigate and Contain",
|
||||
"id": "fc0edc96-ff2b-48b0-9f6f-63da3783fd63",
|
||||
"version": 1,
|
||||
"date": "2018-02-04",
|
||||
"author": "Philip Royer, Splunk",
|
||||
"type": "Response",
|
||||
"description": "This playbook investigates and contains ransomware detected on endpoints.",
|
||||
"how_to_implement": "This playbook requires the Splunk SOAR apps for Palo Alto Networks Firewalls, Palo Alto Wildfire, LDAP, and Carbon Black Response.",
|
||||
"playbook": "ransomware_investigate_and_contain",
|
||||
"references": [],
|
||||
"app_list": [
|
||||
"Carbon Black Response",
|
||||
"LDAP",
|
||||
"Palo Alto Networks Firewall",
|
||||
"WildFire",
|
||||
"Cylance"
|
||||
],
|
||||
"tags": {
|
||||
"analytic_story": [
|
||||
"Ransomware"
|
||||
],
|
||||
"detections": [
|
||||
"Attempted Credential Dump From Registry via Reg exe"
|
||||
],
|
||||
"platform_tags": [
|
||||
"Ransomware",
|
||||
"Response"
|
||||
],
|
||||
"playbook_fields": [
|
||||
"ComputerName",
|
||||
"Username"
|
||||
],
|
||||
"product": [
|
||||
"Splunk SOAR"
|
||||
],
|
||||
"detection_objects": [
|
||||
{
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"lowercase_name": "attempted_credential_dump_from_registry_via_reg_exe",
|
||||
"path": "detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
],
|
||||
"baselines": [],
|
||||
"mappings": {
|
||||
"mitre_attack": [
|
||||
"T1003.002",
|
||||
"T1003"
|
||||
],
|
||||
"kill_chain_phases": [
|
||||
"Actions on Objectives"
|
||||
],
|
||||
"cis20": [
|
||||
"CIS 3",
|
||||
"CIS 5",
|
||||
"CIS 16"
|
||||
],
|
||||
"nist": [
|
||||
"DE.CM"
|
||||
]
|
||||
},
|
||||
"test": {
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe Unit Test",
|
||||
"tests": [
|
||||
{
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"file": "endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml",
|
||||
"pass_condition": "| stats count | where count > 0",
|
||||
"earliest_time": "-24h",
|
||||
"latest_time": "now",
|
||||
"attack_data": [
|
||||
{
|
||||
"file_name": "windows-sysmon.log",
|
||||
"data": "https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log",
|
||||
"source": "XmlWinEventLog:Microsoft-Windows-Sysmon/Operational",
|
||||
"sourcetype": "xmlwineventlog"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"macros": [
|
||||
{
|
||||
"name": "attempted_credential_dump_from_registry_via_reg_exe_filter",
|
||||
"definition": "search *",
|
||||
"description": "Update this macro to limit the output results to filter out false positives."
|
||||
}
|
||||
],
|
||||
"lookups": [],
|
||||
"cve_enrichment": [],
|
||||
"splunk_app_enrichment": [
|
||||
{
|
||||
"name": "Splunk Add-on for Sysmon",
|
||||
"url": "https://splunkbase.splunk.com/app/5709"
|
||||
}
|
||||
],
|
||||
"file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml",
|
||||
"source": "detection"
|
||||
}
|
||||
],
|
||||
"investigations": [
|
||||
{
|
||||
"name": "Get Parent Process Info",
|
||||
"id": "fecf2918-670d-4f1c-872b-3d7317a41bf9",
|
||||
"version": 2,
|
||||
"date": "2019-02-28",
|
||||
"author": "Bhavin Patel, Splunk",
|
||||
"type": "Investigation",
|
||||
"datamodel": [
|
||||
"Endpoint"
|
||||
],
|
||||
"description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest",
|
||||
"search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`",
|
||||
"how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.",
|
||||
"known_false_positives": "",
|
||||
"references": [],
|
||||
"inputs": [
|
||||
"parent_process_name",
|
||||
"dest"
|
||||
],
|
||||
"tags": {
|
||||
"analytic_story": [
|
||||
"Collection and Staging",
|
||||
"Command and Control",
|
||||
"DHS Report TA18-074A",
|
||||
"Disabling Security Tools",
|
||||
"Emotet Malware DHS Report TA18-201A ",
|
||||
"Hidden Cobra Malware",
|
||||
"Lateral Movement",
|
||||
"Malicious PowerShell",
|
||||
"Monitor for Unauthorized Software",
|
||||
"Netsh Abuse",
|
||||
"Orangeworm Attack Group",
|
||||
"Phishing Payloads",
|
||||
"Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns",
|
||||
"Prohibited Traffic Allowed or Protocol Mismatch",
|
||||
"Ransomware",
|
||||
"SamSam Ransomware",
|
||||
"Suspicious Command-Line Executions",
|
||||
"Suspicious DNS Traffic",
|
||||
"Suspicious MSHTA Activity",
|
||||
"Suspicious WMI Use",
|
||||
"Suspicious Windows Registry Activities",
|
||||
"Unusual Processes",
|
||||
"Windows Defense Evasion Tactics",
|
||||
"Windows File Extension and Association Abuse",
|
||||
"Windows Log Manipulation",
|
||||
"Windows Persistence Techniques",
|
||||
"Windows Privilege Escalation",
|
||||
"Windows Service Abuse",
|
||||
"DarkSide Ransomware"
|
||||
],
|
||||
"product": [
|
||||
"Splunk Phantom"
|
||||
],
|
||||
"required_fields": [
|
||||
"_time",
|
||||
"Processes.user",
|
||||
"Processes.parent_process_name",
|
||||
"Processes.process_name",
|
||||
"Processes.dest"
|
||||
],
|
||||
"security_domain": "endpoint"
|
||||
},
|
||||
"lowercase_name": "get_parent_process_info"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
{"stories": [{"name": "DarkSide Ransomware", "id": "507edc74-13d5-4339-878e-b9114ded1f35", "version": 1, "date": "2021-05-12", "author": "Bhavin Patel, Splunk", "description": "Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware", "narrative": "This story addresses Darkside ransomware. This ransomware payload has many similarities to common ransomware however there are certain items particular to it. The creation of a .TXT log that shows every item being encrypted as well as the creation of ransomware notes and files adding a machine ID created based on CRC32 checksum algorithm. This ransomware payload leaves machines in minimal operation level,enough to browse the attackers websites. A customized URI with leaked information is presented to each victim.This is the ransomware payload that shut down the Colonial pipeline. The story is composed of several detection searches covering similar items to other ransomware payloads and those particular to Darkside payload.", "references": ["https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/", "https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html"], "tags": {"name": "DarkSide Ransomware", "analytic_story": "DarkSide Ransomware", "category": ["Malware"], "product": ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "usecase": "Advanced Threat Detection", "mitre_attack_enrichments": [{"mitre_attack_id": "T1003.002", "mitre_attack_technique": "Security Account Manager", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["Dragonfly 2.0", "GALLIUM", "Ke3chang", "Night Dragon", "Threat Group-3390", "Wizard Spider", "menuPass"]}, {"mitre_attack_id": "T1003", "mitre_attack_technique": "OS Credential Dumping", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["APT28", "APT32", "APT39", "Axiom", "Frankenstein", "Leviathan", "Poseidon Group", "Sowbug", "Suckfly", "Tonto Team"]}], "mitre_attack_tactics": ["Credential Access"], "datamodels": ["Endpoint"], "kill_chain_phases": ["Actions on Objectives"]}, "detection_names": ["ESCU - Attempted Credential Dump From Registry via Reg exe - Rule"], "investigation_names": ["ESCU - Get Parent Process Info - Response Task"], "baseline_names": ["ESCU - Baseline Of Cloud Instances Launched"], "author_company": "Splunk", "author_name": "Bhavin Patel"}]}
|
||||
+1
-504
@@ -1,504 +1 @@
|
||||
{
|
||||
"stories": [
|
||||
{
|
||||
"name": "DarkSide Ransomware",
|
||||
"id": "507edc74-13d5-4339-878e-b9114ded1f35",
|
||||
"version": 1,
|
||||
"date": "2021-05-12",
|
||||
"author": "Bhavin Patel, Splunk",
|
||||
"description": "Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware",
|
||||
"narrative": "This story addresses Darkside ransomware. This ransomware payload has many similarities to common ransomware however there are certain items particular to it. The creation of a .TXT log that shows every item being encrypted as well as the creation of ransomware notes and files adding a machine ID created based on CRC32 checksum algorithm. This ransomware payload leaves machines in minimal operation level,enough to browse the attackers websites. A customized URI with leaked information is presented to each victim.This is the ransomware payload that shut down the Colonial pipeline. The story is composed of several detection searches covering similar items to other ransomware payloads and those particular to Darkside payload.",
|
||||
"references": [
|
||||
"https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/",
|
||||
"https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html"
|
||||
],
|
||||
"tags": {
|
||||
"name": "DarkSide Ransomware",
|
||||
"analytic_story": "DarkSide Ransomware",
|
||||
"category": [
|
||||
"Malware"
|
||||
],
|
||||
"product": [
|
||||
"Splunk Enterprise",
|
||||
"Splunk Enterprise Security",
|
||||
"Splunk Cloud"
|
||||
],
|
||||
"usecase": "Advanced Threat Detection",
|
||||
"mitre_attack_enrichments": [
|
||||
{
|
||||
"mitre_attack_id": "T1003.002",
|
||||
"mitre_attack_technique": "Security Account Manager",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"Dragonfly 2.0",
|
||||
"Ke3chang",
|
||||
"Night Dragon",
|
||||
"Soft Cell",
|
||||
"Threat Group-3390",
|
||||
"menuPass"
|
||||
]
|
||||
},
|
||||
{
|
||||
"mitre_attack_id": "T1003",
|
||||
"mitre_attack_technique": "OS Credential Dumping",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"APT28",
|
||||
"APT32",
|
||||
"APT39",
|
||||
"Axiom",
|
||||
"Frankenstein",
|
||||
"Leviathan",
|
||||
"Poseidon Group",
|
||||
"Sowbug",
|
||||
"Suckfly"
|
||||
]
|
||||
}
|
||||
],
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"datamodels": [
|
||||
"Endpoint"
|
||||
],
|
||||
"kill_chain_phases": [
|
||||
"Actions on Objectives"
|
||||
]
|
||||
},
|
||||
"detection_names": [
|
||||
"ESCU - Attempted Credential Dump From Registry via Reg exe - Rule"
|
||||
],
|
||||
"investigation_names": [
|
||||
"ESCU - Get Parent Process Info - Response Task"
|
||||
],
|
||||
"baseline_names": [
|
||||
"ESCU - Baseline Of Cloud Instances Launched"
|
||||
],
|
||||
"author_company": "Splunk",
|
||||
"author_name": "Bhavin Patel",
|
||||
"detections": [
|
||||
{
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911",
|
||||
"version": 6,
|
||||
"date": "2021-09-16",
|
||||
"author": "Patrick Bareiss, Splunk",
|
||||
"type": "TTP",
|
||||
"datamodel": [
|
||||
"Endpoint"
|
||||
],
|
||||
"description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.",
|
||||
"search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`",
|
||||
"how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.",
|
||||
"known_false_positives": "None identified.",
|
||||
"references": [
|
||||
"https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"
|
||||
],
|
||||
"tags": {
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"analytic_story": [
|
||||
"Credential Dumping",
|
||||
"DarkSide Ransomware"
|
||||
],
|
||||
"asset_type": "Endpoint",
|
||||
"automated_detection_testing": "passed",
|
||||
"cis20": [
|
||||
"CIS 3",
|
||||
"CIS 5",
|
||||
"CIS 16"
|
||||
],
|
||||
"confidence": 100,
|
||||
"context": [
|
||||
"Source:Endpoint",
|
||||
"Stage:Credential Access"
|
||||
],
|
||||
"dataset": [
|
||||
"https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"
|
||||
],
|
||||
"impact": 90,
|
||||
"kill_chain_phases": [
|
||||
"Actions on Objectives"
|
||||
],
|
||||
"message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.",
|
||||
"mitre_attack_id": [
|
||||
"T1003.002",
|
||||
"T1003"
|
||||
],
|
||||
"nist": [
|
||||
"DE.CM"
|
||||
],
|
||||
"observable": [
|
||||
{
|
||||
"name": "user",
|
||||
"type": "User",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "dest",
|
||||
"type": "Hostname",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "parent_process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Parent Process"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Child Process"
|
||||
]
|
||||
}
|
||||
],
|
||||
"product": [
|
||||
"Splunk Enterprise",
|
||||
"Splunk Enterprise Security",
|
||||
"Splunk Cloud"
|
||||
],
|
||||
"required_fields": [
|
||||
"_time",
|
||||
"Processes.dest",
|
||||
"Processes.user",
|
||||
"Processes.parent_process_name",
|
||||
"Processes.parent_process",
|
||||
"Processes.original_file_name",
|
||||
"Processes.process_name",
|
||||
"Processes.process",
|
||||
"Processes.process_id",
|
||||
"Processes.parent_process_path",
|
||||
"Processes.process_path",
|
||||
"Processes.parent_process_id"
|
||||
],
|
||||
"risk_score": 90,
|
||||
"security_domain": "endpoint",
|
||||
"risk_severity": "high",
|
||||
"supported_tas": [
|
||||
"Splunk_TA_microsoft_sysmon"
|
||||
],
|
||||
"mitre_attack_enrichments": [
|
||||
{
|
||||
"mitre_attack_id": "T1003.002",
|
||||
"mitre_attack_technique": "Security Account Manager",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"Dragonfly 2.0",
|
||||
"Ke3chang",
|
||||
"Night Dragon",
|
||||
"Soft Cell",
|
||||
"Threat Group-3390",
|
||||
"menuPass"
|
||||
]
|
||||
},
|
||||
{
|
||||
"mitre_attack_id": "T1003",
|
||||
"mitre_attack_technique": "OS Credential Dumping",
|
||||
"mitre_attack_tactics": [
|
||||
"Credential Access"
|
||||
],
|
||||
"mitre_attack_groups": [
|
||||
"APT28",
|
||||
"APT32",
|
||||
"APT39",
|
||||
"Axiom",
|
||||
"Frankenstein",
|
||||
"Leviathan",
|
||||
"Poseidon Group",
|
||||
"Sowbug",
|
||||
"Suckfly"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"deprecated": false,
|
||||
"experimental": false,
|
||||
"deployment": {
|
||||
"name": "ESCU Default Configuration TTP",
|
||||
"id": "b81cd059-a3e8-4c03-96ca-e168c50ff70b",
|
||||
"date": "2021-12-21",
|
||||
"author": "Patrick Bareiss",
|
||||
"description": "This configuration file applies to all detections of type TTP. These detections will use Risk Based Alerting and generate Notable Events.",
|
||||
"scheduling": {
|
||||
"cron_schedule": "0 * * * *",
|
||||
"earliest_time": "-70m@m",
|
||||
"latest_time": "-10m@m",
|
||||
"schedule_window": "auto"
|
||||
},
|
||||
"notable": {
|
||||
"rule_description": "%description%",
|
||||
"rule_title": "%name%",
|
||||
"nes_fields": [
|
||||
"user",
|
||||
"dest"
|
||||
]
|
||||
},
|
||||
"rba": {
|
||||
"enabled": "true"
|
||||
},
|
||||
"tags": {
|
||||
"type": "TTP"
|
||||
}
|
||||
},
|
||||
"annotations": {
|
||||
"mitre_attack": [
|
||||
"T1003.002",
|
||||
"T1003"
|
||||
],
|
||||
"kill_chain_phases": [
|
||||
"Actions on Objectives"
|
||||
],
|
||||
"cis20": [
|
||||
"CIS 3",
|
||||
"CIS 5",
|
||||
"CIS 16"
|
||||
],
|
||||
"nist": [
|
||||
"DE.CM"
|
||||
],
|
||||
"analytic_story": [
|
||||
"Credential Dumping",
|
||||
"DarkSide Ransomware"
|
||||
],
|
||||
"observable": [
|
||||
{
|
||||
"name": "user",
|
||||
"type": "User",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "dest",
|
||||
"type": "Hostname",
|
||||
"role": [
|
||||
"Victim"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "parent_process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Parent Process"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "process_name",
|
||||
"type": "Process",
|
||||
"role": [
|
||||
"Child Process"
|
||||
]
|
||||
}
|
||||
],
|
||||
"context": [
|
||||
"Source:Endpoint",
|
||||
"Stage:Credential Access"
|
||||
],
|
||||
"impact": 90,
|
||||
"confidence": 100
|
||||
},
|
||||
"risk": [
|
||||
{
|
||||
"risk_object_type": "user",
|
||||
"risk_object_field": "user",
|
||||
"risk_score": 90
|
||||
},
|
||||
{
|
||||
"risk_object_type": "system",
|
||||
"risk_object_field": "dest",
|
||||
"risk_score": 90
|
||||
},
|
||||
{
|
||||
"threat_object_field": "parent_process_name",
|
||||
"threat_object_type": "process"
|
||||
},
|
||||
{
|
||||
"threat_object_field": "process_name",
|
||||
"threat_object_type": "process"
|
||||
}
|
||||
],
|
||||
"playbooks": [
|
||||
{
|
||||
"name": "Ransomware Investigate and Contain",
|
||||
"id": "fc0edc96-ff2b-48b0-9f6f-63da3783fd63",
|
||||
"version": 1,
|
||||
"date": "2018-02-04",
|
||||
"author": "Philip Royer, Splunk",
|
||||
"type": "Response",
|
||||
"description": "This playbook investigates and contains ransomware detected on endpoints.",
|
||||
"how_to_implement": "This playbook requires the Splunk SOAR apps for Palo Alto Networks Firewalls, Palo Alto Wildfire, LDAP, and Carbon Black Response.",
|
||||
"playbook": "ransomware_investigate_and_contain",
|
||||
"references": [],
|
||||
"app_list": [
|
||||
"Carbon Black Response",
|
||||
"LDAP",
|
||||
"Palo Alto Networks Firewall",
|
||||
"WildFire",
|
||||
"Cylance"
|
||||
],
|
||||
"tags": {
|
||||
"analytic_story": [
|
||||
"Ransomware"
|
||||
],
|
||||
"detections": [
|
||||
"Attempted Credential Dump From Registry via Reg exe"
|
||||
],
|
||||
"platform_tags": [
|
||||
"Ransomware",
|
||||
"Response"
|
||||
],
|
||||
"playbook_fields": [
|
||||
"ComputerName",
|
||||
"Username"
|
||||
],
|
||||
"product": [
|
||||
"Splunk SOAR"
|
||||
],
|
||||
"detection_objects": [
|
||||
{
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"lowercase_name": "attempted_credential_dump_from_registry_via_reg_exe",
|
||||
"path": "detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
],
|
||||
"baselines": [],
|
||||
"mappings": {
|
||||
"mitre_attack": [
|
||||
"T1003.002",
|
||||
"T1003"
|
||||
],
|
||||
"kill_chain_phases": [
|
||||
"Actions on Objectives"
|
||||
],
|
||||
"cis20": [
|
||||
"CIS 3",
|
||||
"CIS 5",
|
||||
"CIS 16"
|
||||
],
|
||||
"nist": [
|
||||
"DE.CM"
|
||||
]
|
||||
},
|
||||
"test": {
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe Unit Test",
|
||||
"tests": [
|
||||
{
|
||||
"name": "Attempted Credential Dump From Registry via Reg exe",
|
||||
"file": "endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml",
|
||||
"pass_condition": "| stats count | where count > 0",
|
||||
"earliest_time": "-24h",
|
||||
"latest_time": "now",
|
||||
"attack_data": [
|
||||
{
|
||||
"file_name": "windows-sysmon.log",
|
||||
"data": "https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log",
|
||||
"source": "XmlWinEventLog:Microsoft-Windows-Sysmon/Operational",
|
||||
"sourcetype": "xmlwineventlog"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"macros": [
|
||||
{
|
||||
"name": "attempted_credential_dump_from_registry_via_reg_exe_filter",
|
||||
"definition": "search *",
|
||||
"description": "Update this macro to limit the output results to filter out false positives."
|
||||
}
|
||||
],
|
||||
"lookups": [],
|
||||
"cve_enrichment": [],
|
||||
"splunk_app_enrichment": [
|
||||
{
|
||||
"name": "Splunk Add-on for Sysmon",
|
||||
"url": "https://splunkbase.splunk.com/app/5709"
|
||||
}
|
||||
],
|
||||
"file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml",
|
||||
"source": "detection"
|
||||
}
|
||||
],
|
||||
"investigations": [
|
||||
{
|
||||
"name": "Get Parent Process Info",
|
||||
"id": "fecf2918-670d-4f1c-872b-3d7317a41bf9",
|
||||
"version": 2,
|
||||
"date": "2019-02-28",
|
||||
"author": "Bhavin Patel, Splunk",
|
||||
"type": "Investigation",
|
||||
"datamodel": [
|
||||
"Endpoint"
|
||||
],
|
||||
"description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest",
|
||||
"search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`",
|
||||
"how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.",
|
||||
"known_false_positives": "",
|
||||
"references": [],
|
||||
"inputs": [
|
||||
"parent_process_name",
|
||||
"dest"
|
||||
],
|
||||
"tags": {
|
||||
"analytic_story": [
|
||||
"Collection and Staging",
|
||||
"Command and Control",
|
||||
"DHS Report TA18-074A",
|
||||
"Disabling Security Tools",
|
||||
"Emotet Malware DHS Report TA18-201A ",
|
||||
"Hidden Cobra Malware",
|
||||
"Lateral Movement",
|
||||
"Malicious PowerShell",
|
||||
"Monitor for Unauthorized Software",
|
||||
"Netsh Abuse",
|
||||
"Orangeworm Attack Group",
|
||||
"Phishing Payloads",
|
||||
"Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns",
|
||||
"Prohibited Traffic Allowed or Protocol Mismatch",
|
||||
"Ransomware",
|
||||
"SamSam Ransomware",
|
||||
"Suspicious Command-Line Executions",
|
||||
"Suspicious DNS Traffic",
|
||||
"Suspicious MSHTA Activity",
|
||||
"Suspicious WMI Use",
|
||||
"Suspicious Windows Registry Activities",
|
||||
"Unusual Processes",
|
||||
"Windows Defense Evasion Tactics",
|
||||
"Windows File Extension and Association Abuse",
|
||||
"Windows Log Manipulation",
|
||||
"Windows Persistence Techniques",
|
||||
"Windows Privilege Escalation",
|
||||
"Windows Service Abuse",
|
||||
"DarkSide Ransomware"
|
||||
],
|
||||
"product": [
|
||||
"Splunk Phantom"
|
||||
],
|
||||
"required_fields": [
|
||||
"_time",
|
||||
"Processes.user",
|
||||
"Processes.parent_process_name",
|
||||
"Processes.process_name",
|
||||
"Processes.dest"
|
||||
],
|
||||
"security_domain": "endpoint"
|
||||
},
|
||||
"lowercase_name": "get_parent_process_info"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
{"stories": [{"name": "DarkSide Ransomware", "id": "507edc74-13d5-4339-878e-b9114ded1f35", "version": 1, "date": "2021-05-12", "author": "Bhavin Patel, Splunk", "description": "Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware", "narrative": "This story addresses Darkside ransomware. This ransomware payload has many similarities to common ransomware however there are certain items particular to it. The creation of a .TXT log that shows every item being encrypted as well as the creation of ransomware notes and files adding a machine ID created based on CRC32 checksum algorithm. This ransomware payload leaves machines in minimal operation level,enough to browse the attackers websites. A customized URI with leaked information is presented to each victim.This is the ransomware payload that shut down the Colonial pipeline. The story is composed of several detection searches covering similar items to other ransomware payloads and those particular to Darkside payload.", "references": ["https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/", "https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html"], "tags": {"name": "DarkSide Ransomware", "analytic_story": "DarkSide Ransomware", "category": ["Malware"], "product": ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "usecase": "Advanced Threat Detection", "mitre_attack_enrichments": [{"mitre_attack_id": "T1003.002", "mitre_attack_technique": "Security Account Manager", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["Dragonfly 2.0", "GALLIUM", "Ke3chang", "Night Dragon", "Threat Group-3390", "Wizard Spider", "menuPass"]}, {"mitre_attack_id": "T1003", "mitre_attack_technique": "OS Credential Dumping", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["APT28", "APT32", "APT39", "Axiom", "Frankenstein", "Leviathan", "Poseidon Group", "Sowbug", "Suckfly", "Tonto Team"]}], "mitre_attack_tactics": ["Credential Access"], "datamodels": ["Endpoint"], "kill_chain_phases": ["Actions on Objectives"]}, "detection_names": ["ESCU - Attempted Credential Dump From Registry via Reg exe - Rule"], "investigation_names": ["ESCU - Get Parent Process Info - Response Task"], "baseline_names": ["ESCU - Baseline Of Cloud Instances Launched"], "author_company": "Splunk", "author_name": "Bhavin Patel"}]}
|
||||
Vendored
+1
-2405
File diff suppressed because one or more lines are too long
Vendored
+1
-103
@@ -1,103 +1 @@
|
||||
{
|
||||
"deployments": [
|
||||
{
|
||||
"name": "ESCU Default Configuration Anomaly",
|
||||
"id": "a9e210c6-9f50-4f8b-b60e-71bb26e4f216",
|
||||
"date": "2021-12-21",
|
||||
"author": "Patrick Bareiss",
|
||||
"description": "This configuration file applies to all detections of type anomaly. These detections will use Risk Based Alerting.",
|
||||
"scheduling": {
|
||||
"cron_schedule": "0 * * * *",
|
||||
"earliest_time": "-70m@m",
|
||||
"latest_time": "-10m@m",
|
||||
"schedule_window": "auto"
|
||||
},
|
||||
"rba": {
|
||||
"enabled": "true"
|
||||
},
|
||||
"tags": {
|
||||
"type": "Anomaly",
|
||||
"product": "ESCU"
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "ESCU Default Configuration Baseline",
|
||||
"id": "0f7ee854-1aad-4bef-89c5-5c402b488510",
|
||||
"date": "2021-12-21",
|
||||
"author": "Patrick Bareiss",
|
||||
"description": "This configuration file applies to all detections of type baseline.",
|
||||
"scheduling": {
|
||||
"cron_schedule": "0 * * * *",
|
||||
"earliest_time": "-70m@m",
|
||||
"latest_time": "-10m@m",
|
||||
"schedule_window": "auto"
|
||||
},
|
||||
"tags": {
|
||||
"type": "Baseline"
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "ESCU Default Configuration Correlation",
|
||||
"id": "36ba498c-46e8-4b62-8bde-67e984a40fb4",
|
||||
"date": "2021-12-21",
|
||||
"author": "Patrick Bareiss",
|
||||
"description": "This configuration file applies to all detections of type Correlation. These correlations will generate Notable Events.",
|
||||
"scheduling": {
|
||||
"cron_schedule": "0 * * * *",
|
||||
"earliest_time": "-70m@m",
|
||||
"latest_time": "-10m@m",
|
||||
"schedule_window": "auto"
|
||||
},
|
||||
"notable": {
|
||||
"rule_description": "%description%",
|
||||
"rule_title": "%name%",
|
||||
"nes_fields": []
|
||||
},
|
||||
"tags": {
|
||||
"type": "Correlation",
|
||||
"product": "ESCU"
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "ESCU Default Configuration Hunting",
|
||||
"id": "cc5895e8-3420-4ab7-af38-cf87a28f9c3b",
|
||||
"date": "2021-12-21",
|
||||
"author": "Patrick Bareiss",
|
||||
"description": "This configuration file applies to all detections of type hunting.",
|
||||
"scheduling": {
|
||||
"cron_schedule": "0 * * * *",
|
||||
"earliest_time": "-70m@m",
|
||||
"latest_time": "-10m@m",
|
||||
"schedule_window": "auto"
|
||||
},
|
||||
"tags": {
|
||||
"type": "Hunting",
|
||||
"product": "ESCU"
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "ESCU Default Configuration TTP",
|
||||
"id": "b81cd059-a3e8-4c03-96ca-e168c50ff70b",
|
||||
"date": "2021-12-21",
|
||||
"author": "Patrick Bareiss",
|
||||
"description": "This configuration file applies to all detections of type TTP. These detections will use Risk Based Alerting and generate Notable Events.",
|
||||
"scheduling": {
|
||||
"cron_schedule": "0 * * * *",
|
||||
"earliest_time": "-70m@m",
|
||||
"latest_time": "-10m@m",
|
||||
"schedule_window": "auto"
|
||||
},
|
||||
"notable": {
|
||||
"rule_description": "%description%",
|
||||
"rule_title": "%name%",
|
||||
"nes_fields": []
|
||||
},
|
||||
"rba": {
|
||||
"enabled": "true"
|
||||
},
|
||||
"tags": {
|
||||
"type": "TTP"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
{"deployments": [{"name": "ESCU Default Configuration Anomaly", "id": "a9e210c6-9f50-4f8b-b60e-71bb26e4f216", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type anomaly. These detections will use Risk Based Alerting.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "rba": {"enabled": "true"}, "tags": {"type": "Anomaly", "product": "ESCU"}}, {"name": "ESCU Default Configuration Baseline", "id": "0f7ee854-1aad-4bef-89c5-5c402b488510", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type baseline.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "tags": {"type": "Baseline"}}, {"name": "ESCU Default Configuration Correlation", "id": "36ba498c-46e8-4b62-8bde-67e984a40fb4", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type Correlation. These correlations will generate Notable Events.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "notable": {"rule_description": "%description%", "rule_title": "%name%", "nes_fields": []}, "tags": {"type": "Correlation", "product": "ESCU"}}, {"name": "ESCU Default Configuration Hunting", "id": "cc5895e8-3420-4ab7-af38-cf87a28f9c3b", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type hunting.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "tags": {"type": "Hunting", "product": "ESCU"}}, {"name": "ESCU Default Configuration TTP", "id": "b81cd059-a3e8-4c03-96ca-e168c50ff70b", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type TTP. These detections will use Risk Based Alerting and generate Notable Events.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "notable": {"rule_description": "%description%", "rule_title": "%name%", "nes_fields": []}, "rba": {"enabled": "true"}, "tags": {"type": "TTP"}}]}
|
||||
Vendored
+1
-114442
File diff suppressed because one or more lines are too long
Vendored
+1
-353
File diff suppressed because one or more lines are too long
Vendored
+1
-692
File diff suppressed because one or more lines are too long
Vendored
+1
-1944
File diff suppressed because one or more lines are too long
Vendored
+1
-26514
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user