mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge branch 'develop' into nterl0k-t1567-o365-sus-file-exfil
This commit is contained in:
+2
-2
@@ -155,9 +155,9 @@ apps:
|
||||
- uid: 3110
|
||||
title: Splunk Add-on for Microsoft Cloud Services
|
||||
appid: SPLUNK_TA_MICROSOFT_CLOUD_SERVICES
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
description: description of app
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-cloud-services_541.tgz
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-cloud-services_542.tgz
|
||||
- uid: 4055
|
||||
title: Splunk Add-on for Microsoft Office 365
|
||||
appid: SPLUNK_ADD_ON_FOR_MICROSOFT_OFFICE_365
|
||||
|
||||
@@ -10,4 +10,4 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
|
||||
+1
-1
@@ -11,7 +11,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -11,7 +11,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -11,7 +11,7 @@ separator: operationName.localizedValue
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- authorization.action
|
||||
|
||||
@@ -11,7 +11,7 @@ separator: operationName.localizedValue
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- authorization.action
|
||||
|
||||
@@ -11,7 +11,7 @@ separator: operationName.localizedValue
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- _time
|
||||
- authorization.action
|
||||
|
||||
@@ -3,14 +3,17 @@ id: 1997a515-a61a-4f78-ada9-54af34c764f2
|
||||
version: 1
|
||||
date: '2025-01-13'
|
||||
author: Bhavin Patel, Splunk
|
||||
description: Data source object for Azure Monitor Activity. The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub. To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic settings & send events to the activity audit event hub.
|
||||
description: Data source object for Azure Monitor Activity. The Splunk Add-on for
|
||||
Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure
|
||||
EventHub. To configure this logging, visit Intune > Tenant administration > Diagnostic
|
||||
settings > Add diagnostic settings & send events to the activity audit event hub.
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:activity
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.1
|
||||
version: 5.4.2
|
||||
fields:
|
||||
- column
|
||||
- action
|
||||
@@ -93,4 +96,16 @@ fields:
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
- _time
|
||||
example_log: '{"time": "2024-04-29T13:30:28.8622000Z", "tenantId": "26db52ee-c1b5-4c96-a0d4-129e25dc0388", "category": "AuditLogs", "operationName": "createDeviceHealthScript DeviceHealthScript", "properties": {"ActivityDate": "4/29/2024 1:30:28 PM", "ActivityResultStatus": 1, "ActivityType": 0, "Actor": {"ActorType": 1, "Application": "5926fc8e-304e-4f59-8bed-58ca97cc39a4", "ApplicationName": "Microsoft Intune portal extension", "IsDelegatedAdmin": false, "Name": null, "ObjectId": "cf2ef473-7d3b-4f14-961c-2e470e9a70f2", "PartnerTenantId": "00000000-0000-0000-0000-000000000000", "UserPermissions": ["*"], "UPN": "brian.cove@frothlydev.onmicrosoft.com"}, "AdditionalDetails": "", "AuditEventId": "3e7e790e-f15a-4c2c-a91a-516483bb4e37", "Category": 3, "RelationId": null, "TargetDisplayNames": ["<null>"], "TargetObjectIds": ["b16fcad4-b9f5-46fe-9bf0-841cd9be7bc9"], "Targets": [{"ModifiedProperties": [{"Name": "DeviceManagementAPIVersion", "Old": null, "New": "5024-02-13"}], "Name": null}]}, "resultType": "Success", "resultDescription": "None", "correlationId": "949ac544-b4e5-4576-a117-915c47c0ee00", "identity": "brian.cove@frothlydev.onmicrosoft.com"}'
|
||||
example_log: '{"time": "2024-04-29T13:30:28.8622000Z", "tenantId": "26db52ee-c1b5-4c96-a0d4-129e25dc0388",
|
||||
"category": "AuditLogs", "operationName": "createDeviceHealthScript DeviceHealthScript",
|
||||
"properties": {"ActivityDate": "4/29/2024 1:30:28 PM", "ActivityResultStatus": 1,
|
||||
"ActivityType": 0, "Actor": {"ActorType": 1, "Application": "5926fc8e-304e-4f59-8bed-58ca97cc39a4",
|
||||
"ApplicationName": "Microsoft Intune portal extension", "IsDelegatedAdmin": false,
|
||||
"Name": null, "ObjectId": "cf2ef473-7d3b-4f14-961c-2e470e9a70f2", "PartnerTenantId":
|
||||
"00000000-0000-0000-0000-000000000000", "UserPermissions": ["*"], "UPN": "brian.cove@frothlydev.onmicrosoft.com"},
|
||||
"AdditionalDetails": "", "AuditEventId": "3e7e790e-f15a-4c2c-a91a-516483bb4e37",
|
||||
"Category": 3, "RelationId": null, "TargetDisplayNames": ["<null>"], "TargetObjectIds":
|
||||
["b16fcad4-b9f5-46fe-9bf0-841cd9be7bc9"], "Targets": [{"ModifiedProperties": [{"Name":
|
||||
"DeviceManagementAPIVersion", "Old": null, "New": "5024-02-13"}], "Name": null}]},
|
||||
"resultType": "Success", "resultDescription": "None", "correlationId": "949ac544-b4e5-4576-a117-915c47c0ee00",
|
||||
"identity": "brian.cove@frothlydev.onmicrosoft.com"}'
|
||||
|
||||
@@ -22,7 +22,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime
|
||||
"*\\windows\\temp\\*", "*\\users\\public\\*", "*\\windows\\debug\\*", "*\\Users\\Administrator\\Music\\*",
|
||||
"*\\Windows\\servicing\\*", "*\\Users\\Default\\*", "*Recycle.bin*", "*\\Windows\\Media\\*", "\\Windows\\repair\\*",
|
||||
"*\\temp\\*" , "*\\PerfLogs\\*","*\\windows\\tasks\\*", "*:\\programdata\\*") by
|
||||
Processes.parent_process_name Processes.parent_process Processes.process_path Processes.dest
|
||||
Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process_path Processes.dest
|
||||
Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `suspicious_process_file_path_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
|
||||
@@ -65,8 +65,3 @@ tests:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: XmlWinEventLog
|
||||
- name: True Positive Test - CrowdStrike
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/crowdstrike_falcon.log
|
||||
source: crowdstrike
|
||||
sourcetype: crowdstrike:events:sensor
|
||||
|
||||
|
Before Width: | Height: | Size: 149 KiB After Width: | Height: | Size: 149 KiB |
File diff suppressed because it is too large
Load Diff
@@ -5,7 +5,7 @@ date: '2025-01-17'
|
||||
author: Kelby Shelton, Tapish Jain, Splunk
|
||||
type: Investigation
|
||||
description: "Accepts a URL, IP or Domain and provides intelligence on the objects. Generates a per observable report that includes the objects threat level, threat categories, acceptable use categories and score."
|
||||
playbook: Cisco_Talos_Intelligence_Identifier_Reputation_Analysis
|
||||
playbook: CiscoTalosIntelligence_Identifier_Reputation_Analysis
|
||||
how_to_implement: This input playbook requires the Cisco Talos Intelligence connector to be configured and a Splunk SOAR cloud license.
|
||||
references:
|
||||
- https://d3fend.mitre.org/technique/d3f:IdentifierReputationAnalysis/
|
||||
|
||||
Reference in New Issue
Block a user