diff --git a/detections/endpoint/7zip_commandline_to_smb_share_path.yml b/detections/endpoint/7zip_commandline_to_smb_share_path.yml index 7a6633a5b3..71a2f82616 100644 --- a/detections/endpoint/7zip_commandline_to_smb_share_path.yml +++ b/detections/endpoint/7zip_commandline_to_smb_share_path.yml @@ -44,6 +44,7 @@ tags: $dest$ mitre_attack_id: - T1560.001 + - T1560 observable: - name: dest type: Hostname diff --git a/detections/endpoint/access_lsass_memory_for_dump_creation.yml b/detections/endpoint/access_lsass_memory_for_dump_creation.yml index e696dc1e22..47edc20c3e 100644 --- a/detections/endpoint/access_lsass_memory_for_dump_creation.yml +++ b/detections/endpoint/access_lsass_memory_for_dump_creation.yml @@ -43,6 +43,7 @@ tags: Service (LSASS). mitre_attack_id: - T1003.001 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/account_discovery_with_net_app.yml b/detections/endpoint/account_discovery_with_net_app.yml index ca323b4f37..722368e8b8 100644 --- a/detections/endpoint/account_discovery_with_net_app.yml +++ b/detections/endpoint/account_discovery_with_net_app.yml @@ -47,6 +47,7 @@ tags: message: Suspicious $process_name$ usage detected on endpoint $dest$ by user $user$. mitre_attack_id: - T1087.002 + - T1087 observable: - name: user type: User diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index 11492c7e1a..e1c22878d1 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -19,9 +19,9 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTim Components*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `active_setup_registry_autostart_filter`' -how_to_implement: To successfully implement this search, you must be ingesting - data that records registry activity from your hosts to populate the endpoint data - model in the registry node. This is typically populated via endpoint detection-and-response +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. @@ -39,6 +39,7 @@ tags: - Exploitation mitre_attack_id: - T1547.014 + - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml index 9e3a41015f..45b22bb7bd 100644 --- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml +++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml @@ -42,6 +42,7 @@ tags: to prepare autoadminlogon mitre_attack_id: - T1552.002 + - T1552 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml index efc136fcfb..07fe3eaed1 100644 --- a/detections/endpoint/adsisearcher_account_discovery.yml +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -38,6 +38,7 @@ tags: message: powershell process having commandline $Message$ for user enumeration mitre_attack_id: - T1087.002 + - T1087 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index cb0d37c557..61844a9fb4 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -36,6 +36,7 @@ tags: - Exploitation mitre_attack_id: - T1562.007 + - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index 496c7b2b3a..c82db7194b 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -42,6 +42,7 @@ tags: $dest$ by user $user$. mitre_attack_id: - T1021.001 + - T1021 observable: - name: user type: User diff --git a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml index 10d09995c1..644a57103f 100644 --- a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml +++ b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml @@ -38,6 +38,7 @@ tags: user $user$. mitre_attack_id: - T1021.001 + - T1021 observable: - name: user type: User diff --git a/detections/endpoint/allow_network_discovery_in_firewall.yml b/detections/endpoint/allow_network_discovery_in_firewall.yml index aedebe1507..a704470b3f 100644 --- a/detections/endpoint/allow_network_discovery_in_firewall.yml +++ b/detections/endpoint/allow_network_discovery_in_firewall.yml @@ -38,6 +38,7 @@ tags: - Exploitation mitre_attack_id: - T1562.007 + - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index b1832ffe70..a9e51c4f46 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -47,6 +47,7 @@ tags: of 7zip. mitre_attack_id: - T1560.001 + - T1560 observable: - name: user type: User diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml index 70f5e17175..a87b6f4485 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/endpoint/any_powershell_downloadfile.yml @@ -48,6 +48,7 @@ tags: within PowerShell. mitre_attack_id: - T1059.001 + - T1059 observable: - name: user type: User diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml index 72a6433db8..3ec804e9f9 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/endpoint/any_powershell_downloadstring.yml @@ -45,6 +45,7 @@ tags: within PowerShell. mitre_attack_id: - T1059.001 + - T1059 observable: - name: user type: User diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 72e83809e5..288c35e63e 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -53,6 +53,7 @@ tags: - T1036.005 - T1595 - T1003 + - T1036 nist: - ID.AM - PR.DS diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index 87a828d8d3..2d327cc01e 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -46,6 +46,7 @@ tags: attempting to add a certificate to the store on endpoint $dest$ by user $user$. mitre_attack_id: - T1553.004 + - T1553 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index 8dfea2057d..1f5645aacf 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -49,6 +49,7 @@ tags: attempting to disable security services on endpoint $dest$ by user $user$. mitre_attack_id: - T1562.001 + - T1562 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml index bedad02553..c3778c3143 100644 --- a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -47,6 +47,7 @@ tags: on endpoint $dest$ by user $user$ attempting to export the registry keys. mitre_attack_id: - T1003.002 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/auto_admin_logon_registry_entry.yml b/detections/endpoint/auto_admin_logon_registry_entry.yml index 57027ab701..0ce8b228ee 100644 --- a/detections/endpoint/auto_admin_logon_registry_entry.yml +++ b/detections/endpoint/auto_admin_logon_registry_entry.yml @@ -42,6 +42,7 @@ tags: to prepare autoadminlogon mitre_attack_id: - T1552.002 + - T1552 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index 85a1dab5a8..7f447dc72f 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -51,6 +51,7 @@ tags: by user $user$. mitre_attack_id: - T1204.002 + - T1204 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/change_default_file_association.yml b/detections/endpoint/change_default_file_association.yml index 44cab51f50..c9f9b9b0d7 100644 --- a/detections/endpoint/change_default_file_association.yml +++ b/detections/endpoint/change_default_file_association.yml @@ -36,6 +36,7 @@ tags: - Exploitation mitre_attack_id: - T1546.001 + - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml index 5d35b552ed..5b072f7c71 100644 --- a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml +++ b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml @@ -40,6 +40,7 @@ tags: of a specific disk. mitre_attack_id: - T1070.004 + - T1070 observable: - name: user type: User diff --git a/detections/endpoint/cmd_echo_pipe___escalation.yml b/detections/endpoint/cmd_echo_pipe___escalation.yml index abb7fbc623..ecf9fe6f39 100644 --- a/detections/endpoint/cmd_echo_pipe___escalation.yml +++ b/detections/endpoint/cmd_echo_pipe___escalation.yml @@ -46,6 +46,8 @@ tags: mitre_attack_id: - T1059.003 - T1543.003 + - T1059 + - T1543 observable: - name: user type: User diff --git a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml index 5f9d81f862..234273636d 100644 --- a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml @@ -45,6 +45,7 @@ tags: to execute commandline tool in $dest$ mitre_attack_id: - T1059.007 + - T1059 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml b/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml index 1761c1e1a8..9862241bc4 100644 --- a/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml +++ b/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml @@ -39,6 +39,7 @@ tags: on endpoint $Computer$ by user $user$. mitre_attack_id: - T1218.003 + - T1218 observable: - name: user type: User diff --git a/detections/endpoint/control_loading_from_world_writable_directory.yml b/detections/endpoint/control_loading_from_world_writable_directory.yml index d62533f867..0bcf2fd81f 100644 --- a/detections/endpoint/control_loading_from_world_writable_directory.yml +++ b/detections/endpoint/control_loading_from_world_writable_directory.yml @@ -48,6 +48,7 @@ tags: on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. mitre_attack_id: - T1218.002 + - T1218 observable: - name: user type: User diff --git a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml index d306699d3a..5c42674597 100644 --- a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml +++ b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml @@ -46,6 +46,7 @@ tags: group. mitre_attack_id: - T1136.001 + - T1136 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml index 0ceb58467d..2e9c0b6679 100644 --- a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml +++ b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml @@ -43,6 +43,7 @@ tags: on endpoint $dest$ by user $user$ enumerating Windows file shares. mitre_attack_id: - T1070.005 + - T1070 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/create_remote_thread_into_lsass.yml b/detections/endpoint/create_remote_thread_into_lsass.yml index 57d91634f5..a14767b732 100644 --- a/detections/endpoint/create_remote_thread_into_lsass.yml +++ b/detections/endpoint/create_remote_thread_into_lsass.yml @@ -41,6 +41,7 @@ tags: behavior is indicative of credential dumping and should be investigated. mitre_attack_id: - T1003.001 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/create_service_in_suspicious_file_path.yml b/detections/endpoint/create_service_in_suspicious_file_path.yml index 22b3182108..b4de5abcb5 100644 --- a/detections/endpoint/create_service_in_suspicious_file_path.yml +++ b/detections/endpoint/create_service_in_suspicious_file_path.yml @@ -37,6 +37,7 @@ tags: $Service_Name$, potentially leading to a privilege escalation. mitre_attack_id: - T1569.002 + - T1569 observable: - name: Service_File_Name type: Other diff --git a/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml b/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml index 38e69d706d..e497bf35aa 100644 --- a/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml +++ b/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml @@ -47,6 +47,7 @@ tags: to disk. This behavior is related to dumping credentials via Task Manager. mitre_attack_id: - T1003.001 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/creation_of_shadow_copy.yml b/detections/endpoint/creation_of_shadow_copy.yml index ffea072795..9d6834c7db 100644 --- a/detections/endpoint/creation_of_shadow_copy.yml +++ b/detections/endpoint/creation_of_shadow_copy.yml @@ -45,6 +45,7 @@ tags: offline password cracking. mitre_attack_id: - T1003.003 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml index aa1e8a3c66..74bf3b4f5d 100644 --- a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml +++ b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml @@ -43,6 +43,7 @@ tags: offline password cracking. mitre_attack_id: - T1003.003 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml index 936ac84c34..85bd4e7891 100644 --- a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml @@ -45,6 +45,7 @@ tags: password cracking. mitre_attack_id: - T1003.003 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml index 58e83ed423..9efa0420bb 100644 --- a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml @@ -43,6 +43,7 @@ tags: to grab credentials. mitre_attack_id: - T1003.003 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml index 148c40261b..449b1ac903 100644 --- a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml @@ -39,6 +39,7 @@ tags: 3, which may be indicative of the pass the hash technique. mitre_attack_id: - T1550.002 + - T1550 nist: - PR.PT - PR.AT diff --git a/detections/endpoint/detect_azurehound_command_line_arguments.yml b/detections/endpoint/detect_azurehound_command_line_arguments.yml index cdffb2151f..6f20015172 100644 --- a/detections/endpoint/detect_azurehound_command_line_arguments.yml +++ b/detections/endpoint/detect_azurehound_command_line_arguments.yml @@ -46,6 +46,10 @@ tags: - T1482 - T1069.002 - T1069.001 + - T1087 + - T1087 + - T1069 + - T1069 observable: - name: user type: User diff --git a/detections/endpoint/detect_azurehound_file_modifications.yml b/detections/endpoint/detect_azurehound_file_modifications.yml index 6537197435..32b2c98833 100644 --- a/detections/endpoint/detect_azurehound_file_modifications.yml +++ b/detections/endpoint/detect_azurehound_file_modifications.yml @@ -49,6 +49,10 @@ tags: - T1482 - T1069.002 - T1069.001 + - T1087 + - T1087 + - T1069 + - T1069 observable: - name: user type: User diff --git a/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml b/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml index b95e0fedc1..d767e38a31 100644 --- a/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml +++ b/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml @@ -49,6 +49,7 @@ tags: $ComputerName$ by user $user$. mitre_attack_id: - T1003.002 + - T1003 observable: - name: user type: User diff --git a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml index 8038ff0b2f..91d192b29d 100644 --- a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml +++ b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml @@ -47,6 +47,7 @@ tags: investigated. mitre_attack_id: - T1003.001 + - T1003 nist: - PR.IP - PR.AC diff --git a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml index c3984d7e63..2e2a2b03fb 100644 --- a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml +++ b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml @@ -52,6 +52,7 @@ tags: on $ComputerName$ by $User$. mitre_attack_id: - T1059.001 + - T1059 observable: - name: User type: User diff --git a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml index a12a7c815d..8cca3ae5b9 100644 --- a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml +++ b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml @@ -50,6 +50,7 @@ tags: to $user$. mitre_attack_id: - T1078.002 + - T1078 nist: - PR.IP observable: diff --git a/detections/endpoint/detect_excessive_user_account_lockouts.yml b/detections/endpoint/detect_excessive_user_account_lockouts.yml index 92f0dca7aa..e081590ea3 100644 --- a/detections/endpoint/detect_excessive_user_account_lockouts.yml +++ b/detections/endpoint/detect_excessive_user_account_lockouts.yml @@ -39,6 +39,7 @@ tags: related to $user$. mitre_attack_id: - T1078.003 + - T1078 nist: - PR.IP observable: diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml index 74000753e6..b9639bb006 100644 --- a/detections/endpoint/detect_exchange_web_shell.yml +++ b/detections/endpoint/detect_exchange_web_shell.yml @@ -66,6 +66,7 @@ tags: $dest$ by user $user$. mitre_attack_id: - T1505.003 + - T1505 observable: - name: user type: User diff --git a/detections/endpoint/detect_html_help_renamed.yml b/detections/endpoint/detect_html_help_renamed.yml index f531890b16..f916a58917 100644 --- a/detections/endpoint/detect_html_help_renamed.yml +++ b/detections/endpoint/detect_html_help_renamed.yml @@ -54,6 +54,7 @@ tags: $parent_process_name$. mitre_attack_id: - T1218.001 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_html_help_spawn_child_process.yml b/detections/endpoint/detect_html_help_spawn_child_process.yml index 5610c65837..257da1c636 100644 --- a/detections/endpoint/detect_html_help_spawn_child_process.yml +++ b/detections/endpoint/detect_html_help_spawn_child_process.yml @@ -54,6 +54,7 @@ tags: behavior. mitre_attack_id: - T1218.001 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml index bed3e0999b..3e0952506a 100644 --- a/detections/endpoint/detect_html_help_url_in_command_line.yml +++ b/detections/endpoint/detect_html_help_url_in_command_line.yml @@ -58,6 +58,7 @@ tags: download a malicious payload. mitre_attack_id: - T1218.001 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml index 1ab7e62919..6f81ea57b5 100644 --- a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml +++ b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml @@ -59,6 +59,7 @@ tags: a specific file within a CHM on $dest$ under user $user$. mitre_attack_id: - T1218.001 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_mimikatz_using_loaded_images.yml b/detections/endpoint/detect_mimikatz_using_loaded_images.yml index e523b79fbc..6617f7be17 100644 --- a/detections/endpoint/detect_mimikatz_using_loaded_images.yml +++ b/detections/endpoint/detect_mimikatz_using_loaded_images.yml @@ -48,6 +48,7 @@ tags: to credential dumping on $Computer$. Review for further details. mitre_attack_id: - T1003.001 + - T1003 nist: - DE.AE - DE.CM diff --git a/detections/endpoint/detect_mshta_inline_hta_execution.yml b/detections/endpoint/detect_mshta_inline_hta_execution.yml index 51e322a863..5043314f03 100644 --- a/detections/endpoint/detect_mshta_inline_hta_execution.yml +++ b/detections/endpoint/detect_mshta_inline_hta_execution.yml @@ -50,6 +50,7 @@ tags: evasion. mitre_attack_id: - T1218.005 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_mshta_renamed.yml b/detections/endpoint/detect_mshta_renamed.yml index d33e17dc56..713e54dfaf 100644 --- a/detections/endpoint/detect_mshta_renamed.yml +++ b/detections/endpoint/detect_mshta_renamed.yml @@ -47,6 +47,7 @@ tags: $parent_process_name$. mitre_attack_id: - T1218.005 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index e55565847a..3cfee1627c 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -51,6 +51,7 @@ tags: download an additional payload. mitre_attack_id: - T1218.005 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_new_local_admin_account.yml b/detections/endpoint/detect_new_local_admin_account.yml index ac040f36ea..e1152726bf 100644 --- a/detections/endpoint/detect_new_local_admin_account.yml +++ b/detections/endpoint/detect_new_local_admin_account.yml @@ -42,6 +42,7 @@ tags: behavior or not. mitre_attack_id: - T1136.001 + - T1136 nist: - PR.AC - DE.CM diff --git a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml index fc7213197a..48dc4eac69 100644 --- a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml +++ b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml @@ -45,6 +45,7 @@ tags: using unquoted service paths. mitre_attack_id: - T1574.009 + - T1574 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml index 3ec0038961..df5a41e42a 100644 --- a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml +++ b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml @@ -49,6 +49,7 @@ tags: on endpoint $dest$ by user $user$ running prohibited applications. mitre_attack_id: - T1059.003 + - T1059 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index 690fa3d715..d0d72ca52b 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -54,6 +54,7 @@ tags: on endpoint $dest$ by user $user$ running the utility for possibly the first time. mitre_attack_id: - T1021.002 + - T1021 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml index c451a22d1a..002ea4bb99 100644 --- a/detections/endpoint/detect_regasm_spawning_a_process.yml +++ b/detections/endpoint/detect_regasm_spawning_a_process.yml @@ -51,6 +51,7 @@ tags: behavior for $parent_process_name$. mitre_attack_id: - T1218.009 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_regasm_with_network_connection.yml b/detections/endpoint/detect_regasm_with_network_connection.yml index 6b00c654be..e6d3541663 100644 --- a/detections/endpoint/detect_regasm_with_network_connection.yml +++ b/detections/endpoint/detect_regasm_with_network_connection.yml @@ -50,6 +50,7 @@ tags: on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$. mitre_attack_id: - T1218.009 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml index 719fcc2cfc..1129ec0a1d 100644 --- a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml @@ -49,6 +49,7 @@ tags: any command-line arguments on $dest$ by $user$. mitre_attack_id: - T1218.009 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_regsvcs_spawning_a_process.yml b/detections/endpoint/detect_regsvcs_spawning_a_process.yml index 353d09c90d..86b922dc2e 100644 --- a/detections/endpoint/detect_regsvcs_spawning_a_process.yml +++ b/detections/endpoint/detect_regsvcs_spawning_a_process.yml @@ -49,6 +49,7 @@ tags: on endpoint $dest$ by user $user$ typically not normal for this process. mitre_attack_id: - T1218.009 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_regsvcs_with_network_connection.yml b/detections/endpoint/detect_regsvcs_with_network_connection.yml index bcf8b2e515..f96d74d8bf 100644 --- a/detections/endpoint/detect_regsvcs_with_network_connection.yml +++ b/detections/endpoint/detect_regsvcs_with_network_connection.yml @@ -50,6 +50,7 @@ tags: on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$. mitre_attack_id: - T1218.009 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml index d1a5d0ccd3..a0b44caf36 100644 --- a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml @@ -49,6 +49,7 @@ tags: any command-line arguments on $dest$ by $user$. mitre_attack_id: - T1218.009 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml index 9fbe7b7eef..bc1b67e56c 100644 --- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml +++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml @@ -57,6 +57,7 @@ tags: by user $user$. mitre_attack_id: - T1218.010 + - T1218 nist: - DE.CM observable: diff --git a/detections/endpoint/detect_renamed_7_zip.yml b/detections/endpoint/detect_renamed_7_zip.yml index 3b871de923..686669851d 100644 --- a/detections/endpoint/detect_renamed_7_zip.yml +++ b/detections/endpoint/detect_renamed_7_zip.yml @@ -42,6 +42,7 @@ tags: $parent_process_name$ on $dest$ by $user$. mitre_attack_id: - T1560.001 + - T1560 observable: - name: user type: User diff --git a/detections/endpoint/detect_renamed_psexec.yml b/detections/endpoint/detect_renamed_psexec.yml index 1376383912..dbb6ccb7a8 100644 --- a/detections/endpoint/detect_renamed_psexec.yml +++ b/detections/endpoint/detect_renamed_psexec.yml @@ -50,6 +50,7 @@ tags: $parent_process_name$ on $dest$ by $user$. mitre_attack_id: - T1569.002 + - T1569 observable: - name: user type: User diff --git a/detections/endpoint/detect_renamed_winrar.yml b/detections/endpoint/detect_renamed_winrar.yml index d8e9ec6d8a..6cdad6b951 100644 --- a/detections/endpoint/detect_renamed_winrar.yml +++ b/detections/endpoint/detect_renamed_winrar.yml @@ -45,6 +45,7 @@ tags: $parent_process_name$ on $dest$ by $user$. mitre_attack_id: - T1560.001 + - T1560 observable: - name: user type: User diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml index c9a45dec66..d4d1622353 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml @@ -55,6 +55,7 @@ tags: was identified on endpoint $dest$ by user $user$. mitre_attack_id: - T1218.011 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml index 2efa7beab7..a73b6e90dc 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml @@ -53,6 +53,7 @@ tags: was identified on endpoint $dest$ by user $user$. mitre_attack_id: - T1218.011 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml index 3b6861a30d..b81a56da33 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml @@ -55,6 +55,7 @@ tags: endpoint $dest$ by user $user$. mitre_attack_id: - T1218.011 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_rundll32_inline_hta_execution.yml b/detections/endpoint/detect_rundll32_inline_hta_execution.yml index 6dc7254f55..d5f2ec77f7 100644 --- a/detections/endpoint/detect_rundll32_inline_hta_execution.yml +++ b/detections/endpoint/detect_rundll32_inline_hta_execution.yml @@ -53,6 +53,7 @@ tags: message: Suspicious rundll32.exe inline HTA execution on $dest$ mitre_attack_id: - T1218.005 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_sharphound_command_line_arguments.yml b/detections/endpoint/detect_sharphound_command_line_arguments.yml index 854e1b806e..1c66588480 100644 --- a/detections/endpoint/detect_sharphound_command_line_arguments.yml +++ b/detections/endpoint/detect_sharphound_command_line_arguments.yml @@ -49,6 +49,10 @@ tags: - T1482 - T1069.002 - T1069.001 + - T1087 + - T1087 + - T1069 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/detect_sharphound_file_modifications.yml b/detections/endpoint/detect_sharphound_file_modifications.yml index 04a57dc1ec..016572b5b9 100644 --- a/detections/endpoint/detect_sharphound_file_modifications.yml +++ b/detections/endpoint/detect_sharphound_file_modifications.yml @@ -59,6 +59,10 @@ tags: - T1482 - T1069.002 - T1069.001 + - T1087 + - T1087 + - T1069 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/detect_sharphound_usage.yml b/detections/endpoint/detect_sharphound_usage.yml index e69fcf6439..a336efe355 100644 --- a/detections/endpoint/detect_sharphound_usage.yml +++ b/detections/endpoint/detect_sharphound_usage.yml @@ -54,6 +54,10 @@ tags: - T1482 - T1069.002 - T1069.001 + - T1087 + - T1087 + - T1069 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index c5730624be..2ad343e997 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -44,6 +44,7 @@ tags: message: cmd.exe launching script interpreters on $dest$ mitre_attack_id: - T1059.003 + - T1059 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_wmi_event_subscription_persistence.yml b/detections/endpoint/detect_wmi_event_subscription_persistence.yml index be44a1befb..158adc2573 100644 --- a/detections/endpoint/detect_wmi_event_subscription_persistence.yml +++ b/detections/endpoint/detect_wmi_event_subscription_persistence.yml @@ -57,6 +57,7 @@ tags: message: Possible malicious WMI Subscription created on $dest$ mitre_attack_id: - T1546.003 + - T1546 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/disable_amsi_through_registry.yml b/detections/endpoint/disable_amsi_through_registry.yml index 893026ae11..b3234563e7 100644 --- a/detections/endpoint/disable_amsi_through_registry.yml +++ b/detections/endpoint/disable_amsi_through_registry.yml @@ -35,6 +35,7 @@ tags: - Exploitation mitre_attack_id: - T1562.001 + - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_etw_through_registry.yml b/detections/endpoint/disable_etw_through_registry.yml index 8e62da2998..15fc3b41a4 100644 --- a/detections/endpoint/disable_etw_through_registry.yml +++ b/detections/endpoint/disable_etw_through_registry.yml @@ -33,6 +33,7 @@ tags: - Exploitation mitre_attack_id: - T1562.001 + - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_logs_using_wevtutil.yml b/detections/endpoint/disable_logs_using_wevtutil.yml index 737789fa40..e8fe477c6b 100644 --- a/detections/endpoint/disable_logs_using_wevtutil.yml +++ b/detections/endpoint/disable_logs_using_wevtutil.yml @@ -39,6 +39,7 @@ tags: message: WevtUtil.exe used to disable Event Logging on $dest mitre_attack_id: - T1070.001 + - T1070 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/disable_registry_tool.yml b/detections/endpoint/disable_registry_tool.yml index b86174c023..c4a9d34f67 100644 --- a/detections/endpoint/disable_registry_tool.yml +++ b/detections/endpoint/disable_registry_tool.yml @@ -41,6 +41,7 @@ tags: message: Disabled Registry Tools on $dest$ mitre_attack_id: - T1562.001 + - T1562 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/disable_show_hidden_files.yml b/detections/endpoint/disable_show_hidden_files.yml index 8db415439d..7fc1e7e9ce 100644 --- a/detections/endpoint/disable_show_hidden_files.yml +++ b/detections/endpoint/disable_show_hidden_files.yml @@ -44,6 +44,8 @@ tags: mitre_attack_id: - T1564.001 - T1562.001 + - T1564 + - T1562 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/disable_uac_remote_restriction.yml b/detections/endpoint/disable_uac_remote_restriction.yml index 80d564165f..e52ca1e423 100644 --- a/detections/endpoint/disable_uac_remote_restriction.yml +++ b/detections/endpoint/disable_uac_remote_restriction.yml @@ -37,6 +37,7 @@ tags: - Exploitation mitre_attack_id: - T1548.002 + - T1548 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/disable_windows_app_hotkeys.yml b/detections/endpoint/disable_windows_app_hotkeys.yml index 6fee3152df..9f5f3fcfa4 100644 --- a/detections/endpoint/disable_windows_app_hotkeys.yml +++ b/detections/endpoint/disable_windows_app_hotkeys.yml @@ -43,6 +43,7 @@ tags: message: Disabled 'Windows App Hotkeys' on $dest$ mitre_attack_id: - T1562.001 + - T1562 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index bec73336b9..70d9ef034a 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -49,6 +49,7 @@ tags: message: Windows Defender real time behavior monitoring disabled on $dest mitre_attack_id: - T1562.001 + - T1562 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/disable_windows_smartscreen_protection.yml b/detections/endpoint/disable_windows_smartscreen_protection.yml index 4d95ec618e..530c2b238b 100644 --- a/detections/endpoint/disable_windows_smartscreen_protection.yml +++ b/detections/endpoint/disable_windows_smartscreen_protection.yml @@ -41,6 +41,7 @@ tags: message: The Windows Smartscreen was disabled on $dest$ by $user$. mitre_attack_id: - T1562.001 + - T1562 observable: - name: user type: User diff --git a/detections/endpoint/disabling_cmd_application.yml b/detections/endpoint/disabling_cmd_application.yml index 2e71a905be..da42de93a5 100644 --- a/detections/endpoint/disabling_cmd_application.yml +++ b/detections/endpoint/disabling_cmd_application.yml @@ -40,6 +40,7 @@ tags: message: The Windows command prompt was disabled on $dest$ by $user$. mitre_attack_id: - T1562.001 + - T1562 observable: - name: user type: User diff --git a/detections/endpoint/disabling_controlpanel.yml b/detections/endpoint/disabling_controlpanel.yml index c885277219..af3b83aa32 100644 --- a/detections/endpoint/disabling_controlpanel.yml +++ b/detections/endpoint/disabling_controlpanel.yml @@ -39,6 +39,7 @@ tags: message: The Windows Control Panel was disabled on $dest$ by $user$. mitre_attack_id: - T1562.001 + - T1562 observable: - name: user type: User diff --git a/detections/endpoint/disabling_firewall_with_netsh.yml b/detections/endpoint/disabling_firewall_with_netsh.yml index 885e7cc657..14bd3ece53 100644 --- a/detections/endpoint/disabling_firewall_with_netsh.yml +++ b/detections/endpoint/disabling_firewall_with_netsh.yml @@ -42,6 +42,7 @@ tags: message: The Windows Firewall was disabled on $dest$ by $user$. mitre_attack_id: - T1562.001 + - T1562 observable: - name: user type: User diff --git a/detections/endpoint/disabling_folderoptions_windows_feature.yml b/detections/endpoint/disabling_folderoptions_windows_feature.yml index c248d73630..b7c827178f 100644 --- a/detections/endpoint/disabling_folderoptions_windows_feature.yml +++ b/detections/endpoint/disabling_folderoptions_windows_feature.yml @@ -41,6 +41,7 @@ tags: message: The Windows Folder Options, to hide files, was disabled on $dest$ by $user$. mitre_attack_id: - T1562.001 + - T1562 observable: - name: user type: User diff --git a/detections/endpoint/disabling_norun_windows_app.yml b/detections/endpoint/disabling_norun_windows_app.yml index aa5c91dd54..e64e16287e 100644 --- a/detections/endpoint/disabling_norun_windows_app.yml +++ b/detections/endpoint/disabling_norun_windows_app.yml @@ -43,6 +43,7 @@ tags: start menu on $dest$ by $user$. mitre_attack_id: - T1562.001 + - T1562 observable: - name: user type: User diff --git a/detections/endpoint/disabling_remote_user_account_control.yml b/detections/endpoint/disabling_remote_user_account_control.yml index 7880312f6d..18d6e60eed 100644 --- a/detections/endpoint/disabling_remote_user_account_control.yml +++ b/detections/endpoint/disabling_remote_user_account_control.yml @@ -43,6 +43,7 @@ tags: Account Control (UAC) were modified on $dest$ by $user$. mitre_attack_id: - T1548.002 + - T1548 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/disabling_systemrestore_in_registry.yml b/detections/endpoint/disabling_systemrestore_in_registry.yml index 192f7c9f14..1447e5c71e 100644 --- a/detections/endpoint/disabling_systemrestore_in_registry.yml +++ b/detections/endpoint/disabling_systemrestore_in_registry.yml @@ -43,6 +43,7 @@ tags: $user$. mitre_attack_id: - T1562.001 + - T1562 observable: - name: user type: User diff --git a/detections/endpoint/disabling_task_manager.yml b/detections/endpoint/disabling_task_manager.yml index aa7fe700ee..7e09a87f91 100644 --- a/detections/endpoint/disabling_task_manager.yml +++ b/detections/endpoint/disabling_task_manager.yml @@ -41,6 +41,7 @@ tags: message: The Windows Task Manager was disabled on $dest$ by $user$. mitre_attack_id: - T1562.001 + - T1562 observable: - name: user type: User diff --git a/detections/endpoint/domain_account_discovery_with_dsquery.yml b/detections/endpoint/domain_account_discovery_with_dsquery.yml index 4703bc326c..a529264fd2 100644 --- a/detections/endpoint/domain_account_discovery_with_dsquery.yml +++ b/detections/endpoint/domain_account_discovery_with_dsquery.yml @@ -40,6 +40,7 @@ tags: message: an instance of process $process_name$ with commandline $process$ in $dest$ mitre_attack_id: - T1087.002 + - T1087 observable: - name: user type: User diff --git a/detections/endpoint/domain_account_discovery_with_net_app.yml b/detections/endpoint/domain_account_discovery_with_net_app.yml index 53071f5dbc..a7d03f7b80 100644 --- a/detections/endpoint/domain_account_discovery_with_net_app.yml +++ b/detections/endpoint/domain_account_discovery_with_net_app.yml @@ -40,6 +40,7 @@ tags: message: an instance of process $process_name$ with commandline $process$ in $dest$ mitre_attack_id: - T1087.002 + - T1087 observable: - name: user type: User diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index 8fbac42c86..040d016318 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -41,6 +41,7 @@ tags: message: an instance of process $process_name$ with commandline $process$ in $dest$ mitre_attack_id: - T1087.002 + - T1087 observable: - name: user type: User diff --git a/detections/endpoint/domain_group_discovery_with_adsisearcher.yml b/detections/endpoint/domain_group_discovery_with_adsisearcher.yml index 48e8ee1be7..23b0b075d6 100644 --- a/detections/endpoint/domain_group_discovery_with_adsisearcher.yml +++ b/detections/endpoint/domain_group_discovery_with_adsisearcher.yml @@ -38,6 +38,7 @@ tags: message: Domain group discovery enumeration using PowerShell on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/domain_group_discovery_with_dsquery.yml b/detections/endpoint/domain_group_discovery_with_dsquery.yml index 03fc2440bf..5f81fee3d3 100644 --- a/detections/endpoint/domain_group_discovery_with_dsquery.yml +++ b/detections/endpoint/domain_group_discovery_with_dsquery.yml @@ -39,6 +39,7 @@ tags: message: Domain group discovery enumeration on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/domain_group_discovery_with_net.yml b/detections/endpoint/domain_group_discovery_with_net.yml index f485b33d70..52c00a558e 100644 --- a/detections/endpoint/domain_group_discovery_with_net.yml +++ b/detections/endpoint/domain_group_discovery_with_net.yml @@ -39,6 +39,7 @@ tags: message: Domain group discovery enumeration on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/domain_group_discovery_with_wmic.yml b/detections/endpoint/domain_group_discovery_with_wmic.yml index ddd98a6d2a..0dea74f06c 100644 --- a/detections/endpoint/domain_group_discovery_with_wmic.yml +++ b/detections/endpoint/domain_group_discovery_with_wmic.yml @@ -40,6 +40,7 @@ tags: message: Domain group discovery enumeration on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/drop_icedid_license_dat.yml b/detections/endpoint/drop_icedid_license_dat.yml index e2636e402e..f531c31610 100644 --- a/detections/endpoint/drop_icedid_license_dat.yml +++ b/detections/endpoint/drop_icedid_license_dat.yml @@ -36,6 +36,7 @@ tags: message: process $SourceImage$ create a file $TargetImage$ in host $Computer$ mitre_attack_id: - T1204.002 + - T1204 observable: - name: Computer type: Hostname diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml index cc1297820a..ee1428e64c 100644 --- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml +++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml @@ -45,6 +45,7 @@ tags: accessing credentials using comsvcs.dll on endpoint $dest$ by user $user$. mitre_attack_id: - T1003.001 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/dump_lsass_via_procdump.yml b/detections/endpoint/dump_lsass_via_procdump.yml index 1de3f88d35..c8b3d080d8 100644 --- a/detections/endpoint/dump_lsass_via_procdump.yml +++ b/detections/endpoint/dump_lsass_via_procdump.yml @@ -54,6 +54,7 @@ tags: attempting to dump lsass.exe on endpoint $dest$ by user $user$. mitre_attack_id: - T1003.001 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/elevated_group_discovery_with_net.yml b/detections/endpoint/elevated_group_discovery_with_net.yml index 14656d4d5a..e9f4e5015a 100644 --- a/detections/endpoint/elevated_group_discovery_with_net.yml +++ b/detections/endpoint/elevated_group_discovery_with_net.yml @@ -46,6 +46,7 @@ tags: message: Elevated domain group discovery enumeration on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/elevated_group_discovery_with_powerview.yml b/detections/endpoint/elevated_group_discovery_with_powerview.yml index 2a43fd5d03..8e6143c301 100644 --- a/detections/endpoint/elevated_group_discovery_with_powerview.yml +++ b/detections/endpoint/elevated_group_discovery_with_powerview.yml @@ -44,6 +44,7 @@ tags: message: Elevated group discovery using PowerView on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/elevated_group_discovery_with_wmic.yml b/detections/endpoint/elevated_group_discovery_with_wmic.yml index 5ff7c11059..4ddb1e7e02 100644 --- a/detections/endpoint/elevated_group_discovery_with_wmic.yml +++ b/detections/endpoint/elevated_group_discovery_with_wmic.yml @@ -44,6 +44,7 @@ tags: message: Elevated domain group discovery enumeration on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/esentutl_sam_copy.yml b/detections/endpoint/esentutl_sam_copy.yml index f194488b2d..d8d8d11524 100644 --- a/detections/endpoint/esentutl_sam_copy.yml +++ b/detections/endpoint/esentutl_sam_copy.yml @@ -42,6 +42,7 @@ tags: cracking or observability. mitre_attack_id: - T1003.002 + - T1003 observable: - name: user type: User diff --git a/detections/endpoint/etw_registry_disabled.yml b/detections/endpoint/etw_registry_disabled.yml index c129367c35..48fefa846e 100644 --- a/detections/endpoint/etw_registry_disabled.yml +++ b/detections/endpoint/etw_registry_disabled.yml @@ -15,9 +15,9 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTim by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `etw_registry_disabled_filter`' -how_to_implement: To successfully implement this search, you must be ingesting - data that records registry activity from your hosts to populate the endpoint data - model in the registry node. This is typically populated via endpoint detection-and-response +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. @@ -35,6 +35,7 @@ tags: mitre_attack_id: - T1562.006 - T1127 + - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/eventvwr_uac_bypass.yml b/detections/endpoint/eventvwr_uac_bypass.yml index e19f3460b2..c9fc2acc9d 100644 --- a/detections/endpoint/eventvwr_uac_bypass.yml +++ b/detections/endpoint/eventvwr_uac_bypass.yml @@ -45,6 +45,7 @@ tags: by $user$. mitre_attack_id: - T1548.002 + - T1548 observable: - name: user type: User diff --git a/detections/endpoint/excel_spawning_powershell.yml b/detections/endpoint/excel_spawning_powershell.yml index d18a9c48fa..b853bffe4d 100644 --- a/detections/endpoint/excel_spawning_powershell.yml +++ b/detections/endpoint/excel_spawning_powershell.yml @@ -46,6 +46,7 @@ tags: on endpoint $dest$ by user $user$, indicating potential suspicious macro execution. mitre_attack_id: - T1003.002 + - T1003 observable: - name: user type: User diff --git a/detections/endpoint/excel_spawning_windows_script_host.yml b/detections/endpoint/excel_spawning_windows_script_host.yml index 559e3a2dd7..e808a71e12 100644 --- a/detections/endpoint/excel_spawning_windows_script_host.yml +++ b/detections/endpoint/excel_spawning_windows_script_host.yml @@ -48,6 +48,7 @@ tags: on endpoint $dest$ by user $user$, indicating potential suspicious macro execution. mitre_attack_id: - T1003.002 + - T1003 observable: - name: user type: User diff --git a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml index 208cb6f66b..13477b9ca3 100644 --- a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml +++ b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml @@ -48,6 +48,7 @@ tags: to disable services. mitre_attack_id: - T1562.001 + - T1562 observable: - name: dest type: Hostname diff --git a/detections/endpoint/excessive_usage_of_sc_service_utility.yml b/detections/endpoint/excessive_usage_of_sc_service_utility.yml index b744ba7619..0bd91d3cf8 100644 --- a/detections/endpoint/excessive_usage_of_sc_service_utility.yml +++ b/detections/endpoint/excessive_usage_of_sc_service_utility.yml @@ -34,6 +34,7 @@ tags: - Exploitation mitre_attack_id: - T1569.002 + - T1569 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/excessive_usage_of_taskkill.yml b/detections/endpoint/excessive_usage_of_taskkill.yml index a9bb1c522d..116d72a6d9 100644 --- a/detections/endpoint/excessive_usage_of_taskkill.yml +++ b/detections/endpoint/excessive_usage_of_taskkill.yml @@ -39,6 +39,7 @@ tags: 10 within 1m) has been detected on $dest$ with a parent process of $parent_process_name$. mitre_attack_id: - T1562.001 + - T1562 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml index 132ee7ef02..f566eb5c38 100644 --- a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml +++ b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml @@ -40,6 +40,7 @@ tags: on $dest$ by $user$ mitre_attack_id: - T1059.005 + - T1059 observable: - name: user type: User diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index 1f2d894cf6..2331c92704 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -43,6 +43,7 @@ tags: $dest$ by $user$ mitre_attack_id: - T1036.003 + - T1036 nist: - DE.CM - PR.PT diff --git a/detections/endpoint/extraction_of_registry_hives.yml b/detections/endpoint/extraction_of_registry_hives.yml index bec548212b..474f424a7e 100644 --- a/detections/endpoint/extraction_of_registry_hives.yml +++ b/detections/endpoint/extraction_of_registry_hives.yml @@ -44,6 +44,7 @@ tags: credentials executed on $dest$ by user $user$, with a parent process of $parent_process_id$ mitre_attack_id: - T1003.002 + - T1003 observable: - name: user type: User diff --git a/detections/endpoint/fodhelper_uac_bypass.yml b/detections/endpoint/fodhelper_uac_bypass.yml index 27a56f9b48..6586eae065 100644 --- a/detections/endpoint/fodhelper_uac_bypass.yml +++ b/detections/endpoint/fodhelper_uac_bypass.yml @@ -55,6 +55,7 @@ tags: mitre_attack_id: - T1112 - T1548.002 + - T1548 observable: - name: user type: User diff --git a/detections/endpoint/get_aduser_with_powershell.yml b/detections/endpoint/get_aduser_with_powershell.yml index b00b8fede5..d7d92a915a 100644 --- a/detections/endpoint/get_aduser_with_powershell.yml +++ b/detections/endpoint/get_aduser_with_powershell.yml @@ -42,6 +42,7 @@ tags: message: an instance of process $process_name$ with commandline $process$ in $dest$ mitre_attack_id: - T1087.002 + - T1087 observable: - name: user type: User diff --git a/detections/endpoint/get_aduser_with_powershell_script_block.yml b/detections/endpoint/get_aduser_with_powershell_script_block.yml index 86b2592af0..8f3f227eae 100644 --- a/detections/endpoint/get_aduser_with_powershell_script_block.yml +++ b/detections/endpoint/get_aduser_with_powershell_script_block.yml @@ -39,6 +39,7 @@ tags: message: powershell process having commandline $Message$ for user enumeration mitre_attack_id: - T1087.002 + - T1087 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml index 1dd28005b7..6ec2b802dc 100644 --- a/detections/endpoint/get_domainuser_with_powershell.yml +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -41,6 +41,7 @@ tags: message: an instance of process $process_name$ with commandline $process$ in $dest$ mitre_attack_id: - T1087.002 + - T1087 observable: - name: user type: User diff --git a/detections/endpoint/get_domainuser_with_powershell_script_block.yml b/detections/endpoint/get_domainuser_with_powershell_script_block.yml index 658af116c9..aec6b0b367 100644 --- a/detections/endpoint/get_domainuser_with_powershell_script_block.yml +++ b/detections/endpoint/get_domainuser_with_powershell_script_block.yml @@ -36,6 +36,7 @@ tags: message: powershell process having commandline $Message$ for user enumeration mitre_attack_id: - T1087.002 + - T1087 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/get_wmiobject_group_discovery.yml b/detections/endpoint/get_wmiobject_group_discovery.yml index 4505077cb7..37c3322949 100644 --- a/detections/endpoint/get_wmiobject_group_discovery.yml +++ b/detections/endpoint/get_wmiobject_group_discovery.yml @@ -44,6 +44,7 @@ tags: message: System group discovery on $dest$ by $user$. mitre_attack_id: - T1069.001 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml b/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml index 21636a70dc..35de38f64c 100644 --- a/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml +++ b/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml @@ -50,6 +50,7 @@ tags: message: System group discovery enumeration on $dest$ by $user$. mitre_attack_id: - T1069.001 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/getadgroup_with_powershell.yml b/detections/endpoint/getadgroup_with_powershell.yml index cef640c54c..9607a30734 100644 --- a/detections/endpoint/getadgroup_with_powershell.yml +++ b/detections/endpoint/getadgroup_with_powershell.yml @@ -41,6 +41,7 @@ tags: message: Domain group discovery enumeration on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/getadgroup_with_powershell_script_block.yml b/detections/endpoint/getadgroup_with_powershell_script_block.yml index 020781ea8e..56c380944e 100644 --- a/detections/endpoint/getadgroup_with_powershell_script_block.yml +++ b/detections/endpoint/getadgroup_with_powershell_script_block.yml @@ -39,6 +39,7 @@ tags: message: Domain group discovery enumeration using PowerShell on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/getdomaingroup_with_powershell.yml b/detections/endpoint/getdomaingroup_with_powershell.yml index 2a7a65ac3b..75c68adda4 100644 --- a/detections/endpoint/getdomaingroup_with_powershell.yml +++ b/detections/endpoint/getdomaingroup_with_powershell.yml @@ -41,6 +41,7 @@ tags: message: Domain group discovery with PowerView on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/getdomaingroup_with_powershell_script_block.yml b/detections/endpoint/getdomaingroup_with_powershell_script_block.yml index 5581a5dc9b..2801c0ea50 100644 --- a/detections/endpoint/getdomaingroup_with_powershell_script_block.yml +++ b/detections/endpoint/getdomaingroup_with_powershell_script_block.yml @@ -40,6 +40,7 @@ tags: message: Domain group discovery enumeration using PowerView on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/getlocaluser_with_powershell.yml b/detections/endpoint/getlocaluser_with_powershell.yml index 1024798cce..124ec082fc 100644 --- a/detections/endpoint/getlocaluser_with_powershell.yml +++ b/detections/endpoint/getlocaluser_with_powershell.yml @@ -39,6 +39,7 @@ tags: message: Local user discovery enumeration using PowerShell on $dest$ by $user$ mitre_attack_id: - T1087.001 + - T1087 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/getlocaluser_with_powershell_script_block.yml b/detections/endpoint/getlocaluser_with_powershell_script_block.yml index a0c17849da..f4d17cd721 100644 --- a/detections/endpoint/getlocaluser_with_powershell_script_block.yml +++ b/detections/endpoint/getlocaluser_with_powershell_script_block.yml @@ -37,6 +37,7 @@ tags: message: Local user discovery enumeration using PowerShell on $dest$ by $user$ mitre_attack_id: - T1087.001 + - T1087 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml index b54f8f381f..b4e7ef2b68 100644 --- a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml @@ -43,6 +43,7 @@ tags: message: Domain group discovery enumeration on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml index 09c1977e6a..ab1ad6c1ec 100644 --- a/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml @@ -40,6 +40,7 @@ tags: message: Domain group discovery enumeration using PowerShell on $dest$ by $user$ mitre_attack_id: - T1069.002 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml index 9ba8d47259..26e14b6cd0 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -43,6 +43,7 @@ tags: message: an instance of process $process_name$ with commandline $process$ in $dest$ mitre_attack_id: - T1087.002 + - T1087 observable: - name: user type: User diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml index 39ee2767ac..3ba1b7dae8 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml @@ -38,6 +38,7 @@ tags: message: powershell process having commandline $Message$ for user enumeration mitre_attack_id: - T1087.002 + - T1087 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/getwmiobject_user_account_with_powershell.yml b/detections/endpoint/getwmiobject_user_account_with_powershell.yml index a7947ad2e7..a3797b290b 100644 --- a/detections/endpoint/getwmiobject_user_account_with_powershell.yml +++ b/detections/endpoint/getwmiobject_user_account_with_powershell.yml @@ -40,6 +40,7 @@ tags: message: Local user discovery enumeration using PowerShell on $dest$ by $user$ mitre_attack_id: - T1087.001 + - T1087 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml index 72133c07e3..9929fe642e 100644 --- a/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml @@ -37,6 +37,7 @@ tags: message: Local user discovery enumeration using PowerShell on $dest$ by $user$ mitre_attack_id: - T1087.001 + - T1087 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/hide_user_account_from_sign_in_screen.yml b/detections/endpoint/hide_user_account_from_sign_in_screen.yml index 1e09f29522..a25bd2c490 100644 --- a/detections/endpoint/hide_user_account_from_sign_in_screen.yml +++ b/detections/endpoint/hide_user_account_from_sign_in_screen.yml @@ -45,6 +45,7 @@ tags: by $user$ mitre_attack_id: - T1562.001 + - T1562 observable: - name: user type: User diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index 3a1fc7c969..c3a70db769 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -44,6 +44,7 @@ tags: message: Attrib.exe with +h flag to hide files on $dest$ executed by $user$ is detected. mitre_attack_id: - T1222.001 + - T1222 nist: - DE.CM observable: diff --git a/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml b/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml index d15cc3af5f..06a6670bcf 100644 --- a/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml +++ b/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml @@ -36,6 +36,7 @@ tags: message: process $SourceImage$ create a file $TargetImage$ in host $Computer$ mitre_attack_id: - T1560.001 + - T1560 observable: - name: Computer type: Hostname diff --git a/detections/endpoint/jscript_execution_using_cscript_app.yml b/detections/endpoint/jscript_execution_using_cscript_app.yml index 283084eb7a..158df4d177 100644 --- a/detections/endpoint/jscript_execution_using_cscript_app.yml +++ b/detections/endpoint/jscript_execution_using_cscript_app.yml @@ -43,6 +43,7 @@ tags: in $dest$ mitre_attack_id: - T1059.007 + - T1059 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml index 7615864c22..16e0546134 100644 --- a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml +++ b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml @@ -39,6 +39,7 @@ tags: on $dest$ mitre_attack_id: - T1558.003 + - T1558 nist: - DE.CM observable: diff --git a/detections/endpoint/local_account_discovery_with_net.yml b/detections/endpoint/local_account_discovery_with_net.yml index e59d230302..78cc1ed178 100644 --- a/detections/endpoint/local_account_discovery_with_net.yml +++ b/detections/endpoint/local_account_discovery_with_net.yml @@ -38,6 +38,7 @@ tags: message: Local user discovery enumeration on $dest$ by $user$ mitre_attack_id: - T1087.001 + - T1087 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/local_account_discovery_with_wmic.yml b/detections/endpoint/local_account_discovery_with_wmic.yml index 299aada6a3..c7cbc68e54 100644 --- a/detections/endpoint/local_account_discovery_with_wmic.yml +++ b/detections/endpoint/local_account_discovery_with_wmic.yml @@ -37,6 +37,7 @@ tags: message: Local user discovery enumeration on $dest$ by $user$ mitre_attack_id: - T1087.001 + - T1087 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/logon_script_event_trigger_execution.yml b/detections/endpoint/logon_script_event_trigger_execution.yml index e881970354..493b64041b 100644 --- a/detections/endpoint/logon_script_event_trigger_execution.yml +++ b/detections/endpoint/logon_script_event_trigger_execution.yml @@ -34,6 +34,7 @@ tags: - Exploitation mitre_attack_id: - T1037.001 + - T1037 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/mailsniper_invoke_functions.yml b/detections/endpoint/mailsniper_invoke_functions.yml index ab322fb2f1..1568717cf8 100644 --- a/detections/endpoint/mailsniper_invoke_functions.yml +++ b/detections/endpoint/mailsniper_invoke_functions.yml @@ -39,6 +39,7 @@ tags: $user$. mitre_attack_id: - T1114.001 + - T1114 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/malicious_powershell_executed_as_a_service.yml b/detections/endpoint/malicious_powershell_executed_as_a_service.yml index fb6382ba34..deed016eae 100644 --- a/detections/endpoint/malicious_powershell_executed_as_a_service.yml +++ b/detections/endpoint/malicious_powershell_executed_as_a_service.yml @@ -40,6 +40,7 @@ tags: as a service $Service_File_Name$ by $user$ on $dest$ mitre_attack_id: - T1569.002 + - T1569 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml b/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml index 7b5444fb72..85b83513f3 100644 --- a/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml +++ b/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml @@ -5,18 +5,22 @@ date: '2021-10-05' author: David Dorsey, Michael Haag Splunk type: Hunting datamodel: - - Endpoint -description: 'The following hunting analytic identifies PowerShell commands utilizing the WindowStyle parameter to hide the window on the compromised endpoint. This combination of command-line options is suspicious because it is overriding the default PowerShell execution policy, attempts to hide its activity from the user, and connects to the Internet. - Removed in this version of the query is New-Object. - The analytic identifies all variations of WindowStyle, as PowerShell allows the ability to shorten the parameter. For example w, win, windowsty and so forth. In addition, through our research it was identified that PowerShell will interpret different command switch types beyond the hyphen. We have added endash, emdash, horizontal bar, and forward slash.' -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_powershell` by Processes.user - Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name Processes.dest Processes.process_id - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | where match(process,"(?i)[\-|\/|–|—|―]w(in*d*o*w*s*t*y*l*e*)*\s+[^-]") - | `malicious_powershell_process___connect_to_internet_with_hidden_window_filter`' +- Endpoint +description: The following hunting analytic identifies PowerShell commands utilizing + the WindowStyle parameter to hide the window on the compromised endpoint. This combination + of command-line options is suspicious because it is overriding the default PowerShell + execution policy, attempts to hide its activity from the user, and connects to the + Internet. Removed in this version of the query is New-Object. The analytic identifies + all variations of WindowStyle, as PowerShell allows the ability to shorten the parameter. + For example w, win, windowsty and so forth. In addition, through our research it + was identified that PowerShell will interpret different command switch types beyond + the hyphen. We have added endash, emdash, horizontal bar, and forward slash. +search: "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)\ + \ as lastTime from datamodel=Endpoint.Processes where `process_powershell` by Processes.user\ + \ Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name\ + \ Processes.dest Processes.process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`\ + \ | `security_content_ctime(lastTime)` | where match(process,\"(?i)[\\-|\\/|\u2013\ + |\u2014|\u2015]w(in*d*o*w*s*t*y*l*e*)*\\s+[^-]\") | `malicious_powershell_process___connect_to_internet_with_hidden_window_filter`" how_to_implement: You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. @@ -24,11 +28,11 @@ how_to_implement: You must be ingesting data that records process activity from model. known_false_positives: Legitimate process can have this combination of command-line options, but it's not common. -references: - - https://regexr.com/663rr - - https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1059.001_PowerShell/OutPowerShellCommandLineParameter.ps1 - - https://ss64.com/ps/powershell.html - - https://twitter.com/M_haggis/status/1440758396534214658?s=20 +references: +- https://regexr.com/663rr +- https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1059.001_PowerShell/OutPowerShellCommandLineParameter.ps1 +- https://ss64.com/ps/powershell.html +- https://twitter.com/M_haggis/status/1440758396534214658?s=20 tags: analytic_story: - Malicious PowerShell @@ -56,6 +60,7 @@ tags: $dest$ executed by user $user$. mitre_attack_id: - T1059.001 + - T1059 nist: - PR.PT - DE.CM @@ -85,4 +90,4 @@ tags: - Processes.parent_process_name - Processes.dest risk_score: 81 - security_domain: endpoint \ No newline at end of file + security_domain: endpoint diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml index 092198c93f..58b89d983f 100644 --- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml +++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml @@ -50,6 +50,7 @@ tags: message: PowerShell local execution policy bypass attempt on $dest$ mitre_attack_id: - T1059.001 + - T1059 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml index 69aff6f30b..89d024df1f 100644 --- a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml +++ b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml @@ -48,6 +48,7 @@ tags: message: Powershell.exe running with potential obfuscated arguments on $dest$ mitre_attack_id: - T1059.001 + - T1059 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml index a5f4f5809b..ce986c1257 100644 --- a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml +++ b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml @@ -47,6 +47,7 @@ tags: message: New print monitor added on $dest$ mitre_attack_id: - T1547.010 + - T1547 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/ms_scripting_process_loading_ldap_module.yml b/detections/endpoint/ms_scripting_process_loading_ldap_module.yml index d918a16e6c..d30b011364 100644 --- a/detections/endpoint/ms_scripting_process_loading_ldap_module.yml +++ b/detections/endpoint/ms_scripting_process_loading_ldap_module.yml @@ -43,6 +43,7 @@ tags: message: $process_name$ loading ldap modules $ImageLoaded$ in $dest$ mitre_attack_id: - T1059.007 + - T1059 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/ms_scripting_process_loading_wmi_module.yml b/detections/endpoint/ms_scripting_process_loading_wmi_module.yml index 50a0e0d6e3..a9c721de80 100644 --- a/detections/endpoint/ms_scripting_process_loading_wmi_module.yml +++ b/detections/endpoint/ms_scripting_process_loading_wmi_module.yml @@ -44,6 +44,7 @@ tags: message: $process_name$ loading wmi modules $ImageLoaded$ in $dest$ mitre_attack_id: - T1059.007 + - T1059 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml index d0687e4c57..fe779d6c1a 100644 --- a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml +++ b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml @@ -6,12 +6,12 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: This analytic is to detect a suspicious child process of MSBuild - spawned by Windows Script Host - cscript or wscript. - This behavior or event are commonly seen and used by malware or adversaries - to execute malicious msbuild process using malicious script in the compromised host. - During triage, review parallel processes and identify any file modifications. MSBuild - may load a script from the same path without having command-line arguments. +description: This analytic is to detect a suspicious child process of MSBuild spawned + by Windows Script Host - cscript or wscript. This behavior or event are commonly + seen and used by malware or adversaries to execute malicious msbuild process using + malicious script in the compromised host. During triage, review parallel processes + and identify any file modifications. MSBuild may load a script from the same path + without having command-line arguments. search: '| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name @@ -19,8 +19,13 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `msbuild_suspicious_spawned_by_script_process_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. -known_false_positives: False positives should be limited as developers do not spawn MSBuild via a WSH. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives should be limited as developers do not spawn + MSBuild via a WSH. references: - https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/# tags: @@ -32,6 +37,7 @@ tags: - Exploitation mitre_attack_id: - T1127.001 + - T1127 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml index c03f56b0ac..cbdc8cafc2 100644 --- a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml +++ b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml @@ -43,6 +43,7 @@ tags: in host $dest$ mitre_attack_id: - T1218.005 + - T1218 observable: - name: dest type: Hostname diff --git a/detections/endpoint/mshtml_module_load_in_office_product.yml b/detections/endpoint/mshtml_module_load_in_office_product.yml index e644c3940b..b333064dd5 100644 --- a/detections/endpoint/mshtml_module_load_in_office_product.yml +++ b/detections/endpoint/mshtml_module_load_in_office_product.yml @@ -42,6 +42,7 @@ tags: mshtml.dll. mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Hostname diff --git a/detections/endpoint/msmpeng_application_dll_side_loading.yml b/detections/endpoint/msmpeng_application_dll_side_loading.yml index 5949d345bf..c172950f46 100644 --- a/detections/endpoint/msmpeng_application_dll_side_loading.yml +++ b/detections/endpoint/msmpeng_application_dll_side_loading.yml @@ -34,6 +34,7 @@ tags: - Exploitation mitre_attack_id: - T1574.002 + - T1574 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml b/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml index af9c0c7a6a..415b3d1c90 100644 --- a/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml +++ b/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml @@ -59,6 +59,7 @@ tags: message: Potential Kerberos based password spraying attack from $Client_Address$ mitre_attack_id: - T1110.003 + - T1110 observable: - name: Client_Address type: Endpoint diff --git a/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml b/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml index f7c63392df..963bf4798f 100644 --- a/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml +++ b/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml @@ -59,6 +59,7 @@ tags: message: Potential Kerberos based password spraying attack from $Client_Address$ mitre_attack_id: - T1110.003 + - T1110 observable: - name: Client_Address type: Endpoint diff --git a/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml b/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml index 921b06b0d4..151c4529bf 100644 --- a/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml +++ b/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml @@ -63,6 +63,7 @@ tags: message: Potential NTLM based password spraying attack from $Source_Workstation$ mitre_attack_id: - T1110.003 + - T1110 observable: - name: Source_Workstation type: Endpoint diff --git a/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml b/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml index 6c7ec500e2..5e26a71bed 100644 --- a/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml +++ b/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml @@ -64,6 +64,7 @@ tags: message: Potential password spraying attack from $ComputerName$ mitre_attack_id: - T1110.003 + - T1110 observable: - name: ComputerName type: Endpoint diff --git a/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml b/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml index 993b23b81e..37598d8b2d 100644 --- a/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml +++ b/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml @@ -59,6 +59,7 @@ tags: message: Potential Kerberos based password spraying attack from $Client_Address$ mitre_attack_id: - T1110.003 + - T1110 observable: - name: Client_Address type: Endpoint diff --git a/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml b/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml index 0a0836c811..845ed682fa 100644 --- a/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml +++ b/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml @@ -61,6 +61,7 @@ tags: message: Potential NTLM based password spraying attack from $Source_Workstation$ mitre_attack_id: - T1110.003 + - T1110 observable: - name: Source_Workstation type: Endpoint diff --git a/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml b/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml index 9ba84c5279..d03cfac314 100644 --- a/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml +++ b/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml @@ -63,6 +63,7 @@ tags: message: Potential password spraying attack from $ComputerName$ mitre_attack_id: - T1110.003 + - T1110 observable: - name: ComputerName type: Endpoint diff --git a/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml b/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml index 8771fb2160..b9d616aeaf 100644 --- a/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml +++ b/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml @@ -62,6 +62,7 @@ tags: message: Potential password spraying attack on $ComputerName$ mitre_attack_id: - T1110.003 + - T1110 observable: - name: ComputerName type: Endpoint diff --git a/detections/endpoint/net_localgroup_discovery.yml b/detections/endpoint/net_localgroup_discovery.yml index 768e1b7b54..85003a1fd3 100644 --- a/detections/endpoint/net_localgroup_discovery.yml +++ b/detections/endpoint/net_localgroup_discovery.yml @@ -42,6 +42,7 @@ tags: message: Local group discovery on $dest$ by $user$. mitre_attack_id: - T1069.001 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/net_profiler_uac_bypass.yml b/detections/endpoint/net_profiler_uac_bypass.yml index f13ad3cef2..1bbe6e2656 100644 --- a/detections/endpoint/net_profiler_uac_bypass.yml +++ b/detections/endpoint/net_profiler_uac_bypass.yml @@ -44,6 +44,7 @@ tags: path $registry_value_name$ in $dest$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: dest type: Hostname diff --git a/detections/endpoint/nishang_powershelltcponeline.yml b/detections/endpoint/nishang_powershelltcponeline.yml index e43528e550..fe457b149f 100644 --- a/detections/endpoint/nishang_powershelltcponeline.yml +++ b/detections/endpoint/nishang_powershelltcponeline.yml @@ -47,6 +47,7 @@ tags: message: Possible Nishang Invoke-PowerShellTCPOneLine behavior on $dest$ mitre_attack_id: - T1059.001 + - T1059 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml index dafea93521..ef55cbda29 100644 --- a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml +++ b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml @@ -41,6 +41,7 @@ tags: message: a non firefox browser process $process_name$ accessing $Object_Name$ mitre_attack_id: - T1555.003 + - T1555 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml index 042ef2a34f..ea1ad45181 100644 --- a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml +++ b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml @@ -41,6 +41,7 @@ tags: message: a non firefox browser process $process_name$ accessing $Object_Name$ mitre_attack_id: - T1555.003 + - T1555 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/ntdsutil_export_ntds.yml b/detections/endpoint/ntdsutil_export_ntds.yml index 12b840d0ea..0b7c18eac7 100644 --- a/detections/endpoint/ntdsutil_export_ntds.yml +++ b/detections/endpoint/ntdsutil_export_ntds.yml @@ -55,6 +55,7 @@ tags: message: Active Directory NTDS export on $dest$ mitre_attack_id: - T1003.003 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/office_application_drop_executable.yml b/detections/endpoint/office_application_drop_executable.yml index 02b1eaa4f3..4722eacee4 100644 --- a/detections/endpoint/office_application_drop_executable.yml +++ b/detections/endpoint/office_application_drop_executable.yml @@ -46,6 +46,7 @@ tags: message: process $process_name$ drops a file $TargetFilename$ in host $dest$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: Computer type: Hostname diff --git a/detections/endpoint/office_application_spawn_regsvr32_process.yml b/detections/endpoint/office_application_spawn_regsvr32_process.yml index 68bbcc546b..4675c4cf79 100644 --- a/detections/endpoint/office_application_spawn_regsvr32_process.yml +++ b/detections/endpoint/office_application_spawn_regsvr32_process.yml @@ -42,6 +42,7 @@ tags: message: Office application spawning regsvr32.exe on $dest$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/office_application_spawn_rundll32_process.yml b/detections/endpoint/office_application_spawn_rundll32_process.yml index cad9a40af1..cb3ed243b3 100644 --- a/detections/endpoint/office_application_spawn_rundll32_process.yml +++ b/detections/endpoint/office_application_spawn_rundll32_process.yml @@ -44,6 +44,7 @@ tags: message: Office application spawning rundll32.exe on $dest$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/office_document_creating_schedule_task.yml b/detections/endpoint/office_document_creating_schedule_task.yml index 4d479975a8..b77e56b96d 100644 --- a/detections/endpoint/office_document_creating_schedule_task.yml +++ b/detections/endpoint/office_document_creating_schedule_task.yml @@ -48,6 +48,7 @@ tags: message: Office document creating a schedule task on $dest$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/office_document_executing_macro_code.yml b/detections/endpoint/office_document_executing_macro_code.yml index 198925b8da..13ef88d81a 100644 --- a/detections/endpoint/office_document_executing_macro_code.yml +++ b/detections/endpoint/office_document_executing_macro_code.yml @@ -43,6 +43,7 @@ tags: message: Office document executing a macro on $dest$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/office_document_spawned_child_process_to_download.yml b/detections/endpoint/office_document_spawned_child_process_to_download.yml index 3c20bc426a..4b21e07125 100644 --- a/detections/endpoint/office_document_spawned_child_process_to_download.yml +++ b/detections/endpoint/office_document_spawned_child_process_to_download.yml @@ -42,6 +42,7 @@ tags: message: Office document spawning suspicious child process on $dest$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/office_product_spawn_cmd_process.yml b/detections/endpoint/office_product_spawn_cmd_process.yml index adaf7de575..2691d97892 100644 --- a/detections/endpoint/office_product_spawn_cmd_process.yml +++ b/detections/endpoint/office_product_spawn_cmd_process.yml @@ -44,6 +44,7 @@ tags: $process_name$ in host $dest$ mitre_attack_id: - T1218.005 + - T1218 observable: - name: dest type: Hostname diff --git a/detections/endpoint/office_product_spawning_bitsadmin.yml b/detections/endpoint/office_product_spawning_bitsadmin.yml index cdb600e6e5..5fac23fabf 100644 --- a/detections/endpoint/office_product_spawning_bitsadmin.yml +++ b/detections/endpoint/office_product_spawning_bitsadmin.yml @@ -49,6 +49,7 @@ tags: process $process_name$ with process id $process_id$ in host $dest$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Hostname diff --git a/detections/endpoint/office_product_spawning_certutil.yml b/detections/endpoint/office_product_spawning_certutil.yml index f7cf768231..54db62c75f 100644 --- a/detections/endpoint/office_product_spawning_certutil.yml +++ b/detections/endpoint/office_product_spawning_certutil.yml @@ -49,6 +49,7 @@ tags: process $process_name$ with process id $process_id$ in host $dest$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Hostname diff --git a/detections/endpoint/office_product_spawning_mshta.yml b/detections/endpoint/office_product_spawning_mshta.yml index 6106b3e695..343424ad9f 100644 --- a/detections/endpoint/office_product_spawning_mshta.yml +++ b/detections/endpoint/office_product_spawning_mshta.yml @@ -49,6 +49,7 @@ tags: process $process_name$ with process id $process_id$ in host $dest$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Hostname diff --git a/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml b/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml index cfbeb7c686..103d4d23b3 100644 --- a/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml +++ b/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml @@ -52,6 +52,7 @@ tags: in host $dest$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Hostname diff --git a/detections/endpoint/office_product_spawning_wmic.yml b/detections/endpoint/office_product_spawning_wmic.yml index fa41770c29..cc20c0f19d 100644 --- a/detections/endpoint/office_product_spawning_wmic.yml +++ b/detections/endpoint/office_product_spawning_wmic.yml @@ -51,6 +51,7 @@ tags: process $process_name$ with process id $process_id$ in host $dest$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Hostname diff --git a/detections/endpoint/office_product_writing_cab_or_inf.yml b/detections/endpoint/office_product_writing_cab_or_inf.yml index db49bd8fd4..01a509ecc2 100644 --- a/detections/endpoint/office_product_writing_cab_or_inf.yml +++ b/detections/endpoint/office_product_writing_cab_or_inf.yml @@ -50,6 +50,7 @@ tags: cab file to this. This is not typical of $process_name$. mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Hostname diff --git a/detections/endpoint/office_spawning_control.yml b/detections/endpoint/office_spawning_control.yml index 446ff63f48..2c5ccb23a9 100644 --- a/detections/endpoint/office_spawning_control.yml +++ b/detections/endpoint/office_spawning_control.yml @@ -51,6 +51,7 @@ tags: on endpoint $dest$ clicking a suspicious attachment. mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Hostname diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index f15b0a9895..58181c33c1 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -44,6 +44,7 @@ tags: message: A suspicious file modification or replace in $file_path$ in host $dest$ mitre_attack_id: - T1546.008 + - T1546 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/powershell_4104_hunting.yml b/detections/endpoint/powershell_4104_hunting.yml index 01dd1b41b7..1eccb78527 100644 --- a/detections/endpoint/powershell_4104_hunting.yml +++ b/detections/endpoint/powershell_4104_hunting.yml @@ -62,6 +62,7 @@ tags: on endpoint $dest$ by user $user$ executing suspicious commands. mitre_attack_id: - T1059.001 + - T1059 observable: - name: user type: User diff --git a/detections/endpoint/powershell_creating_thread_mutex.yml b/detections/endpoint/powershell_creating_thread_mutex.yml index 3b4c93be23..5e90a86b08 100644 --- a/detections/endpoint/powershell_creating_thread_mutex.yml +++ b/detections/endpoint/powershell_creating_thread_mutex.yml @@ -42,6 +42,7 @@ tags: EventCode $EventCode$ in host $ComputerName$ mitre_attack_id: - T1027.005 + - T1027 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/powershell_disable_security_monitoring.yml b/detections/endpoint/powershell_disable_security_monitoring.yml index 94dde9352f..407a386845 100644 --- a/detections/endpoint/powershell_disable_security_monitoring.yml +++ b/detections/endpoint/powershell_disable_security_monitoring.yml @@ -36,6 +36,7 @@ tags: - Exploitation mitre_attack_id: - T1562.001 + - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_domain_enumeration.yml b/detections/endpoint/powershell_domain_enumeration.yml index 8fa2e478d1..5a84bcf1c8 100644 --- a/detections/endpoint/powershell_domain_enumeration.yml +++ b/detections/endpoint/powershell_domain_enumeration.yml @@ -47,6 +47,7 @@ tags: with EventCode $EventCode$ in host $ComputerName$ mitre_attack_id: - T1059.001 + - T1059 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/powershell_enable_smb1protocol_feature.yml b/detections/endpoint/powershell_enable_smb1protocol_feature.yml index d1957dc29e..0b6af2b269 100644 --- a/detections/endpoint/powershell_enable_smb1protocol_feature.yml +++ b/detections/endpoint/powershell_enable_smb1protocol_feature.yml @@ -31,6 +31,7 @@ tags: - Exploitation mitre_attack_id: - T1027.005 + - T1027 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/powershell_execute_com_object.yml b/detections/endpoint/powershell_execute_com_object.yml index bc3b89bde8..30626cd311 100644 --- a/detections/endpoint/powershell_execute_com_object.yml +++ b/detections/endpoint/powershell_execute_com_object.yml @@ -40,6 +40,7 @@ tags: with EventCode $EventCode$ in host $ComputerName$ mitre_attack_id: - T1546.015 + - T1546 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml b/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml index 040219fbfd..dac9e3d781 100644 --- a/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml +++ b/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml @@ -51,6 +51,7 @@ tags: mitre_attack_id: - T1055 - T1059.001 + - T1059 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml b/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml index e903014977..435ea94f77 100644 --- a/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml +++ b/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml @@ -51,6 +51,7 @@ tags: mitre_attack_id: - T1027 - T1059.001 + - T1059 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/powershell_get_localgroup_discovery.yml b/detections/endpoint/powershell_get_localgroup_discovery.yml index 09ac3e7d86..ec1447a04d 100644 --- a/detections/endpoint/powershell_get_localgroup_discovery.yml +++ b/detections/endpoint/powershell_get_localgroup_discovery.yml @@ -41,6 +41,7 @@ tags: message: Local group discovery on $dest$ by $user$. mitre_attack_id: - T1069.001 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml b/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml index 449c4c4ce0..f64e26b4ca 100644 --- a/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml +++ b/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml @@ -50,6 +50,7 @@ tags: message: Local group discovery on $dest$ by $user$. mitre_attack_id: - T1069.001 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml b/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml index ee9ee03b06..84c7772e86 100644 --- a/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml +++ b/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml @@ -51,6 +51,7 @@ tags: in $Message$ to load .net code in memory with EventCode $EventCode$ in host $ComputerName$ mitre_attack_id: - T1059.001 + - T1059 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/powershell_processing_stream_of_data.yml b/detections/endpoint/powershell_processing_stream_of_data.yml index c0a533d2d5..ca9ed99c07 100644 --- a/detections/endpoint/powershell_processing_stream_of_data.yml +++ b/detections/endpoint/powershell_processing_stream_of_data.yml @@ -43,6 +43,7 @@ tags: in host $ComputerName$ mitre_attack_id: - T1059.001 + - T1059 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/print_spooler_adding_a_printer_driver.yml b/detections/endpoint/print_spooler_adding_a_printer_driver.yml index cc1cfc97e3..d65fc252fd 100644 --- a/detections/endpoint/print_spooler_adding_a_printer_driver.yml +++ b/detections/endpoint/print_spooler_adding_a_printer_driver.yml @@ -50,6 +50,7 @@ tags: message: Suspicious print driver was loaded on endpoint $ComputerName$. mitre_attack_id: - T1547.012 + - T1547 observable: - name: ComputerName type: Endpoint diff --git a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml index 6e5b4fc245..919bc479cc 100644 --- a/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml +++ b/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml @@ -48,6 +48,7 @@ tags: with EventCode $EventCode$. mitre_attack_id: - T1547.012 + - T1547 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml index 9489d60655..9cff5c5c59 100644 --- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml +++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml @@ -52,6 +52,7 @@ tags: $dest$ mitre_attack_id: - T1566.002 + - T1566 nist: - ID.AM - PR.DS diff --git a/detections/endpoint/process_kill_base_on_file_path.yml b/detections/endpoint/process_kill_base_on_file_path.yml index 348aa36b7c..1f31e2837d 100644 --- a/detections/endpoint/process_kill_base_on_file_path.yml +++ b/detections/endpoint/process_kill_base_on_file_path.yml @@ -41,6 +41,7 @@ tags: commandline $process$ in host $dest$ mitre_attack_id: - T1562.001 + - T1562 observable: - name: dest type: Hostname diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index 9d38fe10ac..faf4444a75 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -49,6 +49,7 @@ tags: in host $dest$ mitre_attack_id: - T1562.004 + - T1562 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml index c6ff3b9dc0..9d4d46991d 100644 --- a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml +++ b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml @@ -35,6 +35,7 @@ tags: - Exploitation mitre_attack_id: - T1070.004 + - T1070 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml index 976e65c665..ffd507fbab 100644 --- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml +++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml @@ -49,6 +49,7 @@ tags: message: A reg.exe process $process_name$ with commandline $process$ in host $dest$ mitre_attack_id: - T1574.011 + - T1574 nist: - PR.IP - PR.PT diff --git a/detections/endpoint/registry_keys_for_creating_shim_databases.yml b/detections/endpoint/registry_keys_for_creating_shim_databases.yml index 12583e6efe..5d87f2c5a4 100644 --- a/detections/endpoint/registry_keys_for_creating_shim_databases.yml +++ b/detections/endpoint/registry_keys_for_creating_shim_databases.yml @@ -42,6 +42,7 @@ tags: $dest$ mitre_attack_id: - T1546.011 + - T1546 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 33f290cdd1..19cfceef0d 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -11,14 +11,13 @@ description: The search looks for modifications to registry keys that can be use search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* - OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* - OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* - OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* - OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* - OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows - NT\\CurrentVersion\\Image File Execution Options*" AND Registry.registry_key_name=Debugger) - OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" AND Registry.registry_key_name="Security - Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" + OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* + OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* + OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* + OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* + OR (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution + Options*" AND Registry.registry_key_name=Debugger) OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa" + AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\CurrentControlSet\\Control\\Lsa\\OSConfig" AND Registry.registry_key_name="Security Packages") OR (Registry.registry_path="*\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\*") OR (Registry.registry_path="*currentVersion\\Windows" AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion" @@ -64,6 +63,7 @@ tags: message: A registry activity in $registry_path$ related to persistence in host $dest$ mitre_attack_id: - T1547.001 + - T1547 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml index e91f558ec6..111952d065 100644 --- a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml +++ b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml @@ -47,6 +47,7 @@ tags: in host $dest$ mitre_attack_id: - T1546.012 + - T1546 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/regsvr32_silent_param_dll_loading.yml b/detections/endpoint/regsvr32_silent_param_dll_loading.yml index d27c7425aa..e985cf2b20 100644 --- a/detections/endpoint/regsvr32_silent_param_dll_loading.yml +++ b/detections/endpoint/regsvr32_silent_param_dll_loading.yml @@ -36,6 +36,7 @@ tags: - Exploitation mitre_attack_id: - T1218.010 + - T1218 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/rundll32_control_rundll_hunt.yml b/detections/endpoint/rundll32_control_rundll_hunt.yml index c9a4f1b93d..b990fc0ba0 100644 --- a/detections/endpoint/rundll32_control_rundll_hunt.yml +++ b/detections/endpoint/rundll32_control_rundll_hunt.yml @@ -51,6 +51,7 @@ tags: on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. mitre_attack_id: - T1218.011 + - T1218 observable: - name: user type: User diff --git a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml index b0f3f201d7..5a1ac0ee10 100644 --- a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml +++ b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml @@ -53,6 +53,7 @@ tags: on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. mitre_attack_id: - T1218.011 + - T1218 observable: - name: user type: User diff --git a/detections/endpoint/rundll32_dnsquery.yml b/detections/endpoint/rundll32_dnsquery.yml index ca03bace5f..4f554b2ad2 100644 --- a/detections/endpoint/rundll32_dnsquery.yml +++ b/detections/endpoint/rundll32_dnsquery.yml @@ -39,6 +39,7 @@ tags: $Computer$ mitre_attack_id: - T1218.011 + - T1218 observable: - name: Computer type: Hostname diff --git a/detections/endpoint/rundll32_lockworkstation.yml b/detections/endpoint/rundll32_lockworkstation.yml index e98876a8ed..232c2ac6d7 100644 --- a/detections/endpoint/rundll32_lockworkstation.yml +++ b/detections/endpoint/rundll32_lockworkstation.yml @@ -39,6 +39,7 @@ tags: message: process $process_name$ with cmdline $process$ in host $dest$ mitre_attack_id: - T1218.011 + - T1218 observable: - name: dest type: Hostname diff --git a/detections/endpoint/rundll32_process_creating_exe_dll_files.yml b/detections/endpoint/rundll32_process_creating_exe_dll_files.yml index 1a596c34d7..7a4fdfec85 100644 --- a/detections/endpoint/rundll32_process_creating_exe_dll_files.yml +++ b/detections/endpoint/rundll32_process_creating_exe_dll_files.yml @@ -37,6 +37,7 @@ tags: message: rundll32 process $process_name$ drops a file $TargetFilename$ in host $dest$ mitre_attack_id: - T1218.011 + - T1218 observable: - name: Computer type: Hostname diff --git a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml index e753e33958..708486231e 100644 --- a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml @@ -55,6 +55,7 @@ tags: process commandline $process$ in host $dest$ mitre_attack_id: - T1218.011 + - T1218 observable: - name: dest type: Hostname diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/endpoint/rundll_loading_dll_by_ordinal.yml index f60585c5a5..99ec2f277f 100644 --- a/detections/endpoint/rundll_loading_dll_by_ordinal.yml +++ b/detections/endpoint/rundll_loading_dll_by_ordinal.yml @@ -44,6 +44,7 @@ tags: commandline $process$ in host $dest$ mitre_attack_id: - T1218.011 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/ryuk_wake_on_lan_command.yml b/detections/endpoint/ryuk_wake_on_lan_command.yml index 63b690b819..3b1a5cde08 100644 --- a/detections/endpoint/ryuk_wake_on_lan_command.yml +++ b/detections/endpoint/ryuk_wake_on_lan_command.yml @@ -47,6 +47,7 @@ tags: $dest$ mitre_attack_id: - T1059.003 + - T1059 observable: - name: dest type: Hostname diff --git a/detections/endpoint/sam_database_file_access_attempt.yml b/detections/endpoint/sam_database_file_access_attempt.yml index fb1765f6ee..a082dff66f 100644 --- a/detections/endpoint/sam_database_file_access_attempt.yml +++ b/detections/endpoint/sam_database_file_access_attempt.yml @@ -42,6 +42,7 @@ tags: attempting to gain access to credentials on $dest$ by user $user$. mitre_attack_id: - T1003.002 + - T1003 observable: - name: user type: User diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index 85aa89544f..fe0205380e 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -49,6 +49,7 @@ tags: services in host $dest$ mitre_attack_id: - T1543.003 + - T1543 nist: - PR.IP - PR.PT diff --git a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml index 808d5a3886..d627f66d3c 100644 --- a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml +++ b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml @@ -45,6 +45,7 @@ tags: message: process $Image$ create a file $TargetFilename$ in host $Computer$ mitre_attack_id: - T1087.002 + - T1087 observable: - name: Computer type: Hostname diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index 44fa29fd2d..96a6b392d3 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -45,6 +45,7 @@ tags: $process$ in host $dest$ mitre_attack_id: - T1053.005 + - T1053 nist: - PR.IP observable: diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index 11bbb12a20..11496da387 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -46,6 +46,7 @@ tags: in host $dest$ mitre_attack_id: - T1053.005 + - T1053 nist: - PR.IP observable: diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index 8ee09e559f..c6fd3a72f5 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -45,6 +45,7 @@ tags: in host $dest$ mitre_attack_id: - T1053.005 + - T1053 nist: - PR.IP observable: diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml index 00b8914da3..1257a0a11e 100644 --- a/detections/endpoint/screensaver_event_trigger_execution.yml +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -37,6 +37,7 @@ tags: - Exploitation mitre_attack_id: - T1546.002 + - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/sdclt_uac_bypass.yml b/detections/endpoint/sdclt_uac_bypass.yml index 45477c7d1c..db3b46956c 100644 --- a/detections/endpoint/sdclt_uac_bypass.yml +++ b/detections/endpoint/sdclt_uac_bypass.yml @@ -44,6 +44,7 @@ tags: path $registry_value_name$ in $dest$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: dest type: Hostname diff --git a/detections/endpoint/sdelete_application_execution.yml b/detections/endpoint/sdelete_application_execution.yml index 0ded4ef8bc..ab0adf69cd 100644 --- a/detections/endpoint/sdelete_application_execution.yml +++ b/detections/endpoint/sdelete_application_execution.yml @@ -19,7 +19,11 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as Processes.dest Processes.user Processes.parent_process_name Processes.parent_process | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `sdelete_application_execution_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. known_false_positives: user may execute and use this application references: - https://app.any.run/tasks/956f50be-2c13-465a-ac00-6224c14c5f89/ @@ -33,6 +37,7 @@ tags: mitre_attack_id: - T1485 - T1070.004 + - T1070 product: - Splunk Enterprise - Splunk Enterprise Security @@ -41,11 +46,11 @@ tags: - _time - Processes.dest - Processes.user - - Processes.parent_process_name #parent process name - - Processes.parent_process #parent cmdline + - Processes.parent_process_name + - Processes.parent_process - Processes.original_file_name - - Processes.process_name #process name - - Processes.process #process cmdline + - Processes.process_name + - Processes.process - Processes.process_id - Processes.parent_process_path - Processes.process_path diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index 1c6c8d605f..e404794b9e 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -42,6 +42,7 @@ tags: to dump credentials in host $dest$ mitre_attack_id: - T1003.003 + - T1003 observable: - name: dest type: Hostname diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index 4a007740e3..72c1be9b45 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -47,6 +47,7 @@ tags: and reg value $registry_value_name$ in host $dest$ mitre_attack_id: - T1059.001 + - T1059 nist: - DE.CM observable: diff --git a/detections/endpoint/shim_database_file_creation.yml b/detections/endpoint/shim_database_file_creation.yml index e59f84bc50..a29923fe90 100644 --- a/detections/endpoint/shim_database_file_creation.yml +++ b/detections/endpoint/shim_database_file_creation.yml @@ -43,6 +43,7 @@ tags: message: A process that possibly write shim database in $file_path$ in host $dest$ mitre_attack_id: - T1546.011 + - T1546 nist: - DE.CM observable: diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index c2e6feecfd..6ac4dc6618 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -44,6 +44,7 @@ tags: $dest$ mitre_attack_id: - T1546.011 + - T1546 nist: - DE.CM observable: diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index bc0dfe52d2..41eaafaaab 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -40,6 +40,7 @@ tags: message: A user account created or delete shortly in host $dest$ mitre_attack_id: - T1136.001 + - T1136 nist: - PR.IP observable: diff --git a/detections/endpoint/silentcleanup_uac_bypass.yml b/detections/endpoint/silentcleanup_uac_bypass.yml index 61b5025568..bbd46535fb 100644 --- a/detections/endpoint/silentcleanup_uac_bypass.yml +++ b/detections/endpoint/silentcleanup_uac_bypass.yml @@ -42,6 +42,7 @@ tags: path $registry_value_name$ in $dest$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: dest type: Hostname diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index f09df3de5b..3ef19c46a8 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -41,6 +41,7 @@ tags: message: A suspicious process $process_name$ with single letter in host $dest$ mitre_attack_id: - T1204.002 + - T1204 nist: - ID.AM - PR.DS diff --git a/detections/endpoint/slui_runas_elevated.yml b/detections/endpoint/slui_runas_elevated.yml index 38830bc4cd..214b13ac1c 100644 --- a/detections/endpoint/slui_runas_elevated.yml +++ b/detections/endpoint/slui_runas_elevated.yml @@ -47,6 +47,7 @@ tags: $dest$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: dest type: Hostname diff --git a/detections/endpoint/slui_spawning_a_process.yml b/detections/endpoint/slui_spawning_a_process.yml index 579685a0e7..da332eedf0 100644 --- a/detections/endpoint/slui_spawning_a_process.yml +++ b/detections/endpoint/slui_spawning_a_process.yml @@ -45,6 +45,7 @@ tags: in host $dest$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: dest type: Hostname diff --git a/detections/endpoint/spoolsv_spawning_rundll32.yml b/detections/endpoint/spoolsv_spawning_rundll32.yml index 9fadebeb10..d60fa4a4f2 100644 --- a/detections/endpoint/spoolsv_spawning_rundll32.yml +++ b/detections/endpoint/spoolsv_spawning_rundll32.yml @@ -48,6 +48,7 @@ tags: This behavior is suspicious and related to PrintNightmare. mitre_attack_id: - T1547.012 + - T1547 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml index 0836ae7c82..85a54dbaed 100644 --- a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml +++ b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml @@ -39,6 +39,7 @@ tags: on endpoint $Computer$. This behavior is suspicious and related to PrintNightmare. mitre_attack_id: - T1547.012 + - T1547 observable: - name: Computer type: Endpoint diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml index afc4984e1c..cf7150056b 100644 --- a/detections/endpoint/spoolsv_writing_a_dll.yml +++ b/detections/endpoint/spoolsv_writing_a_dll.yml @@ -49,6 +49,7 @@ tags: $dest$. This behavior is suspicious and related to PrintNightmare. mitre_attack_id: - T1547.012 + - T1547 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml index a46a5d2e9f..540559a44a 100644 --- a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml +++ b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml @@ -45,6 +45,7 @@ tags: $dest$. This behavior is suspicious and related to PrintNightmare. mitre_attack_id: - T1547.012 + - T1547 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml index 8a6d6373f9..9d797b74ee 100644 --- a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml +++ b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml @@ -45,6 +45,7 @@ tags: via command $cmd_line$ mitre_attack_id: - T1003.003 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/ssa___detect_kerberoasting.yml b/detections/endpoint/ssa___detect_kerberoasting.yml index 63b1c8a188..79d5759281 100644 --- a/detections/endpoint/ssa___detect_kerberoasting.yml +++ b/detections/endpoint/ssa___detect_kerberoasting.yml @@ -47,6 +47,7 @@ tags: command $cmd_line$ mitre_attack_id: - T1558.003 + - T1558 nist: - DE.CM observable: diff --git a/detections/endpoint/ssa___detect_pass_hash.yml b/detections/endpoint/ssa___detect_pass_hash.yml index 2267f6ffcd..f18e5a0058 100644 --- a/detections/endpoint/ssa___detect_pass_hash.yml +++ b/detections/endpoint/ssa___detect_pass_hash.yml @@ -48,6 +48,7 @@ tags: via command $cmd_line$ mitre_attack_id: - T1550.002 + - T1550 nist: - PR.PT - PR.AT diff --git a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml index ab890a2895..b980fcd92c 100644 --- a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml +++ b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml @@ -64,6 +64,7 @@ tags: $dest_user_id$ and observed by the destination device $dest_device_id$ mitre_attack_id: - T1550.002 + - T1550 nist: - PR.PT - PR.AT diff --git a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml index 82a5385966..1c4dd950d4 100644 --- a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml +++ b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml @@ -66,6 +66,7 @@ tags: $dest_user_id$ and observed by the logging device $origin_device_id$ mitre_attack_id: - T1550.002 + - T1550 nist: - PR.PT - PR.AT diff --git a/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml index 0aa1b3fb6a..da8841f7af 100644 --- a/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml @@ -59,6 +59,7 @@ tags: - T1083 - T1518 - T1592.002 + - T1592 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml b/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml index 702f66a066..14690827dd 100644 --- a/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml @@ -47,6 +47,7 @@ tags: - T1021.002 - T1135 - T1039 + - T1021 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml index 4d72993fc4..84ef4d60e4 100644 --- a/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml @@ -51,6 +51,7 @@ tags: - T1021.002 - T1135 - T1039 + - T1021 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml index 085c118f58..a7f7b012bb 100644 --- a/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml @@ -51,6 +51,7 @@ tags: - T1021.002 - T1135 - T1039 + - T1021 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml b/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml index 5ab92c7f7a..c52a966f6f 100644 --- a/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml @@ -51,6 +51,9 @@ tags: - T1068 - T1078 - T1098 + - T1589 + - T1590 + - T1590 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml index 130cb2e20b..c686ef4204 100644 --- a/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml @@ -44,6 +44,8 @@ tags: mitre_attack_id: - T1595.002 - T1592.002 + - T1595 + - T1592 nist: - PR.AC - PR.IP diff --git a/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml b/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml index cc9ace99c4..6609a9d9cb 100644 --- a/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml +++ b/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml @@ -50,6 +50,7 @@ tags: event logs in host $dest_device_id$ mitre_attack_id: - T1070.001 + - T1070 observable: - name: dest_device_id type: Hostname diff --git a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml index 24431d68eb..35b1676175 100644 --- a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml +++ b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml @@ -46,6 +46,7 @@ tags: event logs in host $dest_device_id$ mitre_attack_id: - T1070.001 + - T1070 observable: - name: dest_device_id type: Hostname diff --git a/detections/endpoint/start_up_during_safe_mode_boot.yml b/detections/endpoint/start_up_during_safe_mode_boot.yml index 5f2664d98f..b4f49a32f1 100644 --- a/detections/endpoint/start_up_during_safe_mode_boot.yml +++ b/detections/endpoint/start_up_during_safe_mode_boot.yml @@ -41,6 +41,7 @@ tags: $registry_value_name$ on $dest$ mitre_attack_id: - T1547.001 + - T1547 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/suspicious_copy_on_system32.yml b/detections/endpoint/suspicious_copy_on_system32.yml index 3eb05fde0f..8e53a92099 100644 --- a/detections/endpoint/suspicious_copy_on_system32.yml +++ b/detections/endpoint/suspicious_copy_on_system32.yml @@ -13,12 +13,17 @@ description: This analytic is to detect a suspicious copy of file from systemroo but this is really a anomaly that needs to be check within the network. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name - IN("cmd.exe", "powershell*","pwsh.exe", "sqlps.exe", "sqltoolsps.exe", "powershell_ise.exe") AND `process_copy` AND Processes.process IN("*\\Windows\\System32\*", - "*\\Windows\\SysWow64\\*") AND Processes.process = "*copy*" by Processes.dest Processes.user - Processes.parent_process_name Processes.process_name Processes.process Processes.process_id - Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)`| `suspicious_copy_on_system32_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. + IN("cmd.exe", "powershell*","pwsh.exe", "sqlps.exe", "sqltoolsps.exe", "powershell_ise.exe") + AND `process_copy` AND Processes.process IN("*\\Windows\\System32\*", "*\\Windows\\SysWow64\\*") + AND Processes.process = "*copy*" by Processes.dest Processes.user Processes.parent_process_name + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| + `suspicious_copy_on_system32_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. known_false_positives: every user may do this event but very un-ussual. references: - https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120 @@ -31,6 +36,7 @@ tags: - Exploitation mitre_attack_id: - T1036.003 + - T1036 product: - Splunk Enterprise - Splunk Enterprise Security @@ -39,11 +45,11 @@ tags: - _time - Processes.dest - Processes.user - - Processes.parent_process_name #parent process name - - Processes.parent_process #parent cmdline + - Processes.parent_process_name + - Processes.parent_process - Processes.original_file_name - - Processes.process_name #process name - - Processes.process #process cmdline + - Processes.process_name + - Processes.process - Processes.process_id - Processes.parent_process_path - Processes.process_path diff --git a/detections/endpoint/suspicious_driver_loaded_path.yml b/detections/endpoint/suspicious_driver_loaded_path.yml index e9e8c99c7e..10a0bada0e 100644 --- a/detections/endpoint/suspicious_driver_loaded_path.yml +++ b/detections/endpoint/suspicious_driver_loaded_path.yml @@ -44,6 +44,7 @@ tags: message: Suspicious driver $ImageLoaded$ on $Computer$ mitre_attack_id: - T1543.003 + - T1543 observable: - name: Computer type: Endpoint diff --git a/detections/endpoint/suspicious_event_log_service_behavior.yml b/detections/endpoint/suspicious_event_log_service_behavior.yml index 4b2706e518..711154dccf 100644 --- a/detections/endpoint/suspicious_event_log_service_behavior.yml +++ b/detections/endpoint/suspicious_event_log_service_behavior.yml @@ -47,6 +47,7 @@ tags: message: The Windows Event Log Service shutdown on $ComputerName$ mitre_attack_id: - T1070.001 + - T1070 nist: - DE.DP - PR.IP diff --git a/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml b/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml index 198e2d21ea..223881e649 100644 --- a/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml +++ b/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml @@ -41,6 +41,7 @@ tags: message: regsvr32 process $process_name$ with commandline $process$ in host $dest$ mitre_attack_id: - T1218.010 + - T1218 observable: - name: dest type: Hostname diff --git a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml index fa8eb14e8d..5dd1f1bdc3 100644 --- a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml +++ b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml @@ -40,6 +40,7 @@ tags: message: rundll32 process $process_name$ with commandline $process$ in host $dest$ mitre_attack_id: - T1218.011 + - T1218 observable: - name: dest type: Hostname diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml index c1b68d43d2..615511455e 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml @@ -53,6 +53,7 @@ tags: mitre_attack_id: - T1127 - T1036.003 + - T1036 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml index ee399b0b5d..b8c944214a 100644 --- a/detections/endpoint/suspicious_msbuild_path.yml +++ b/detections/endpoint/suspicious_msbuild_path.yml @@ -53,6 +53,8 @@ tags: mitre_attack_id: - T1127.001 - T1036.003 + - T1127 + - T1036 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml index 973dbdaa07..f2891750df 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/endpoint/suspicious_msbuild_rename.yml @@ -51,6 +51,8 @@ tags: mitre_attack_id: - T1127.001 - T1036.003 + - T1127 + - T1036 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_msbuild_spawn.yml b/detections/endpoint/suspicious_msbuild_spawn.yml index c27f2512a0..6dd7d3a8e7 100644 --- a/detections/endpoint/suspicious_msbuild_spawn.yml +++ b/detections/endpoint/suspicious_msbuild_spawn.yml @@ -49,6 +49,7 @@ tags: message: Suspicious msbuild.exe process executed on $dest$ by $user$ mitre_attack_id: - T1127.001 + - T1127 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index 3c4d2ba9f1..f625d91f87 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -48,6 +48,7 @@ tags: message: suspicious mshta child process detected on host $dest$ by user $user$. mitre_attack_id: - T1218.005 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_mshta_spawn.yml b/detections/endpoint/suspicious_mshta_spawn.yml index 28fbd4aa7d..cec0d1c2db 100644 --- a/detections/endpoint/suspicious_mshta_spawn.yml +++ b/detections/endpoint/suspicious_mshta_spawn.yml @@ -47,6 +47,7 @@ tags: message: mshta.exe spawned by wmiprvse.exe on $dest$ mitre_attack_id: - T1218.005 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml index 6327c94cab..74347de490 100644 --- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml +++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml @@ -57,6 +57,7 @@ tags: malicious code mitre_attack_id: - T1218.010 + - T1218 nist: - DE.CM observable: diff --git a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml index 7116e1e610..a53412661e 100644 --- a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml +++ b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml @@ -56,6 +56,7 @@ tags: code mitre_attack_id: - T1218.011 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_rundll32_plugininit.yml b/detections/endpoint/suspicious_rundll32_plugininit.yml index 1f38049a11..7cdf4723e9 100644 --- a/detections/endpoint/suspicious_rundll32_plugininit.yml +++ b/detections/endpoint/suspicious_rundll32_plugininit.yml @@ -40,6 +40,7 @@ tags: message: rundll32 process $process_name$ with commandline $process$ in host $dest$ mitre_attack_id: - T1218.011 + - T1218 observable: - name: dest type: Hostname diff --git a/detections/endpoint/suspicious_rundll32_rename.yml b/detections/endpoint/suspicious_rundll32_rename.yml index 07c01a5c50..6b329e015a 100644 --- a/detections/endpoint/suspicious_rundll32_rename.yml +++ b/detections/endpoint/suspicious_rundll32_rename.yml @@ -52,6 +52,8 @@ tags: mitre_attack_id: - T1218.011 - T1036.003 + - T1218 + - T1036 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_rundll32_startw.yml b/detections/endpoint/suspicious_rundll32_startw.yml index 48a3a1d075..29aa9075d9 100644 --- a/detections/endpoint/suspicious_rundll32_startw.yml +++ b/detections/endpoint/suspicious_rundll32_startw.yml @@ -57,6 +57,7 @@ tags: message: rundll32.exe running with suspicious parameters on $dest$ mitre_attack_id: - T1218.011 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml b/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml index ab6536acaf..6a7727c7da 100644 --- a/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml @@ -53,6 +53,7 @@ tags: on $dest$ by $user$ mitre_attack_id: - T1218.011 + - T1218 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index efedc0b128..f27fec7309 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -47,6 +47,7 @@ tags: message: Suspicious scheduled task registered on $dest$ mitre_attack_id: - T1053.005 + - T1053 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index 4c32b8f3d4..1cf511bf39 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -7,15 +7,15 @@ type: TTP datamodel: - Endpoint description: The wevtutil.exe application is the windows event log utility. This searches - for wevtutil.exe with parameters for clearing the application, security, setup, trace - or system event logs. + for wevtutil.exe with parameters for clearing the application, security, setup, + trace or system event logs. search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where Processes.process_name=wevtutil.exe Processes.process IN ("* cl *", "*clear-log*") (Processes.process="*System*" - OR Processes.process="*Security*" OR Processes.process="*Setup*" OR Processes.process="*Application*" OR Processes.process="*trace*") - by Processes.process_name Processes.parent_process_name Processes.dest Processes.user| - `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` - | `suspicious_wevtutil_usage_filter`' + where Processes.process_name=wevtutil.exe Processes.process IN ("* cl *", "*clear-log*") + (Processes.process="*System*" OR Processes.process="*Security*" OR Processes.process="*Setup*" + OR Processes.process="*Application*" OR Processes.process="*trace*") by Processes.process_name + Processes.parent_process_name Processes.dest Processes.user| `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `suspicious_wevtutil_usage_filter`' how_to_implement: You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. @@ -24,7 +24,7 @@ how_to_implement: You must be ingesting data that records process activity from known_false_positives: The wevtutil.exe application is a legitimate Windows event log utility. Administrators may use it to manage Windows event logs. references: - - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md tags: analytic_story: - Windows Log Manipulation @@ -47,6 +47,7 @@ tags: message: Wevtutil.exe being used to clear Event Logs on $dest$ by $user$ mitre_attack_id: - T1070.001 + - T1070 nist: - DE.DP - PR.IP diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index b85a4a6084..96e027ffb1 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -54,6 +54,7 @@ tags: message: System process running from unexpected location on $dest$ mitre_attack_id: - T1036.003 + - T1036 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml index fcf99f419e..12ad4308ff 100644 --- a/detections/endpoint/time_provider_persistence_registry.yml +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -37,6 +37,7 @@ tags: - Exploitation mitre_attack_id: - T1547.003 + - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml b/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml index 1532a647be..6949009607 100644 --- a/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml +++ b/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml @@ -42,6 +42,7 @@ tags: with EventCode $EventCode$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: Computer type: Hostname diff --git a/detections/endpoint/uac_bypass_with_colorui_com_object.yml b/detections/endpoint/uac_bypass_with_colorui_com_object.yml index 84ce9eb604..82b188d113 100644 --- a/detections/endpoint/uac_bypass_with_colorui_com_object.yml +++ b/detections/endpoint/uac_bypass_with_colorui_com_object.yml @@ -38,6 +38,7 @@ tags: on endpoint $Computer$ by user $user$. mitre_attack_id: - T1218.003 + - T1218 observable: - name: user type: User diff --git a/detections/endpoint/uninstall_app_using_msiexec.yml b/detections/endpoint/uninstall_app_using_msiexec.yml index e3305b5e7e..fc2c1b0fec 100644 --- a/detections/endpoint/uninstall_app_using_msiexec.yml +++ b/detections/endpoint/uninstall_app_using_msiexec.yml @@ -39,6 +39,7 @@ tags: message: process $process_name$ with a cmdline $process$ in host $dest$ mitre_attack_id: - T1218.007 + - T1218 observable: - name: dest type: Hostname diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index 10c7e25200..a22640a966 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -43,6 +43,7 @@ tags: message: Possible Sysmon filter driver unloading on $dest$ mitre_attack_id: - T1562.001 + - T1562 nist: - DE.CM observable: diff --git a/detections/endpoint/vbscript_execution_using_wscript_app.yml b/detections/endpoint/vbscript_execution_using_wscript_app.yml index 5cb1e55d97..478aa9f2b4 100644 --- a/detections/endpoint/vbscript_execution_using_wscript_app.yml +++ b/detections/endpoint/vbscript_execution_using_wscript_app.yml @@ -18,7 +18,11 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `vbscript_execution_using_wscript_app_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. known_false_positives: unknown references: - https://www.joesandbox.com/analysis/369332/0/html @@ -32,6 +36,7 @@ tags: - Exploitation mitre_attack_id: - T1059.005 + - T1059 product: - Splunk Enterprise - Splunk Enterprise Security @@ -40,11 +45,11 @@ tags: - _time - Processes.dest - Processes.user - - Processes.parent_process_name #parent process name - - Processes.parent_process #parent cmdline + - Processes.parent_process_name + - Processes.parent_process - Processes.original_file_name - - Processes.process_name #process name - - Processes.process #process cmdline + - Processes.process_name + - Processes.process - Processes.process_id - Processes.parent_process_path - Processes.process_path diff --git a/detections/endpoint/verclsid_clsid_execution.yml b/detections/endpoint/verclsid_clsid_execution.yml index 556ef2e416..1d14188e12 100644 --- a/detections/endpoint/verclsid_clsid_execution.yml +++ b/detections/endpoint/verclsid_clsid_execution.yml @@ -19,7 +19,11 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as Processes.dest Processes.user Processes.parent_process_name Processes.parent_process | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `verclsid_clsid_execution_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. known_false_positives: windows can used this application for its normal COM object validation. references: @@ -34,6 +38,7 @@ tags: - Exploitation mitre_attack_id: - T1218.012 + - T1218 product: - Splunk Enterprise - Splunk Enterprise Security @@ -42,11 +47,11 @@ tags: - _time - Processes.dest - Processes.user - - Processes.parent_process_name #parent process name - - Processes.parent_process #parent cmdline + - Processes.parent_process_name + - Processes.parent_process - Processes.original_file_name - - Processes.process_name #process name - - Processes.process #process cmdline + - Processes.process_name + - Processes.process - Processes.process_id - Processes.parent_process_path - Processes.process_path diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml index ce8dcabe42..16930dbc8e 100644 --- a/detections/endpoint/w3wp_spawning_shell.yml +++ b/detections/endpoint/w3wp_spawning_shell.yml @@ -51,6 +51,7 @@ tags: message: Possible Web Shell execution on $dest$ mitre_attack_id: - T1505.003 + - T1505 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/wbemprox_com_object_execution.yml b/detections/endpoint/wbemprox_com_object_execution.yml index bfbff429fa..4c95fadc7c 100644 --- a/detections/endpoint/wbemprox_com_object_execution.yml +++ b/detections/endpoint/wbemprox_com_object_execution.yml @@ -39,6 +39,7 @@ tags: message: Suspicious COM Object Execution on $Computer$ mitre_attack_id: - T1218.003 + - T1218 observable: - name: Computer type: Endpoint diff --git a/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml b/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml index c93c9ea6e6..2ef303b5a7 100644 --- a/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml +++ b/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml @@ -45,6 +45,7 @@ tags: message: Wermgr.exe process connecting IP location web services on $ComputerName$ mitre_attack_id: - T1590.005 + - T1590 observable: - name: ComputerName type: Endpoint diff --git a/detections/endpoint/windows_disableantispyware_reg.yml b/detections/endpoint/windows_disableantispyware_reg.yml index 3388fb9e89..bb539c4ea0 100644 --- a/detections/endpoint/windows_disableantispyware_reg.yml +++ b/detections/endpoint/windows_disableantispyware_reg.yml @@ -46,6 +46,7 @@ tags: message: Windows DisableAntiSpyware registry key set to 'disabled' on $dest$ mitre_attack_id: - T1562.001 + - T1562 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/windows_event_log_cleared.yml b/detections/endpoint/windows_event_log_cleared.yml index b185e92dbd..e0c92a85bf 100644 --- a/detections/endpoint/windows_event_log_cleared.yml +++ b/detections/endpoint/windows_event_log_cleared.yml @@ -47,6 +47,7 @@ tags: message: Windows event logs cleared on $dest$ via EventCode $EventCode$ mitre_attack_id: - T1070.001 + - T1070 nist: - DE.DP - PR.IP diff --git a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml index e8d0ac5da9..3f135b0e36 100644 --- a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml +++ b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml @@ -62,6 +62,7 @@ tags: by the following command: $Command$' mitre_attack_id: - T1053.005 + - T1053 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml index c9f8a80525..b34070f242 100644 --- a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml +++ b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml @@ -63,6 +63,7 @@ tags: by the following command: $Command$' mitre_attack_id: - T1053.005 + - T1053 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/winword_spawning_cmd.yml b/detections/endpoint/winword_spawning_cmd.yml index 3be1953d5f..58e672c3da 100644 --- a/detections/endpoint/winword_spawning_cmd.yml +++ b/detections/endpoint/winword_spawning_cmd.yml @@ -46,6 +46,7 @@ tags: which is very common in spearphishing attacks.' mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/winword_spawning_powershell.yml b/detections/endpoint/winword_spawning_powershell.yml index 1ba0b16446..3a9a0f7d08 100644 --- a/detections/endpoint/winword_spawning_powershell.yml +++ b/detections/endpoint/winword_spawning_powershell.yml @@ -48,6 +48,7 @@ tags: process: $process_name$ which is very common in spearphishing attacks' mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/winword_spawning_windows_script_host.yml b/detections/endpoint/winword_spawning_windows_script_host.yml index 22493feea3..0a1092031f 100644 --- a/detections/endpoint/winword_spawning_windows_script_host.yml +++ b/detections/endpoint/winword_spawning_windows_script_host.yml @@ -45,6 +45,7 @@ tags: message: User $user$ on $dest$ spawned Windows Script Host from Winword.exe mitre_attack_id: - T1566.001 + - T1566 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml index 968baa4806..953a5e1593 100644 --- a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml +++ b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml @@ -61,6 +61,7 @@ tags: $filter$. Consumer: $Consumer$. EventCode: $EventCode$' mitre_attack_id: - T1546.003 + - T1546 nist: - PR.PT - PR.AT diff --git a/detections/endpoint/wmic_group_discovery.yml b/detections/endpoint/wmic_group_discovery.yml index ade199fd96..15979c5439 100644 --- a/detections/endpoint/wmic_group_discovery.yml +++ b/detections/endpoint/wmic_group_discovery.yml @@ -45,6 +45,7 @@ tags: message: Local group discovery on $dest$ by $user$. mitre_attack_id: - T1069.001 + - T1069 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/write_executable_in_smb_share.yml b/detections/endpoint/write_executable_in_smb_share.yml index 0465108fa9..bf7b25c2d2 100644 --- a/detections/endpoint/write_executable_in_smb_share.yml +++ b/detections/endpoint/write_executable_in_smb_share.yml @@ -39,6 +39,7 @@ tags: name=$Share_Name$, Target name=$Relative_Target_Name$, and Access mask=$Access_Mask$ mitre_attack_id: - T1021.002 + - T1021 observable: - name: user type: User diff --git a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml index 1d680f7db2..8642194ea4 100644 --- a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml +++ b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml @@ -41,6 +41,7 @@ tags: - T1055 - T1543 - T1134.004 + - T1134 product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,11 +50,11 @@ tags: - _time - Processes.dest - Processes.user - - Processes.parent_process_name #parent process name - - Processes.parent_process #parent cmdline + - Processes.parent_process_name + - Processes.parent_process - Processes.original_file_name - - Processes.process_name #process name - - Processes.process #process cmdline + - Processes.process_name + - Processes.process - Processes.process_id - Processes.parent_process_path - Processes.process_path diff --git a/detections/endpoint/wsreset_uac_bypass.yml b/detections/endpoint/wsreset_uac_bypass.yml index 5d2ab46587..6b4a5762ea 100644 --- a/detections/endpoint/wsreset_uac_bypass.yml +++ b/detections/endpoint/wsreset_uac_bypass.yml @@ -43,6 +43,7 @@ tags: path $registry_value_name$ in $dest$ mitre_attack_id: - T1548.002 + - T1548 observable: - name: dest type: Hostname diff --git a/detections/endpoint/xmrig_driver_loaded.yml b/detections/endpoint/xmrig_driver_loaded.yml index c3c9d278af..acadcdf186 100644 --- a/detections/endpoint/xmrig_driver_loaded.yml +++ b/detections/endpoint/xmrig_driver_loaded.yml @@ -36,6 +36,7 @@ tags: message: A driver $ImageLoaded$ related to xmrig crytominer loaded in host $Computer$ mitre_attack_id: - T1543.003 + - T1543 observable: - name: Computer type: Hostname