From 11bbb7f943d25803697ddbc13c4f532f8f6d5141 Mon Sep 17 00:00:00 2001 From: Lou Stella Date: Thu, 28 Oct 2021 17:12:47 -0500 Subject: [PATCH] added nist & cis20 --- detections/endpoint/ssa___attempt_to_delete_services.yml | 9 ++++++++- .../endpoint/ssa___attempt_to_disable_services.yml | 9 ++++++++- detections/endpoint/ssa___delete_a_net_user.yml | 9 ++++++++- .../ssa___deny_permission_using_cacls_utility.yml | 9 ++++++++- detections/endpoint/ssa___disable_net_user_account.yml | 9 ++++++++- .../ssa___grant_permission_using_cacls_utility.yml | 9 ++++++++- .../endpoint/ssa___resize_shadowstorage_volume.yml | 9 ++++++++- .../endpoint/ssa___wevtutil_usage_to_clear_logs.yml | 9 ++++++++- .../endpoint/ssa___wevtutil_usage_to_disable_logs.yml | 9 ++++++++- 9 files changed, 72 insertions(+), 9 deletions(-) diff --git a/detections/endpoint/ssa___attempt_to_delete_services.yml b/detections/endpoint/ssa___attempt_to_delete_services.yml index f77c97d2a1..d92d74e7f9 100644 --- a/detections/endpoint/ssa___attempt_to_delete_services.yml +++ b/detections/endpoint/ssa___attempt_to_delete_services.yml @@ -1,6 +1,6 @@ name: Attempt To delete Services id: a0c8c292-d01a-11eb-aa18-acde48001122 -version: 1 +version: 2 date: '2021-06-18' author: Teoderick Contreras, splunk type: TTP @@ -39,6 +39,13 @@ tags: - Exploitation mitre_attack_id: - T1489 + cis20: + - CIS 8 + - CIS 13 + nist: + - PR.DS + - PR.IP + risk_severity: high product: - Splunk Behavioral Analytics required_fields: diff --git a/detections/endpoint/ssa___attempt_to_disable_services.yml b/detections/endpoint/ssa___attempt_to_disable_services.yml index 3e13147b33..4794e86a6f 100644 --- a/detections/endpoint/ssa___attempt_to_disable_services.yml +++ b/detections/endpoint/ssa___attempt_to_disable_services.yml @@ -1,6 +1,6 @@ name: Attempt To Disable Services id: afb31de4-d023-11eb-98d5-acde48001122 -version: 1 +version: 2 date: '2021-06-18' author: Teoderick Contreras, Splunk type: TTP @@ -41,6 +41,13 @@ tags: - Exploitation mitre_attack_id: - T1489 + cis20: + - CIS 9 + - CIS 8 + nist: + - PR.DS + - PR.IP + risk_severity: medium product: - Splunk Behavioral Analytics required_fields: diff --git a/detections/endpoint/ssa___delete_a_net_user.yml b/detections/endpoint/ssa___delete_a_net_user.yml index a8045c182e..25eb1df355 100644 --- a/detections/endpoint/ssa___delete_a_net_user.yml +++ b/detections/endpoint/ssa___delete_a_net_user.yml @@ -1,6 +1,6 @@ name: Delete A Net User id: 8776d79c-d26e-11eb-9a56-acde48001122 -version: 1 +version: 2 date: '2021-06-21' author: Teoderick Contreras, Splunk type: Anomaly @@ -42,6 +42,13 @@ tags: - Exploitation mitre_attack_id: - T1489 + cis20: + - CIS 4 + - CIS 16 + nist: + - PR.AC + - PR.IP + risk_severity: high product: - Splunk Behavioral Analytics required_fields: diff --git a/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml b/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml index 121eba4fee..57632a497f 100644 --- a/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml +++ b/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml @@ -1,6 +1,6 @@ name: Deny Permission using Cacls Utility id: b76eae28-cd25-11eb-9c92-acde48001122 -version: 1 +version: 2 date: '2021-06-14' author: Teoderick Contreras, Splunk type: TTP @@ -46,6 +46,13 @@ tags: a permission of a file or directory in host $dest_device_id$ mitre_attack_id: - T1222 + cis20: + - CIS 14 + - CIS 16 + nist: + - PR.AC + - PR.IP + risk_severity: medium observable: - name: dest_device_id type: Hostname diff --git a/detections/endpoint/ssa___disable_net_user_account.yml b/detections/endpoint/ssa___disable_net_user_account.yml index a51a08f051..0dbcd13932 100644 --- a/detections/endpoint/ssa___disable_net_user_account.yml +++ b/detections/endpoint/ssa___disable_net_user_account.yml @@ -1,6 +1,6 @@ name: Disable Net User Account id: ba858b08-d26c-11eb-af9b-acde48001122 -version: 1 +version: 2 date: '2021-06-21' author: Teoderick Contreras, Splunk type: TTP @@ -41,6 +41,13 @@ tags: - Exploitation mitre_attack_id: - T1489 + cis20: + - CIS 4 + - CIS 16 + nist: + - PR.AC + - PR.IP + risk_severity: medium product: - Splunk Behavioral Analytics required_fields: diff --git a/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml b/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml index a4577693be..2e96b79f99 100644 --- a/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml +++ b/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml @@ -1,6 +1,6 @@ name: Grant Permission Using Cacls Utility id: c6da561a-cd29-11eb-ae65-acde48001122 -version: 1 +version: 2 date: '2021-06-14' author: Teoderick Contreras, Splunk type: TTP @@ -55,6 +55,13 @@ tags: type: user role: - Victim + cis20: + - CIS 14 + - CIS 16 + nist: + - PR.AC + - PR.IP + risk_severity: medium product: - Splunk Behavioral Analytics required_fields: diff --git a/detections/endpoint/ssa___resize_shadowstorage_volume.yml b/detections/endpoint/ssa___resize_shadowstorage_volume.yml index 1cb7e4687a..d9f6739c9e 100644 --- a/detections/endpoint/ssa___resize_shadowstorage_volume.yml +++ b/detections/endpoint/ssa___resize_shadowstorage_volume.yml @@ -1,6 +1,6 @@ name: Resize Shadowstorage Volume id: dbc30554-d27e-11eb-9e5e-acde48001122 -version: 1 +version: 2 date: '2021-06-21' author: Teoderick Contreras, Splunk type: TTP @@ -43,6 +43,13 @@ tags: - Exploitation mitre_attack_id: - T1489 + cis20: + - CIS 10 + - CIS 13 + nist: + - PR.DS + - PR.IP + risk_severity: high product: - Splunk Behavioral Analytics required_fields: diff --git a/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml b/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml index 73a7fbd8bf..dc817e0263 100644 --- a/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml +++ b/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml @@ -1,6 +1,6 @@ name: WevtUtil Usage To Clear Logs id: 5438113c-cdd9-11eb-93b8-acde48001122 -version: 1 +version: 2 date: '2021-06-15' author: Teoderick Contreras, Splunk type: TTP @@ -51,6 +51,13 @@ tags: mitre_attack_id: - T1070 - T1070.001 + cis20: + - CIS 8 + - CIS 13 + nist: + - PR.DS + - PR.IP + risk_severity: medium observable: - name: dest_device_id type: Hostname diff --git a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml index 69d1c02046..acfa77163f 100644 --- a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml +++ b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml @@ -1,6 +1,6 @@ name: Wevtutil Usage To Disable Logs id: a4bdc944-cdd9-11eb-ac97-acde48001122 -version: 1 +version: 2 date: '2021-06-15' author: Teoderick Contreras, Splunk type: TTP @@ -47,6 +47,13 @@ tags: mitre_attack_id: - T1070 - T1070.001 + cis20: + - CIS 8 + - CIS 13 + nist: + - PR.DS + - PR.IP + risk_severity: high observable: - name: dest_device_id type: Hostname