Update Analytics to Support ATT&CK v19 (#4036)

---------

Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
This commit is contained in:
Lou Stella
2026-05-05 11:29:28 -04:00
committed by GitHub
parent 917fe77cc0
commit 9c183fa110
192 changed files with 1381 additions and 1245 deletions
+1 -1
View File
@@ -22,7 +22,7 @@ jobs:
echo "- Contentctl version - $(cat requirements.txt)"
pip install -r requirements.txt
git clone --depth=1 --single-branch --branch=master https://github.com/redcanaryco/atomic-red-team.git external_repos/atomic-red-team
git clone --depth=1 --single-branch --branch="ATT&CK-v18.1" https://github.com/mitre/cti external_repos/cti
git clone --depth=1 --single-branch --branch="master" https://github.com/mitre-attack/attack-stix-data external_repos/cti
- name: Running appinspect with enrichments
env:
+1 -1
View File
@@ -22,7 +22,7 @@ jobs:
echo "- Contentctl version - $(cat requirements.txt)"
pip install -r requirements.txt
git clone --depth=1 --single-branch --branch=master https://github.com/redcanaryco/atomic-red-team.git external_repos/atomic-red-team
git clone --depth=1 --single-branch --branch="ATT&CK-v18.1" https://github.com/mitre/cti external_repos/cti
git clone --depth=1 --single-branch --branch="master" https://github.com/mitre-attack/attack-stix-data external_repos/cti
- name: Running build with enrichments
run: |
File diff suppressed because it is too large Load Diff
@@ -1,7 +1,7 @@
name: Cisco ASA - Core Syslog Message Volume Drop
id: 4b4f8fdd-1f9e-45d8-9b0f-1f64c0b297a4
version: 3
date: '2025-10-13'
version: 4
date: '2026-05-04'
author: Bhavin Patel, Micheal Haag, Splunk
status: production
type: Hunting
@@ -47,7 +47,7 @@ tags:
- ArcaneDoor
asset_type: Network
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Cisco ASA - Logging Disabled via CLI
id: 7b4c9f3e-5a88-4b7b-9c4b-94d8e5d67201
version: 6
date: '2026-04-15'
version: 7
date: '2026-05-04'
author: Bhavin Patel, Micheal Haag, Nasreddine Bencherchali, Splunk
status: production
type: TTP
@@ -72,7 +72,7 @@ tags:
- Suspicious Cisco Adaptive Security Appliance Activity
asset_type: Network
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Cisco ASA - Logging Filters Configuration Tampering
id: b87b48a8-6d1a-4280-9cf1-16a950dbf901
version: 4
date: '2026-04-15'
version: 5
date: '2026-05-04'
author: Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
@@ -83,7 +83,7 @@ tags:
- Suspicious Cisco Adaptive Security Appliance Activity
asset_type: Network
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Cisco ASA - Logging Message Suppression
id: 4e6c9d2a-8f3b-4c7e-9a5f-2d8b6e1c4a9f
version: 4
date: '2026-04-15'
version: 5
date: '2026-05-04'
author: Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
@@ -69,7 +69,7 @@ tags:
- ArcaneDoor
asset_type: Network
mitre_attack_id:
- T1562.002
- T1685.001
- T1070
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: ESXi Audit Tampering
id: c48a155b-2861-417a-813c-220f5272cf01
version: 3
date: '2026-04-15'
version: 4
date: '2026-05-04'
author: Raven Tait, Splunk
status: production
type: TTP
@@ -35,7 +35,7 @@ tags:
- Black Basta Ransomware
asset_type: Infrastructure
mitre_attack_id:
- T1562.003
- T1690
- T1070
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: ESXi Download Errors
id: 515cccd0-c4d8-4427-92d9-8a8f8b5a71dc
version: 3
date: '2026-04-15'
version: 4
date: '2026-05-04'
author: Raven Tait, Splunk
status: production
type: Anomaly
@@ -34,7 +34,7 @@ tags:
asset_type: Infrastructure
mitre_attack_id:
- T1601.001
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ESXi Encryption Settings Modified
id: dbbbe26f-83fe-4ee3-8b77-ccf7fbd416c8
version: 3
date: '2026-04-15'
version: 4
date: '2026-05-04'
author: Raven Tait, Splunk
status: production
type: TTP
@@ -33,7 +33,7 @@ tags:
- Black Basta Ransomware
asset_type: Infrastructure
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ESXi Firewall Disabled
id: e321804c-8eb5-42f2-a843-36b289a6c6b2
version: 4
date: '2026-04-15'
version: 5
date: '2026-05-04'
author: Raven Tait, Splunk
status: production
type: TTP
@@ -34,7 +34,7 @@ tags:
- China-Nexus Threat Activity
asset_type: Infrastructure
mitre_attack_id:
- T1562.004
- T1686
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ESXi Lockdown Mode Disabled
id: 07c0d28a-9a9b-409f-8d4b-65355bd19ead
version: 3
date: '2026-04-15'
version: 4
date: '2026-05-04'
author: Raven Tait, Splunk
status: production
type: TTP
@@ -33,7 +33,7 @@ tags:
- Black Basta Ransomware
asset_type: Infrastructure
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ESXi Loghost Config Tampering
id: 64bc2fa3-c493-44b4-8e94-3e5dbf71377e
version: 3
date: '2026-04-15'
version: 4
date: '2026-05-04'
author: Raven Tait, Splunk
status: production
type: TTP
@@ -33,7 +33,7 @@ tags:
- Black Basta Ransomware
asset_type: Infrastructure
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ESXi Syslog Config Change
id: e530beb9-9b8c-4c9b-9776-0a05521ff32d
version: 3
date: '2026-04-15'
version: 4
date: '2026-05-04'
author: Raven Tait, Splunk
status: production
type: TTP
@@ -33,7 +33,7 @@ tags:
- Black Basta Ransomware
asset_type: Infrastructure
mitre_attack_id:
- T1562.003
- T1690
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ESXi VIB Acceptance Level Tampering
id: d051d94f-c792-445e-b5d2-0b904f93ac09
version: 4
date: '2026-04-15'
version: 5
date: '2026-05-04'
author: Raven Tait, Splunk
status: production
type: TTP
@@ -37,7 +37,7 @@ tags:
- China-Nexus Threat Activity
asset_type: Infrastructure
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: M365 Copilot Agentic Jailbreak Attack
id: e5c7b380-19da-42e9-9e53-0af4cd27aee3
version: 3
date: '2026-04-15'
version: 4
date: '2026-05-04'
author: Rod Soto
status: experimental
type: Anomaly
@@ -9,17 +9,21 @@ data_source:
- M365 Exported eDiscovery Prompts
description: Detects agentic AI jailbreak attempts that try to establish persistent control over M365 Copilot through rule injection, universal triggers, response automation, system overrides, and persona establishment techniques. The detection analyzes the PromptText field for keywords like "from now on," "always respond," "ignore previous," "new rule," "override," and role-playing commands (e.g., "act as," "you are now") that attempt to inject persistent instructions. The search computes risk by counting distinct jailbreak indicators per user session, flagging coordinated manipulation attempts.
search: >
`m365_exported_ediscovery_prompt_logs`
| eval user = Sender
| eval rule_injection=if(match(Subject_Title, "(?i)(rules|instructions)\s*="), "YES", "NO")
| eval universal_trigger=if(match(Subject_Title, "(?i)(every|all).*prompt"), "YES", "NO")
| eval response_automation=if(match(Subject_Title, "(?i)(always|automatic).*respond"), "YES", "NO")
| eval system_override=if(match(Subject_Title, "(?i)(override|bypass|ignore).*(system|default)"), "YES", "NO")
| eval persona_establishment=if(match(Subject_Title, "(?i)(with.*\[.*\]|persona)"), "YES", "NO")
| where rule_injection="YES" OR universal_trigger="YES" OR response_automation="YES" OR system_override="YES" OR persona_establishment="YES"
| table _time, "Source ID", user, Subject_Title, rule_injection, universal_trigger, response_automation, system_override, persona_establishment, Workload
| sort -_time
| `m365_copilot_agentic_jailbreak_attack_filter`
`m365_exported_ediscovery_prompt_logs` | eval user = Sender | eval
rule_injection=if(match(Subject_Title, "(?i)(rules|instructions)\s*="), "YES",
"NO") | eval universal_trigger=if(match(Subject_Title,
"(?i)(every|all).*prompt"), "YES", "NO") | eval
response_automation=if(match(Subject_Title,
"(?i)(always|automatic).*respond"), "YES", "NO") | eval
system_override=if(match(Subject_Title,
"(?i)(override|bypass|ignore).*(system|default)"), "YES", "NO") | eval
persona_establishment=if(match(Subject_Title, "(?i)(with.*\[.*\]|persona)"),
"YES", "NO") | where rule_injection="YES" OR universal_trigger="YES" OR
response_automation="YES" OR system_override="YES" OR
persona_establishment="YES" | table _time, "Source ID", user, Subject_Title,
rule_injection, universal_trigger, response_automation, system_override,
persona_establishment, Workload | sort -_time |
`m365_copilot_agentic_jailbreak_attack_filter`
how_to_implement: To export M365 Copilot prompt logs, navigate to the Microsoft Purview compliance portal (compliance.microsoft.com) and access eDiscovery. Create a new eDiscovery case, add target user accounts or date ranges as data sources, then create a search query targeting M365 Copilot interactions across relevant workloads. Once the search completes, export the results to generate a package containing prompt logs with fields like Subject_Title (prompt text), Sender, timestamps, and workload metadata. Download the exported files using the eDiscovery Export Tool and ingest them into Splunk for security analysis and detection of jailbreak attempts, data exfiltration requests, and policy violations.
known_false_positives: Legitimate users discussing AI ethics research, security professionals testing system robustness, developers creating training materials for AI safety, or academic discussions about AI limitations and behavioral constraints may trigger false positives.
references:
@@ -45,7 +49,7 @@ tags:
- Suspicious Microsoft 365 Copilot Activities
asset_type: Web Application
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: M365 Copilot Impersonation Jailbreak Attack
id: cc26aba8-7f4a-4078-b91a-052d6a53cb13
version: 3
date: '2026-03-10'
version: 4
date: '2026-05-04'
author: Rod Soto
status: experimental
type: TTP
@@ -49,7 +49,7 @@ tags:
- Suspicious Microsoft 365 Copilot Activities
asset_type: Web Proxy
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: M365 Copilot Information Extraction Jailbreak Attack
id: c0ee37bb-ed43-4632-8e38-060fba80b0b2
version: 3
date: '2026-04-15'
version: 4
date: '2026-05-04'
author: Rod Soto
status: experimental
type: TTP
@@ -9,16 +9,52 @@ data_source:
- M365 Exported eDiscovery Prompts
description: Detects M365 Copilot information extraction jailbreak attacks that attempt to obtain sensitive, classified, or comprehensive data through various social engineering techniques including fictional entity impersonation, bulk data requests, and privacy bypass attempts. The detection searches exported eDiscovery prompt logs for extraction keywords like "transcendent," "tell me everything," "confidential," "dump," "extract," "reveal," and "bypass" in the Subject_Title field, categorizing each attempt by extraction type and assigning severity levels (CRITICAL for classified/proprietary data, HIGH for bulk extraction or privacy bypass). Prompts are further analyzed for compound risk patterns such as "Confidential+Extraction" or "Bulk_Request+Bypass," filtering out low-severity cases to surface the most dangerous attempts to exfiltrate sensitive organizational information through AI manipulation.
search: >
`m365_exported_ediscovery_prompt_logs`
| search Subject_Title="*transcendent*" OR Subject_Title="*incorporeal*" OR Subject_Title="*being who*" OR Subject_Title="*tell me everything*" OR Subject_Title="*give me all*" OR Subject_Title="*comprehensive*" OR Subject_Title="*step by step*" OR Subject_Title="*hidden*" OR Subject_Title="*secret*" OR Subject_Title="*confidential*" OR Subject_Title="*classified*" OR Subject_Title="*internal*" OR Subject_Title="*sensitive*" OR Subject_Title="*proprietary*" OR Subject_Title="*dump*" OR Subject_Title="*extract*" OR Subject_Title="*reveal*" OR Subject_Title="*disclose*" OR Subject_Title="*leak*"
| eval user = Sender
| eval extraction_type=case(match(Subject_Title, "(?i)(transcendent|incorporeal).*being"), "Knowledge_Entity", match(Subject_Title, "(?i)tell.*me.*(everything|all)"), "Everything_Request", match(Subject_Title, "(?i)(give|show|provide).*me.*(all|every)"), "Complete_Data_Request", match(Subject_Title, "(?i)(hidden|secret|confidential|classified)"), "Restricted_Info", match(Subject_Title, "(?i)(comprehensive|complete|full|entire)"), "Complete_Info", match(Subject_Title, "(?i)(dump|extract|scrape).*(data|info|content)"), "Data_Extraction", match(Subject_Title, "(?i)(reveal|disclose|expose|leak)"), "Information_Disclosure", match(Subject_Title, "(?i)(internal|proprietary|sensitive).*information"), "Sensitive_Data_Request", match(Subject_Title, "(?i)step.*by.*step.*(process|procedure|method)"), "Process_Extraction", match(Subject_Title, "(?i)(bypass|ignore).*privacy"), "Privacy_Bypass", match(Subject_Title, "(?i)(access|view|see).*(private|restricted)"), "Unauthorized_Access", 1=1, "Generic_Request")
| eval severity=case(match(Subject_Title, "(?i)(transcendent|incorporeal)"), "HIGH", match(Subject_Title, "(?i)tell.*everything"), "HIGH", match(Subject_Title, "(?i)(dump|extract|scrape)"), "HIGH", match(Subject_Title, "(?i)(classified|proprietary|confidential)"), "CRITICAL", match(Subject_Title, "(?i)(hidden|secret|internal|sensitive)"), "MEDIUM", match(Subject_Title, "(?i)(reveal|disclose|leak)"), "MEDIUM", match(Subject_Title, "(?i)(bypass|ignore).*privacy"), "HIGH", 1=1, "LOW")
| where severity!="LOW"
| eval data_risk_flags=case(match(Subject_Title, "(?i)(classified|confidential|proprietary)") AND match(Subject_Title, "(?i)(dump|extract|scrape)"), "Confidential+Extraction", match(Subject_Title, "(?i)(everything|all|complete)") AND match(Subject_Title, "(?i)(bypass|ignore)"), "Bulk_Request+Bypass", match(Subject_Title, "(?i)(classified|confidential|proprietary)"), "Confidential", match(Subject_Title, "(?i)(dump|extract|scrape)"), "Extraction", match(Subject_Title, "(?i)(everything|all|complete|comprehensive)"), "Bulk_Request", match(Subject_Title, "(?i)(bypass|ignore)"), "Bypass_Attempt", 1=1, "Standard_Request")
| table _time, user, Subject_Title, extraction_type, severity, data_risk_flags, Size
| sort -severity, -_time
| `m365_copilot_information_extraction_jailbreak_attack_filter`
`m365_exported_ediscovery_prompt_logs` | search Subject_Title="*transcendent*"
OR Subject_Title="*incorporeal*" OR Subject_Title="*being who*" OR
Subject_Title="*tell me everything*" OR Subject_Title="*give me all*" OR
Subject_Title="*comprehensive*" OR Subject_Title="*step by step*" OR
Subject_Title="*hidden*" OR Subject_Title="*secret*" OR
Subject_Title="*confidential*" OR Subject_Title="*classified*" OR
Subject_Title="*internal*" OR Subject_Title="*sensitive*" OR
Subject_Title="*proprietary*" OR Subject_Title="*dump*" OR
Subject_Title="*extract*" OR Subject_Title="*reveal*" OR
Subject_Title="*disclose*" OR Subject_Title="*leak*" | eval user = Sender |
eval extraction_type=case(match(Subject_Title,
"(?i)(transcendent|incorporeal).*being"), "Knowledge_Entity",
match(Subject_Title, "(?i)tell.*me.*(everything|all)"), "Everything_Request",
match(Subject_Title, "(?i)(give|show|provide).*me.*(all|every)"),
"Complete_Data_Request", match(Subject_Title,
"(?i)(hidden|secret|confidential|classified)"), "Restricted_Info",
match(Subject_Title, "(?i)(comprehensive|complete|full|entire)"),
"Complete_Info", match(Subject_Title,
"(?i)(dump|extract|scrape).*(data|info|content)"), "Data_Extraction",
match(Subject_Title, "(?i)(reveal|disclose|expose|leak)"),
"Information_Disclosure", match(Subject_Title,
"(?i)(internal|proprietary|sensitive).*information"),
"Sensitive_Data_Request", match(Subject_Title,
"(?i)step.*by.*step.*(process|procedure|method)"), "Process_Extraction",
match(Subject_Title, "(?i)(bypass|ignore).*privacy"), "Privacy_Bypass",
match(Subject_Title, "(?i)(access|view|see).*(private|restricted)"),
"Unauthorized_Access", 1=1, "Generic_Request") | eval
severity=case(match(Subject_Title, "(?i)(transcendent|incorporeal)"), "HIGH",
match(Subject_Title, "(?i)tell.*everything"), "HIGH", match(Subject_Title,
"(?i)(dump|extract|scrape)"), "HIGH", match(Subject_Title,
"(?i)(classified|proprietary|confidential)"), "CRITICAL", match(Subject_Title,
"(?i)(hidden|secret|internal|sensitive)"), "MEDIUM", match(Subject_Title,
"(?i)(reveal|disclose|leak)"), "MEDIUM", match(Subject_Title,
"(?i)(bypass|ignore).*privacy"), "HIGH", 1=1, "LOW") | where severity!="LOW" |
eval data_risk_flags=case(match(Subject_Title,
"(?i)(classified|confidential|proprietary)") AND match(Subject_Title,
"(?i)(dump|extract|scrape)"), "Confidential+Extraction", match(Subject_Title,
"(?i)(everything|all|complete)") AND match(Subject_Title,
"(?i)(bypass|ignore)"), "Bulk_Request+Bypass", match(Subject_Title,
"(?i)(classified|confidential|proprietary)"), "Confidential",
match(Subject_Title, "(?i)(dump|extract|scrape)"), "Extraction",
match(Subject_Title, "(?i)(everything|all|complete|comprehensive)"),
"Bulk_Request", match(Subject_Title, "(?i)(bypass|ignore)"), "Bypass_Attempt",
1=1, "Standard_Request") | table _time, user, Subject_Title, extraction_type,
severity, data_risk_flags, Size | sort -severity, -_time |
`m365_copilot_information_extraction_jailbreak_attack_filter`
how_to_implement: To export M365 Copilot prompt logs, navigate to the Microsoft Purview compliance portal (compliance.microsoft.com) and access eDiscovery. Create a new eDiscovery case, add target user accounts or date ranges as data sources, then create a search query targeting M365 Copilot interactions across relevant workloads. Once the search completes, export the results to generate a package containing prompt logs with fields like Subject_Title (prompt text), Sender, timestamps, and workload metadata. Download the exported files using the eDiscovery Export Tool and ingest them into Splunk for security analysis and detection of jailbreak attempts, data exfiltration requests, and policy violations.
known_false_positives: Legitimate researchers studying data classification systems, cybersecurity professionals testing information handling policies, compliance officers reviewing data access procedures, journalists researching transparency issues, or employees asking for comprehensive project documentation may trigger false positives.
references:
@@ -44,7 +80,7 @@ tags:
- Suspicious Microsoft 365 Copilot Activities
asset_type: Web Application
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: M365 Copilot Jailbreak Attempts
id: b05a4f25-e07d-436f-ab03-f954afa922c0
version: 4
date: '2026-04-15'
version: 5
date: '2026-05-04'
author: Rod Soto
status: experimental
type: Anomaly
@@ -54,7 +54,7 @@ tags:
- Suspicious Microsoft 365 Copilot Activities
asset_type: Web Application
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: M365 Copilot Non Compliant Devices Accessing M365 Copilot
id: e26bc52d-9cbc-4743-9745-e8781d935042
version: 4
date: '2026-04-15'
version: 5
date: '2026-05-04'
author: Rod Soto
status: production
type: Anomaly
@@ -43,7 +43,7 @@ tags:
- Suspicious Microsoft 365 Copilot Activities
asset_type: Web Application
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ASL AWS Defense Evasion Delete Cloudtrail
id: 1f0b47e5-0134-43eb-851c-e3258638945e
version: 12
date: '2026-04-15'
version: 13
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -46,7 +46,7 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ASL AWS Defense Evasion Delete CloudWatch Log Group
id: 0f701b38-a0fb-43fd-a83d-d12265f71f33
version: 11
date: '2026-04-15'
version: 12
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -46,7 +46,7 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ASL AWS Defense Evasion Impair Security Services
id: 5029b681-0462-47b7-82e7-f7e3d37f5a2d
version: 9
date: '2026-02-25'
version: 10
date: '2026-05-04'
author: Patrick Bareiss, Bhavin Patel, Gowthamaraj Rajendran, Splunk
status: production
type: Hunting
@@ -30,7 +30,7 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ASL AWS Defense Evasion PutBucketLifecycle
id: 986565a2-7707-48ea-9590-37929cebc938
version: 5
date: '2026-02-25'
version: 6
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Hunting
@@ -33,7 +33,7 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1485.001
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ASL AWS Defense Evasion Stop Logging Cloudtrail
id: 0b78a8f9-1d31-4d23-85c8-56ad13d5b4c1
version: 10
date: '2026-04-15'
version: 11
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -46,7 +46,7 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ASL AWS Defense Evasion Update Cloudtrail
id: f3eb471c-16d0-404d-897c-7653f0a78cba
version: 10
date: '2026-04-15'
version: 11
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -46,7 +46,7 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ASL AWS Network Access Control List Created with All Open Ports
id: a2625034-c2de-44fc-b45c-7bac9c4a7974
version: 7
date: '2026-04-15'
version: 8
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -52,7 +52,7 @@ tags:
- AWS Network ACL Activity
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- T1686.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ASL AWS Network Access Control List Deleted
id: e010ddf5-e9a5-44e5-bdd6-0c919ba8fc8b
version: 8
date: '2026-04-15'
version: 9
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -49,7 +49,7 @@ tags:
- Scattered Lapsus$ Hunters
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- T1686.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Bedrock Delete GuardRails
id: 7a5e3d62-f743-11ee-9f6e-acde48001122
version: 5
date: '2026-04-15'
version: 6
date: '2026-05-04'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -9,12 +9,12 @@ description: The following analytic identifies attempts to delete AWS Bedrock Gu
data_source:
- AWS CloudTrail DeleteGuardrail
search: >-
`cloudtrail` eventSource=bedrock.amazonaws.com eventName=DeleteGuardrail
| rename user_name as user
| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.guardrailIdentifier) as guardrailIds by src user user_agent vendor_account vendor_product dest signature vendor_region
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `aws_bedrock_delete_guardrails_filter`
`cloudtrail` eventSource=bedrock.amazonaws.com eventName=DeleteGuardrail |
rename user_name as user | stats count min(_time) as firstTime max(_time) as
lastTime values(requestParameters.guardrailIdentifier) as guardrailIds by src
user user_agent vendor_account vendor_product dest signature vendor_region |
`security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |
`aws_bedrock_delete_guardrails_filter`
how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search requires AWS CloudTrail logs with Bedrock service events enabled. You must install and configure the AWS App for Splunk (version 6.0.0 or later) and Splunk Add-on for AWS (version 5.1.0 or later) to collect CloudTrail logs from AWS. Ensure the CloudTrail is capturing Bedrock GuardRails management events.
known_false_positives: Legitimate administrators may delete GuardRails as part of normal operations, such as when replacing outdated guardrails with updated versions, cleaning up test resources, or consolidating security controls. Consider implementing an allowlist for expected administrators who regularly manage GuardRails configurations.
references:
@@ -44,7 +44,7 @@ tags:
- AWS Bedrock Security
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Bedrock Delete Model Invocation Logging Configuration
id: 9c5e3d62-f743-11ee-9f6e-acde48001124
version: 5
date: '2026-04-15'
version: 6
date: '2026-05-04'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -9,12 +9,12 @@ description: The following analytic identifies attempts to delete AWS Bedrock mo
data_source:
- AWS CloudTrail DeleteModelInvocationLoggingConfiguration
search: >-
`cloudtrail` eventSource=bedrock.amazonaws.com eventName=DeleteModelInvocationLoggingConfiguration
| rename user_name as user
| stats count min(_time) as firstTime max(_time) as lastTime by src user user_agent vendor_account vendor_product dest signature vendor_region
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `aws_bedrock_delete_model_invocation_logging_configuration_filter`
`cloudtrail` eventSource=bedrock.amazonaws.com
eventName=DeleteModelInvocationLoggingConfiguration | rename user_name as user
| stats count min(_time) as firstTime max(_time) as lastTime by src user
user_agent vendor_account vendor_product dest signature vendor_region |
`security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |
`aws_bedrock_delete_model_invocation_logging_configuration_filter`
how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search requires AWS CloudTrail logs with Bedrock service events enabled. You must install and configure the AWS App for Splunk (version 6.0.0 or later) and Splunk Add-on for AWS (version 5.1.0 or later) to collect CloudTrail logs from AWS. Ensure the CloudTrail is capturing Bedrock model invocation logging management events.
known_false_positives: Legitimate administrators may delete model invocation logging configurations during maintenance, when updating logging policies, or when cleaning up unused resources. Consider implementing an allowlist for expected administrators who regularly manage logging configurations.
references:
@@ -43,7 +43,7 @@ tags:
- AWS Bedrock Security
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Delete Cloudtrail
id: 82092925-9ca1-4e06-98b8-85a2d3889552
version: 10
date: '2026-04-15'
version: 11
date: '2026-05-04'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -45,7 +45,7 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Delete CloudWatch Log Group
id: d308b0f1-edb7-4a62-a614-af321160710f
version: 10
date: '2026-04-15'
version: 11
date: '2026-05-04'
author: Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -45,7 +45,7 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Impair Security Services
id: b28c4957-96a6-47e0-a965-6c767aac1458
version: 12
date: '2026-04-15'
version: 13
date: '2026-05-04'
author: Bhavin Patel, Gowthamaraj Rajendran, Splunk, PashFW, Github Community
status: production
type: TTP
@@ -52,7 +52,7 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Defense Evasion PutBucketLifecycle
id: ce1c0e2b-9303-4903-818b-0d9002fc6ea4
version: 8
date: '2026-02-25'
version: 9
date: '2026-05-04'
author: Bhavin Patel
status: production
type: Hunting
@@ -31,7 +31,7 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1485.001
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Stop Logging Cloudtrail
id: 8a2f3ca2-4eb5-4389-a549-14063882e537
version: 10
date: '2026-04-15'
version: 11
date: '2026-05-04'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -45,7 +45,7 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Update Cloudtrail
id: 7c921d28-ef48-4f1b-85b3-0af8af7697db
version: 10
date: '2026-04-15'
version: 11
date: '2026-05-04'
author: Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -45,7 +45,7 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Network Access Control List Created with All Open Ports
id: ada0f478-84a8-4641-a3f1-d82362d6bd75
version: 11
date: '2026-04-15'
version: 12
date: '2026-05-04'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: production
type: TTP
@@ -51,7 +51,7 @@ tags:
- AWS Network ACL Activity
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- T1686.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Network Access Control List Deleted
id: ada0f478-84a8-4641-a3f1-d82362d6fd75
version: 11
date: '2026-04-15'
version: 12
date: '2026-05-04'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -45,7 +45,7 @@ tags:
- AWS Network ACL Activity
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- T1686.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Azure AD Block User Consent For Risky Apps Disabled
id: 875de3d7-09bc-4916-8c0a-0929f4ced3d8
version: 11
date: '2026-04-15'
version: 12
date: '2026-05-04'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -37,7 +37,7 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Tenant
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: GitHub Enterprise Delete Branch Ruleset
id: 6169ea23-3719-439f-957a-0ea5174b70e2
version: 7
date: '2026-04-15'
version: 8
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -50,7 +50,7 @@ tags:
- NPM Supply Chain Compromise
asset_type: GitHub
mitre_attack_id:
- T1562.001
- T1685
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Enterprise Disable 2FA Requirement
id: 5a773226-ebd7-480c-a819-fccacfeddcd9
version: 6
date: '2026-04-15'
version: 7
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -47,7 +47,7 @@ tags:
- GitHub Malicious Activity
asset_type: GitHub
mitre_attack_id:
- T1562.001
- T1685
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Enterprise Disable Audit Log Event Stream
id: 7bc111cc-7f1b-4be7-99fa-50cf8d2e7564
version: 7
date: '2026-04-15'
version: 8
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -48,7 +48,7 @@ tags:
- NPM Supply Chain Compromise
asset_type: GitHub
mitre_attack_id:
- T1562.008
- T1685.002
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Enterprise Disable Classic Branch Protection Rule
id: 372176ba-450c-4abd-9b86-419bb44c1b76
version: 6
date: '2026-04-15'
version: 7
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -49,7 +49,7 @@ tags:
- GitHub Malicious Activity
asset_type: GitHub
mitre_attack_id:
- T1562.001
- T1685
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Enterprise Disable Dependabot
id: 787dd1c1-eb3a-4a31-8e8c-2ad24b214bc8
version: 6
date: '2026-04-15'
version: 7
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -48,7 +48,7 @@ tags:
- GitHub Malicious Activity
asset_type: GitHub
mitre_attack_id:
- T1562.001
- T1685
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Enterprise Disable IP Allow List
id: afed020e-edcd-4913-a675-cebedf81d4fb
version: 6
date: '2026-04-15'
version: 7
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -47,7 +47,7 @@ tags:
- GitHub Malicious Activity
asset_type: GitHub
mitre_attack_id:
- T1562.001
- T1685
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Enterprise Modify Audit Log Event Stream
id: 99abf2e1-863c-4ec6-82f8-714391590a4c
version: 7
date: '2026-04-15'
version: 8
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -48,7 +48,7 @@ tags:
- NPM Supply Chain Compromise
asset_type: GitHub
mitre_attack_id:
- T1562.008
- T1685.002
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Enterprise Pause Audit Log Event Stream
id: 21083dcb-276d-4ef9-8f7e-2113ca5e8094
version: 7
date: '2026-04-15'
version: 8
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -49,7 +49,7 @@ tags:
- NPM Supply Chain Compromise
asset_type: GitHub
mitre_attack_id:
- T1562.008
- T1685.002
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Enterprise Register Self Hosted Runner
id: b27685a2-8826-4123-ab78-2d9d0d419ed0
version: 7
date: '2026-04-15'
version: 8
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -49,7 +49,7 @@ tags:
- NPM Supply Chain Compromise
asset_type: GitHub
mitre_attack_id:
- T1562.001
- T1685
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Organizations Delete Branch Ruleset
id: 8e454f64-4bd6-45e6-8a94-1b482593d721
version: 8
date: '2026-04-15'
version: 9
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -50,7 +50,7 @@ tags:
- NPM Supply Chain Compromise
asset_type: GitHub
mitre_attack_id:
- T1562.001
- T1685
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Organizations Disable 2FA Requirement
id: 3ed0d6ba-4791-4fa8-a1ef-403e438c7033
version: 7
date: '2026-04-15'
version: 8
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -48,7 +48,7 @@ tags:
- GitHub Malicious Activity
asset_type: GitHub
mitre_attack_id:
- T1562.001
- T1685
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Organizations Disable Classic Branch Protection Rule
id: 33cffee0-41ee-402e-a238-d37825f2d788
version: 7
date: '2026-04-15'
version: 8
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -49,7 +49,7 @@ tags:
- GitHub Malicious Activity
asset_type: GitHub
mitre_attack_id:
- T1562.001
- T1685
- T1195
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: GitHub Organizations Disable Dependabot
id: 69078d8c-0de6-45de-bb00-14e78e042fd6
version: 7
date: '2026-04-15'
version: 8
date: '2026-05-04'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -48,7 +48,7 @@ tags:
- GitHub Malicious Activity
asset_type: GitHub
mitre_attack_id:
- T1562.001
- T1685
- T1195
product:
- Splunk Enterprise
@@ -1,27 +1,38 @@
name: Microsoft Intune DeviceManagementConfigurationPolicies
id: 3c49e5ed-625c-408c-a2c7-8e2b524efb2c
version: 3
date: '2026-02-25'
version: 4
date: '2026-05-04'
author: Dean Luxton
data_source:
- Azure Monitor Activity
type: Hunting
status: production
description: >-
Microsoft Intune device management configuration policies are a tool administrators can use to remotely manage policies and settings on intune managed devices.
This functionality can also be abused to disable defences & evade detection.
This detection identifies when a new device management configuration policy has been created.
Microsoft Intune device management configuration policies are a tool
administrators can use to remotely manage policies and settings on intune
managed devices. This functionality can also be abused to disable defences &
evade detection. This detection identifies when a new device management
configuration policy has been created.
search: >-
`azure_monitor_activity` operationName="* DeviceManagementConfigurationPolicy*"
| rename identity as user, properties.TargetObjectIds{} as TargetObjectId, properties.TargetDisplayNames{} as TargetDisplayName, properties.Actor.IsDelegatedAdmin as user_isDelegatedAdmin
| eval details=mvzip('properties.Targets{}.ModifiedProperties{}.Name','properties.Targets{}.ModifiedProperties{}.New',": ")
| rex field="operationName" "^(?P<action>\w+)\s" | replace "Patch" with "updated", "Create" with "created", "Delete", with "deleted", "assign", with "assigned" IN action
| eval action=if(match(operationName ,"Assignment$"),"assigned",'action')
| table _time operationName action user user_type user_isDelegatedAdmin TargetDisplayName TargetObjectId details status tenantId correlationId | `microsoft_intune_devicemanagementconfigurationpolicies_filter`
`azure_monitor_activity` operationName="*
DeviceManagementConfigurationPolicy*" | rename identity as user,
properties.TargetObjectIds{} as TargetObjectId,
properties.TargetDisplayNames{} as TargetDisplayName,
properties.Actor.IsDelegatedAdmin as user_isDelegatedAdmin | eval
details=mvzip('properties.Targets{}.ModifiedProperties{}.Name','properties.Targets{}.ModifiedProperties{}.New',":
") | rex field="operationName" "^(?P<action>\w+)\s" | replace "Patch" with
"updated", "Create" with "created", "Delete", with "deleted", "assign", with
"assigned" IN action | eval action=if(match(operationName
,"Assignment$"),"assigned",'action') | table _time operationName action user
user_type user_isDelegatedAdmin TargetDisplayName TargetObjectId details
status tenantId correlationId |
`microsoft_intune_devicemanagementconfigurationpolicies_filter`
how_to_implement: >-
The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub.
To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic settings & send events to the activity audit event hub.
Deploy as a risk based alerting rule for quick deployment or perform baselining & tune accordingly.
The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest
In-Tune audit logs via Azure EventHub. To configure this logging, visit Intune
> Tenant administration > Diagnostic settings > Add diagnostic settings & send
events to the activity audit event hub. Deploy as a risk based alerting rule
for quick deployment or perform baselining & tune accordingly.
known_false_positives: Legitimate adminstrative usage of this functionality will trigger this detection.
references:
- https://posts.specterops.io/death-from-above-lateral-movement-from-azure-to-on-prem-ad-d18cb3959d4d
@@ -35,8 +46,8 @@ tags:
- T1072
- T1484
- T1021.007
- T1562.001
- T1562.004
- T1685
- T1686
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: O365 Advanced Audit Disabled
id: 49862dd4-9cb2-4c48-a542-8c8a588d9361
version: 9
date: '2026-04-15'
version: 10
date: '2026-05-04'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
type: TTP
@@ -36,7 +36,7 @@ tags:
- Office 365 Persistence Mechanisms
asset_type: O365 Tenant
mitre_attack_id:
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: O365 Block User Consent For Risky Apps Disabled
id: 12a23592-e3da-4344-8545-205d3290647c
version: 8
date: '2026-04-15'
version: 9
date: '2026-05-04'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -38,7 +38,7 @@ tags:
asset_type: O365 Tenant
atomic_guid: []
mitre_attack_id:
- T1562
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: O365 Bypass MFA via Trusted IP
id: c783dd98-c703-4252-9e8a-f19d9f66949e
version: 11
date: '2026-04-15'
version: 12
date: '2026-05-04'
author: Bhavin Patel, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -36,7 +36,7 @@ tags:
- Office 365 Persistence Mechanisms
asset_type: O365 Tenant
mitre_attack_id:
- T1562.007
- T1686.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: O365 Email Security Feature Changed
id: 4d28013d-3a0f-4d65-a33f-4e8009fee0ae
version: 10
date: '2026-04-15'
version: 11
date: '2026-05-04'
author: Steven Dick
status: production
type: TTP
@@ -46,8 +46,7 @@ tags:
- Office 365 Account Takeover
asset_type: O365 Tenant
mitre_attack_id:
- T1562.001
- T1562.008
- T1685.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Processes launching netsh
id: b89919ed-fe5f-492c-b139-95dbb162040e
version: 14
date: '2026-03-26'
version: 15
date: '2026-05-04'
author: Michael Haag, Josef Kuepker, Splunk
status: deprecated
type: Anomaly
@@ -59,7 +59,7 @@ tags:
- Hellcat Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1562.004
- T1686
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Add or Set Windows Defender Exclusion
id: 773b66fe-4dd9-11ec-8289-acde48001122
version: 15
date: '2026-04-15'
version: 16
date: '2026-05-04'
author: Teoderick Contreras, Nasreddine Bencherchali, Splunk
status: production
type: TTP
@@ -91,7 +91,7 @@ tags:
- NetSupport RMM Tool Abuse
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Allow File And Printing Sharing In Firewall
id: ce27646e-d411-11eb-8a00-acde48001122
version: 13
date: '2026-04-15'
version: 14
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -58,7 +58,7 @@ tags:
- Hellcat Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1562.007
- T1686.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Allow Network Discovery In Firewall
id: ccd6a38c-d40b-11eb-85a5-acde48001122
version: 12
date: '2026-04-15'
version: 13
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -55,7 +55,7 @@ tags:
- Hellcat Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1562.007
- T1686.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable AMSI Through Registry
id: 9c27ec42-d338-11eb-9044-acde48001122
version: 13
date: '2026-04-15'
version: 14
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -37,7 +37,7 @@ tags:
- Windows Registry Abuse
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Defender AntiVirus Registry
id: aa4f695a-3024-11ec-9987-acde48001122
version: 16
date: '2026-04-15'
version: 17
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -42,7 +42,7 @@ tags:
- Cactus Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Defender BlockAtFirstSeen Feature
id: 2dd719ac-3021-11ec-97b4-acde48001122
version: 14
date: '2026-04-15'
version: 15
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -41,7 +41,7 @@ tags:
- Windows Registry Abuse
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Defender Enhanced Notification
id: dc65678c-301f-11ec-8e30-acde48001122
version: 13
date: '2026-04-15'
version: 14
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -40,7 +40,7 @@ tags:
- Windows Registry Abuse
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Defender MpEngine Registry
id: cc391750-3024-11ec-955a-acde48001122
version: 14
date: '2026-04-15'
version: 15
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -38,7 +38,7 @@ tags:
- Windows Registry Abuse
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Defender Spynet Reporting
id: 898debf4-3021-11ec-ba7c-acde48001122
version: 13
date: '2026-04-15'
version: 14
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -41,7 +41,7 @@ tags:
- CISA AA23-347A
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Defender Submit Samples Consent Feature
id: 73922ff8-3022-11ec-bf5e-acde48001122
version: 13
date: '2026-04-15'
version: 14
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -41,7 +41,7 @@ tags:
- BlankGrabber Stealer
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable ETW Through Registry
id: f0eacfa4-d33f-11eb-8f9d-acde48001122
version: 13
date: '2026-04-15'
version: 14
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -36,7 +36,7 @@ tags:
- Windows Registry Abuse
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Logs Using WevtUtil
id: 236e7c8e-c9d9-11eb-a824-acde48001122
version: 13
date: '2026-04-15'
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -55,7 +55,7 @@ tags:
- Rhysida Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1070.001
- T1685.005
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Registry Tool
id: cd2cf33c-9201-11eb-a10a-acde48001122
version: 15
date: '2026-04-15'
version: 16
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -37,7 +37,7 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1112
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Schedule Task
id: db596056-3019-11ec-a9ff-acde48001122
version: 11
date: '2026-04-15'
version: 12
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -50,7 +50,7 @@ tags:
- Living Off The Land
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Show Hidden Files
id: 6f3ccfa2-91fe-11eb-8f9b-acde48001122
version: 16
date: '2026-04-15'
version: 17
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: Anomaly
@@ -37,7 +37,7 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1112
- T1562.001
- T1685
- T1564.001
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Disable Windows App Hotkeys
id: 1490f224-ad8b-11eb-8c4f-acde48001122
version: 15
date: '2026-04-15'
version: 16
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -36,7 +36,7 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1112
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Windows Behavior Monitoring
id: 79439cae-9200-11eb-a4d3-acde48001122
version: 21
date: '2026-04-15'
version: 22
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -47,7 +47,7 @@ tags:
- BlankGrabber Stealer
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disable Windows SmartScreen Protection
id: 664f0fd0-91ff-11eb-a56f-acde48001122
version: 14
date: '2026-04-15'
version: 15
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -39,7 +39,7 @@ tags:
- Windows Registry Abuse
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disabling CMD Application
id: ff86077c-9212-11eb-a1e6-acde48001122
version: 15
date: '2026-04-15'
version: 16
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -40,7 +40,7 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1112
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disabling ControlPanel
id: 6ae0148e-9215-11eb-a94a-acde48001122
version: 15
date: '2026-04-15'
version: 16
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -39,7 +39,7 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1112
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disabling Defender Services
id: 911eacdc-317f-11ec-ad30-acde48001122
version: 13
date: '2026-04-15'
version: 14
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -39,7 +39,7 @@ tags:
- RedLine Stealer
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disabling Firewall with Netsh
id: 6860a62c-9203-11eb-9e05-acde48001122
version: 12
date: '2026-04-15'
version: 13
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -55,7 +55,7 @@ tags:
- BlackByte Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disabling FolderOptions Windows Feature
id: 83776de4-921a-11eb-868a-acde48001122
version: 14
date: '2026-04-15'
version: 15
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -39,7 +39,7 @@ tags:
- Windows Registry Abuse
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disabling NoRun Windows App
id: de81bc46-9213-11eb-adc9-acde48001122
version: 15
date: '2026-04-15'
version: 16
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -40,7 +40,7 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1112
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Disabling Task Manager
id: dac279bc-9202-11eb-b7fb-acde48001122
version: 14
date: '2026-04-15'
version: 15
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -40,7 +40,7 @@ tags:
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: ETW Registry Disabled
id: 8ed523ac-276b-11ec-ac39-acde48001122
version: 16
date: '2026-04-15'
version: 17
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -44,7 +44,7 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1127
- T1562.006
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Excessive number of service control start as disabled
id: 77592bec-d5cc-11eb-9e60-acde48001122
version: 11
date: '2026-04-15'
version: 12
date: '2026-05-04'
author: Michael Hart, Splunk
status: production
type: Anomaly
@@ -51,7 +51,7 @@ tags:
- Windows Defense Evasion Tactics
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Excessive Usage Of Taskkill
id: fe5bca48-accb-11eb-a67c-acde48001122
version: 12
date: '2026-04-15'
version: 13
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -55,7 +55,7 @@ tags:
- BlankGrabber Stealer
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Firewall Allowed Program Enable
id: 9a8f63a8-43ac-11ec-904c-acde48001122
version: 10
date: '2026-04-15'
version: 11
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -54,7 +54,7 @@ tags:
- Azorult
asset_type: Endpoint
mitre_attack_id:
- T1562.004
- T1686
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Hide User Account From Sign-In Screen
id: 834ba832-ad89-11eb-937d-acde48001122
version: 14
date: '2026-04-15'
version: 15
date: '2026-05-04'
author: Teoderick Contreras, Splunk, Steven Dick
status: production
type: TTP
@@ -42,7 +42,7 @@ tags:
- Warzone RAT
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Linux Auditd Auditd Daemon Abort
id: 76d6573f-c4ab-4fa1-8390-c036416d4add
version: 4
date: '2026-04-15'
version: 5
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -42,7 +42,7 @@ tags:
- Compromised Linux Host
asset_type: Endpoint
mitre_attack_id:
- T1562.012
- T1685.004
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Linux Auditd Auditd Daemon Shutdown
id: 6e2574b3-e24b-4321-ae3c-ba83a75bb714
version: 4
date: '2026-04-15'
version: 5
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -42,7 +42,7 @@ tags:
- Compromised Linux Host
asset_type: Endpoint
mitre_attack_id:
- T1562.012
- T1685.004
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Linux Auditd Auditd Daemon Start
id: 6b0cb0ff-9a7e-4475-a687-43827fdb31d6
version: 4
date: '2026-04-15'
version: 5
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -42,7 +42,7 @@ tags:
- Compromised Linux Host
asset_type: Endpoint
mitre_attack_id:
- T1562.012
- T1685.004
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Linux Auditd Disable Or Modify System Firewall
id: 07052556-d4b5-4bae-89aa-cbdc1bb11250
version: 10
date: '2026-04-15'
version: 11
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -45,7 +45,7 @@ tags:
- Compromised Linux Host
asset_type: Endpoint
mitre_attack_id:
- T1562.004
- T1686
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Linux Impair Defenses Process Kill
id: 435c6b33-adf9-47fe-be87-8e29fd6654f5
version: 9
date: '2026-02-25'
version: 10
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
@@ -33,7 +33,7 @@ tags:
- Scattered Lapsus$ Hunters
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Linux Iptables Firewall Modification
id: 309d59dc-1e1b-49b2-9800-7cf18d12f7b7
version: 14
date: '2026-04-15'
version: 15
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -69,7 +69,7 @@ tags:
- Sandworm Tools
asset_type: Endpoint
mitre_attack_id:
- T1562.004
- T1686
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Linux Stdout Redirection To Dev Null File
id: de62b809-a04d-46b5-9a15-8298d330f0c8
version: 12
date: '2026-04-15'
version: 13
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -50,7 +50,7 @@ tags:
- Industroyer2
asset_type: Endpoint
mitre_attack_id:
- T1562.004
- T1686
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: MSBuild Suspicious Spawned By Script Process
id: 213b3148-24ea-11ec-93a2-acde48001122
version: 11
date: '2026-04-15'
version: 12
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -1,7 +1,7 @@
name: Powershell Disable Security Monitoring
id: c148a894-dd93-11eb-bf2a-acde48001122
version: 14
date: '2026-04-15'
version: 15
date: '2026-05-04'
author: Michael Haag, Nasreddine Bencherchali, Splunk
status: production
type: TTP
@@ -115,7 +115,7 @@ tags:
- BlankGrabber Stealer
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Powershell Remove Windows Defender Directory
id: adf47620-79fa-11ec-b248-acde48001122
version: 14
date: '2026-04-15'
version: 15
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -38,7 +38,7 @@ tags:
- WhisperGate
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Powershell Windows Defender Exclusion Commands
id: 907ac95c-4dd9-11ec-ba2c-acde48001122
version: 13
date: '2026-04-15'
version: 14
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -58,7 +58,7 @@ tags:
- BlankGrabber Stealer
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Process Kill Base On File Path
id: 5ffaa42c-acdb-11eb-9ad3-acde48001122
version: 13
date: '2026-04-15'
version: 14
date: '2026-05-04'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -58,7 +58,7 @@ tags:
- XMRig
asset_type: Endpoint
mitre_attack_id:
- T1562.001
- T1685
product:
- Splunk Enterprise
- Splunk Enterprise Security

Some files were not shown because too many files have changed in this diff Show More