mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update Analytics to Support ATT&CK v19 (#4036)
--------- Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
This commit is contained in:
@@ -22,7 +22,7 @@ jobs:
|
||||
echo "- Contentctl version - $(cat requirements.txt)"
|
||||
pip install -r requirements.txt
|
||||
git clone --depth=1 --single-branch --branch=master https://github.com/redcanaryco/atomic-red-team.git external_repos/atomic-red-team
|
||||
git clone --depth=1 --single-branch --branch="ATT&CK-v18.1" https://github.com/mitre/cti external_repos/cti
|
||||
git clone --depth=1 --single-branch --branch="master" https://github.com/mitre-attack/attack-stix-data external_repos/cti
|
||||
|
||||
- name: Running appinspect with enrichments
|
||||
env:
|
||||
|
||||
@@ -22,7 +22,7 @@ jobs:
|
||||
echo "- Contentctl version - $(cat requirements.txt)"
|
||||
pip install -r requirements.txt
|
||||
git clone --depth=1 --single-branch --branch=master https://github.com/redcanaryco/atomic-red-team.git external_repos/atomic-red-team
|
||||
git clone --depth=1 --single-branch --branch="ATT&CK-v18.1" https://github.com/mitre/cti external_repos/cti
|
||||
git clone --depth=1 --single-branch --branch="master" https://github.com/mitre-attack/attack-stix-data external_repos/cti
|
||||
|
||||
- name: Running build with enrichments
|
||||
run: |
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -1,7 +1,7 @@
|
||||
name: Cisco ASA - Core Syslog Message Volume Drop
|
||||
id: 4b4f8fdd-1f9e-45d8-9b0f-1f64c0b297a4
|
||||
version: 3
|
||||
date: '2025-10-13'
|
||||
version: 4
|
||||
date: '2026-05-04'
|
||||
author: Bhavin Patel, Micheal Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -47,7 +47,7 @@ tags:
|
||||
- ArcaneDoor
|
||||
asset_type: Network
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Cisco ASA - Logging Disabled via CLI
|
||||
id: 7b4c9f3e-5a88-4b7b-9c4b-94d8e5d67201
|
||||
version: 6
|
||||
date: '2026-04-15'
|
||||
version: 7
|
||||
date: '2026-05-04'
|
||||
author: Bhavin Patel, Micheal Haag, Nasreddine Bencherchali, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -72,7 +72,7 @@ tags:
|
||||
- Suspicious Cisco Adaptive Security Appliance Activity
|
||||
asset_type: Network
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Cisco ASA - Logging Filters Configuration Tampering
|
||||
id: b87b48a8-6d1a-4280-9cf1-16a950dbf901
|
||||
version: 4
|
||||
date: '2026-04-15'
|
||||
version: 5
|
||||
date: '2026-05-04'
|
||||
author: Nasreddine Bencherchali, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -83,7 +83,7 @@ tags:
|
||||
- Suspicious Cisco Adaptive Security Appliance Activity
|
||||
asset_type: Network
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Cisco ASA - Logging Message Suppression
|
||||
id: 4e6c9d2a-8f3b-4c7e-9a5f-2d8b6e1c4a9f
|
||||
version: 4
|
||||
date: '2026-04-15'
|
||||
version: 5
|
||||
date: '2026-05-04'
|
||||
author: Nasreddine Bencherchali, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -69,7 +69,7 @@ tags:
|
||||
- ArcaneDoor
|
||||
asset_type: Network
|
||||
mitre_attack_id:
|
||||
- T1562.002
|
||||
- T1685.001
|
||||
- T1070
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ESXi Audit Tampering
|
||||
id: c48a155b-2861-417a-813c-220f5272cf01
|
||||
version: 3
|
||||
date: '2026-04-15'
|
||||
version: 4
|
||||
date: '2026-05-04'
|
||||
author: Raven Tait, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -35,7 +35,7 @@ tags:
|
||||
- Black Basta Ransomware
|
||||
asset_type: Infrastructure
|
||||
mitre_attack_id:
|
||||
- T1562.003
|
||||
- T1690
|
||||
- T1070
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ESXi Download Errors
|
||||
id: 515cccd0-c4d8-4427-92d9-8a8f8b5a71dc
|
||||
version: 3
|
||||
date: '2026-04-15'
|
||||
version: 4
|
||||
date: '2026-05-04'
|
||||
author: Raven Tait, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -34,7 +34,7 @@ tags:
|
||||
asset_type: Infrastructure
|
||||
mitre_attack_id:
|
||||
- T1601.001
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ESXi Encryption Settings Modified
|
||||
id: dbbbe26f-83fe-4ee3-8b77-ccf7fbd416c8
|
||||
version: 3
|
||||
date: '2026-04-15'
|
||||
version: 4
|
||||
date: '2026-05-04'
|
||||
author: Raven Tait, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -33,7 +33,7 @@ tags:
|
||||
- Black Basta Ransomware
|
||||
asset_type: Infrastructure
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ESXi Firewall Disabled
|
||||
id: e321804c-8eb5-42f2-a843-36b289a6c6b2
|
||||
version: 4
|
||||
date: '2026-04-15'
|
||||
version: 5
|
||||
date: '2026-05-04'
|
||||
author: Raven Tait, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -34,7 +34,7 @@ tags:
|
||||
- China-Nexus Threat Activity
|
||||
asset_type: Infrastructure
|
||||
mitre_attack_id:
|
||||
- T1562.004
|
||||
- T1686
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ESXi Lockdown Mode Disabled
|
||||
id: 07c0d28a-9a9b-409f-8d4b-65355bd19ead
|
||||
version: 3
|
||||
date: '2026-04-15'
|
||||
version: 4
|
||||
date: '2026-05-04'
|
||||
author: Raven Tait, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -33,7 +33,7 @@ tags:
|
||||
- Black Basta Ransomware
|
||||
asset_type: Infrastructure
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ESXi Loghost Config Tampering
|
||||
id: 64bc2fa3-c493-44b4-8e94-3e5dbf71377e
|
||||
version: 3
|
||||
date: '2026-04-15'
|
||||
version: 4
|
||||
date: '2026-05-04'
|
||||
author: Raven Tait, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -33,7 +33,7 @@ tags:
|
||||
- Black Basta Ransomware
|
||||
asset_type: Infrastructure
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ESXi Syslog Config Change
|
||||
id: e530beb9-9b8c-4c9b-9776-0a05521ff32d
|
||||
version: 3
|
||||
date: '2026-04-15'
|
||||
version: 4
|
||||
date: '2026-05-04'
|
||||
author: Raven Tait, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -33,7 +33,7 @@ tags:
|
||||
- Black Basta Ransomware
|
||||
asset_type: Infrastructure
|
||||
mitre_attack_id:
|
||||
- T1562.003
|
||||
- T1690
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ESXi VIB Acceptance Level Tampering
|
||||
id: d051d94f-c792-445e-b5d2-0b904f93ac09
|
||||
version: 4
|
||||
date: '2026-04-15'
|
||||
version: 5
|
||||
date: '2026-05-04'
|
||||
author: Raven Tait, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -37,7 +37,7 @@ tags:
|
||||
- China-Nexus Threat Activity
|
||||
asset_type: Infrastructure
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: M365 Copilot Agentic Jailbreak Attack
|
||||
id: e5c7b380-19da-42e9-9e53-0af4cd27aee3
|
||||
version: 3
|
||||
date: '2026-04-15'
|
||||
version: 4
|
||||
date: '2026-05-04'
|
||||
author: Rod Soto
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
@@ -9,17 +9,21 @@ data_source:
|
||||
- M365 Exported eDiscovery Prompts
|
||||
description: Detects agentic AI jailbreak attempts that try to establish persistent control over M365 Copilot through rule injection, universal triggers, response automation, system overrides, and persona establishment techniques. The detection analyzes the PromptText field for keywords like "from now on," "always respond," "ignore previous," "new rule," "override," and role-playing commands (e.g., "act as," "you are now") that attempt to inject persistent instructions. The search computes risk by counting distinct jailbreak indicators per user session, flagging coordinated manipulation attempts.
|
||||
search: >
|
||||
`m365_exported_ediscovery_prompt_logs`
|
||||
| eval user = Sender
|
||||
| eval rule_injection=if(match(Subject_Title, "(?i)(rules|instructions)\s*="), "YES", "NO")
|
||||
| eval universal_trigger=if(match(Subject_Title, "(?i)(every|all).*prompt"), "YES", "NO")
|
||||
| eval response_automation=if(match(Subject_Title, "(?i)(always|automatic).*respond"), "YES", "NO")
|
||||
| eval system_override=if(match(Subject_Title, "(?i)(override|bypass|ignore).*(system|default)"), "YES", "NO")
|
||||
| eval persona_establishment=if(match(Subject_Title, "(?i)(with.*\[.*\]|persona)"), "YES", "NO")
|
||||
| where rule_injection="YES" OR universal_trigger="YES" OR response_automation="YES" OR system_override="YES" OR persona_establishment="YES"
|
||||
| table _time, "Source ID", user, Subject_Title, rule_injection, universal_trigger, response_automation, system_override, persona_establishment, Workload
|
||||
| sort -_time
|
||||
| `m365_copilot_agentic_jailbreak_attack_filter`
|
||||
`m365_exported_ediscovery_prompt_logs` | eval user = Sender | eval
|
||||
rule_injection=if(match(Subject_Title, "(?i)(rules|instructions)\s*="), "YES",
|
||||
"NO") | eval universal_trigger=if(match(Subject_Title,
|
||||
"(?i)(every|all).*prompt"), "YES", "NO") | eval
|
||||
response_automation=if(match(Subject_Title,
|
||||
"(?i)(always|automatic).*respond"), "YES", "NO") | eval
|
||||
system_override=if(match(Subject_Title,
|
||||
"(?i)(override|bypass|ignore).*(system|default)"), "YES", "NO") | eval
|
||||
persona_establishment=if(match(Subject_Title, "(?i)(with.*\[.*\]|persona)"),
|
||||
"YES", "NO") | where rule_injection="YES" OR universal_trigger="YES" OR
|
||||
response_automation="YES" OR system_override="YES" OR
|
||||
persona_establishment="YES" | table _time, "Source ID", user, Subject_Title,
|
||||
rule_injection, universal_trigger, response_automation, system_override,
|
||||
persona_establishment, Workload | sort -_time |
|
||||
`m365_copilot_agentic_jailbreak_attack_filter`
|
||||
how_to_implement: To export M365 Copilot prompt logs, navigate to the Microsoft Purview compliance portal (compliance.microsoft.com) and access eDiscovery. Create a new eDiscovery case, add target user accounts or date ranges as data sources, then create a search query targeting M365 Copilot interactions across relevant workloads. Once the search completes, export the results to generate a package containing prompt logs with fields like Subject_Title (prompt text), Sender, timestamps, and workload metadata. Download the exported files using the eDiscovery Export Tool and ingest them into Splunk for security analysis and detection of jailbreak attempts, data exfiltration requests, and policy violations.
|
||||
known_false_positives: Legitimate users discussing AI ethics research, security professionals testing system robustness, developers creating training materials for AI safety, or academic discussions about AI limitations and behavioral constraints may trigger false positives.
|
||||
references:
|
||||
@@ -45,7 +49,7 @@ tags:
|
||||
- Suspicious Microsoft 365 Copilot Activities
|
||||
asset_type: Web Application
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: M365 Copilot Impersonation Jailbreak Attack
|
||||
id: cc26aba8-7f4a-4078-b91a-052d6a53cb13
|
||||
version: 3
|
||||
date: '2026-03-10'
|
||||
version: 4
|
||||
date: '2026-05-04'
|
||||
author: Rod Soto
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -49,7 +49,7 @@ tags:
|
||||
- Suspicious Microsoft 365 Copilot Activities
|
||||
asset_type: Web Proxy
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: M365 Copilot Information Extraction Jailbreak Attack
|
||||
id: c0ee37bb-ed43-4632-8e38-060fba80b0b2
|
||||
version: 3
|
||||
date: '2026-04-15'
|
||||
version: 4
|
||||
date: '2026-05-04'
|
||||
author: Rod Soto
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -9,16 +9,52 @@ data_source:
|
||||
- M365 Exported eDiscovery Prompts
|
||||
description: Detects M365 Copilot information extraction jailbreak attacks that attempt to obtain sensitive, classified, or comprehensive data through various social engineering techniques including fictional entity impersonation, bulk data requests, and privacy bypass attempts. The detection searches exported eDiscovery prompt logs for extraction keywords like "transcendent," "tell me everything," "confidential," "dump," "extract," "reveal," and "bypass" in the Subject_Title field, categorizing each attempt by extraction type and assigning severity levels (CRITICAL for classified/proprietary data, HIGH for bulk extraction or privacy bypass). Prompts are further analyzed for compound risk patterns such as "Confidential+Extraction" or "Bulk_Request+Bypass," filtering out low-severity cases to surface the most dangerous attempts to exfiltrate sensitive organizational information through AI manipulation.
|
||||
search: >
|
||||
`m365_exported_ediscovery_prompt_logs`
|
||||
| search Subject_Title="*transcendent*" OR Subject_Title="*incorporeal*" OR Subject_Title="*being who*" OR Subject_Title="*tell me everything*" OR Subject_Title="*give me all*" OR Subject_Title="*comprehensive*" OR Subject_Title="*step by step*" OR Subject_Title="*hidden*" OR Subject_Title="*secret*" OR Subject_Title="*confidential*" OR Subject_Title="*classified*" OR Subject_Title="*internal*" OR Subject_Title="*sensitive*" OR Subject_Title="*proprietary*" OR Subject_Title="*dump*" OR Subject_Title="*extract*" OR Subject_Title="*reveal*" OR Subject_Title="*disclose*" OR Subject_Title="*leak*"
|
||||
| eval user = Sender
|
||||
| eval extraction_type=case(match(Subject_Title, "(?i)(transcendent|incorporeal).*being"), "Knowledge_Entity", match(Subject_Title, "(?i)tell.*me.*(everything|all)"), "Everything_Request", match(Subject_Title, "(?i)(give|show|provide).*me.*(all|every)"), "Complete_Data_Request", match(Subject_Title, "(?i)(hidden|secret|confidential|classified)"), "Restricted_Info", match(Subject_Title, "(?i)(comprehensive|complete|full|entire)"), "Complete_Info", match(Subject_Title, "(?i)(dump|extract|scrape).*(data|info|content)"), "Data_Extraction", match(Subject_Title, "(?i)(reveal|disclose|expose|leak)"), "Information_Disclosure", match(Subject_Title, "(?i)(internal|proprietary|sensitive).*information"), "Sensitive_Data_Request", match(Subject_Title, "(?i)step.*by.*step.*(process|procedure|method)"), "Process_Extraction", match(Subject_Title, "(?i)(bypass|ignore).*privacy"), "Privacy_Bypass", match(Subject_Title, "(?i)(access|view|see).*(private|restricted)"), "Unauthorized_Access", 1=1, "Generic_Request")
|
||||
| eval severity=case(match(Subject_Title, "(?i)(transcendent|incorporeal)"), "HIGH", match(Subject_Title, "(?i)tell.*everything"), "HIGH", match(Subject_Title, "(?i)(dump|extract|scrape)"), "HIGH", match(Subject_Title, "(?i)(classified|proprietary|confidential)"), "CRITICAL", match(Subject_Title, "(?i)(hidden|secret|internal|sensitive)"), "MEDIUM", match(Subject_Title, "(?i)(reveal|disclose|leak)"), "MEDIUM", match(Subject_Title, "(?i)(bypass|ignore).*privacy"), "HIGH", 1=1, "LOW")
|
||||
| where severity!="LOW"
|
||||
| eval data_risk_flags=case(match(Subject_Title, "(?i)(classified|confidential|proprietary)") AND match(Subject_Title, "(?i)(dump|extract|scrape)"), "Confidential+Extraction", match(Subject_Title, "(?i)(everything|all|complete)") AND match(Subject_Title, "(?i)(bypass|ignore)"), "Bulk_Request+Bypass", match(Subject_Title, "(?i)(classified|confidential|proprietary)"), "Confidential", match(Subject_Title, "(?i)(dump|extract|scrape)"), "Extraction", match(Subject_Title, "(?i)(everything|all|complete|comprehensive)"), "Bulk_Request", match(Subject_Title, "(?i)(bypass|ignore)"), "Bypass_Attempt", 1=1, "Standard_Request")
|
||||
| table _time, user, Subject_Title, extraction_type, severity, data_risk_flags, Size
|
||||
| sort -severity, -_time
|
||||
| `m365_copilot_information_extraction_jailbreak_attack_filter`
|
||||
`m365_exported_ediscovery_prompt_logs` | search Subject_Title="*transcendent*"
|
||||
OR Subject_Title="*incorporeal*" OR Subject_Title="*being who*" OR
|
||||
Subject_Title="*tell me everything*" OR Subject_Title="*give me all*" OR
|
||||
Subject_Title="*comprehensive*" OR Subject_Title="*step by step*" OR
|
||||
Subject_Title="*hidden*" OR Subject_Title="*secret*" OR
|
||||
Subject_Title="*confidential*" OR Subject_Title="*classified*" OR
|
||||
Subject_Title="*internal*" OR Subject_Title="*sensitive*" OR
|
||||
Subject_Title="*proprietary*" OR Subject_Title="*dump*" OR
|
||||
Subject_Title="*extract*" OR Subject_Title="*reveal*" OR
|
||||
Subject_Title="*disclose*" OR Subject_Title="*leak*" | eval user = Sender |
|
||||
eval extraction_type=case(match(Subject_Title,
|
||||
"(?i)(transcendent|incorporeal).*being"), "Knowledge_Entity",
|
||||
match(Subject_Title, "(?i)tell.*me.*(everything|all)"), "Everything_Request",
|
||||
match(Subject_Title, "(?i)(give|show|provide).*me.*(all|every)"),
|
||||
"Complete_Data_Request", match(Subject_Title,
|
||||
"(?i)(hidden|secret|confidential|classified)"), "Restricted_Info",
|
||||
match(Subject_Title, "(?i)(comprehensive|complete|full|entire)"),
|
||||
"Complete_Info", match(Subject_Title,
|
||||
"(?i)(dump|extract|scrape).*(data|info|content)"), "Data_Extraction",
|
||||
match(Subject_Title, "(?i)(reveal|disclose|expose|leak)"),
|
||||
"Information_Disclosure", match(Subject_Title,
|
||||
"(?i)(internal|proprietary|sensitive).*information"),
|
||||
"Sensitive_Data_Request", match(Subject_Title,
|
||||
"(?i)step.*by.*step.*(process|procedure|method)"), "Process_Extraction",
|
||||
match(Subject_Title, "(?i)(bypass|ignore).*privacy"), "Privacy_Bypass",
|
||||
match(Subject_Title, "(?i)(access|view|see).*(private|restricted)"),
|
||||
"Unauthorized_Access", 1=1, "Generic_Request") | eval
|
||||
severity=case(match(Subject_Title, "(?i)(transcendent|incorporeal)"), "HIGH",
|
||||
match(Subject_Title, "(?i)tell.*everything"), "HIGH", match(Subject_Title,
|
||||
"(?i)(dump|extract|scrape)"), "HIGH", match(Subject_Title,
|
||||
"(?i)(classified|proprietary|confidential)"), "CRITICAL", match(Subject_Title,
|
||||
"(?i)(hidden|secret|internal|sensitive)"), "MEDIUM", match(Subject_Title,
|
||||
"(?i)(reveal|disclose|leak)"), "MEDIUM", match(Subject_Title,
|
||||
"(?i)(bypass|ignore).*privacy"), "HIGH", 1=1, "LOW") | where severity!="LOW" |
|
||||
eval data_risk_flags=case(match(Subject_Title,
|
||||
"(?i)(classified|confidential|proprietary)") AND match(Subject_Title,
|
||||
"(?i)(dump|extract|scrape)"), "Confidential+Extraction", match(Subject_Title,
|
||||
"(?i)(everything|all|complete)") AND match(Subject_Title,
|
||||
"(?i)(bypass|ignore)"), "Bulk_Request+Bypass", match(Subject_Title,
|
||||
"(?i)(classified|confidential|proprietary)"), "Confidential",
|
||||
match(Subject_Title, "(?i)(dump|extract|scrape)"), "Extraction",
|
||||
match(Subject_Title, "(?i)(everything|all|complete|comprehensive)"),
|
||||
"Bulk_Request", match(Subject_Title, "(?i)(bypass|ignore)"), "Bypass_Attempt",
|
||||
1=1, "Standard_Request") | table _time, user, Subject_Title, extraction_type,
|
||||
severity, data_risk_flags, Size | sort -severity, -_time |
|
||||
`m365_copilot_information_extraction_jailbreak_attack_filter`
|
||||
how_to_implement: To export M365 Copilot prompt logs, navigate to the Microsoft Purview compliance portal (compliance.microsoft.com) and access eDiscovery. Create a new eDiscovery case, add target user accounts or date ranges as data sources, then create a search query targeting M365 Copilot interactions across relevant workloads. Once the search completes, export the results to generate a package containing prompt logs with fields like Subject_Title (prompt text), Sender, timestamps, and workload metadata. Download the exported files using the eDiscovery Export Tool and ingest them into Splunk for security analysis and detection of jailbreak attempts, data exfiltration requests, and policy violations.
|
||||
known_false_positives: Legitimate researchers studying data classification systems, cybersecurity professionals testing information handling policies, compliance officers reviewing data access procedures, journalists researching transparency issues, or employees asking for comprehensive project documentation may trigger false positives.
|
||||
references:
|
||||
@@ -44,7 +80,7 @@ tags:
|
||||
- Suspicious Microsoft 365 Copilot Activities
|
||||
asset_type: Web Application
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: M365 Copilot Jailbreak Attempts
|
||||
id: b05a4f25-e07d-436f-ab03-f954afa922c0
|
||||
version: 4
|
||||
date: '2026-04-15'
|
||||
version: 5
|
||||
date: '2026-05-04'
|
||||
author: Rod Soto
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
@@ -54,7 +54,7 @@ tags:
|
||||
- Suspicious Microsoft 365 Copilot Activities
|
||||
asset_type: Web Application
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
+3
-3
@@ -1,7 +1,7 @@
|
||||
name: M365 Copilot Non Compliant Devices Accessing M365 Copilot
|
||||
id: e26bc52d-9cbc-4743-9745-e8781d935042
|
||||
version: 4
|
||||
date: '2026-04-15'
|
||||
version: 5
|
||||
date: '2026-05-04'
|
||||
author: Rod Soto
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -43,7 +43,7 @@ tags:
|
||||
- Suspicious Microsoft 365 Copilot Activities
|
||||
asset_type: Web Application
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ASL AWS Defense Evasion Delete Cloudtrail
|
||||
id: 1f0b47e5-0134-43eb-851c-e3258638945e
|
||||
version: 12
|
||||
date: '2026-04-15'
|
||||
version: 13
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -46,7 +46,7 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ASL AWS Defense Evasion Delete CloudWatch Log Group
|
||||
id: 0f701b38-a0fb-43fd-a83d-d12265f71f33
|
||||
version: 11
|
||||
date: '2026-04-15'
|
||||
version: 12
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -46,7 +46,7 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ASL AWS Defense Evasion Impair Security Services
|
||||
id: 5029b681-0462-47b7-82e7-f7e3d37f5a2d
|
||||
version: 9
|
||||
date: '2026-02-25'
|
||||
version: 10
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Bhavin Patel, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -30,7 +30,7 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ASL AWS Defense Evasion PutBucketLifecycle
|
||||
id: 986565a2-7707-48ea-9590-37929cebc938
|
||||
version: 5
|
||||
date: '2026-02-25'
|
||||
version: 6
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -33,7 +33,7 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1485.001
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ASL AWS Defense Evasion Stop Logging Cloudtrail
|
||||
id: 0b78a8f9-1d31-4d23-85c8-56ad13d5b4c1
|
||||
version: 10
|
||||
date: '2026-04-15'
|
||||
version: 11
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -46,7 +46,7 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ASL AWS Defense Evasion Update Cloudtrail
|
||||
id: f3eb471c-16d0-404d-897c-7653f0a78cba
|
||||
version: 10
|
||||
date: '2026-04-15'
|
||||
version: 11
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -46,7 +46,7 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
+3
-3
@@ -1,7 +1,7 @@
|
||||
name: ASL AWS Network Access Control List Created with All Open Ports
|
||||
id: a2625034-c2de-44fc-b45c-7bac9c4a7974
|
||||
version: 7
|
||||
date: '2026-04-15'
|
||||
version: 8
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -52,7 +52,7 @@ tags:
|
||||
- AWS Network ACL Activity
|
||||
asset_type: AWS Instance
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1686.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ASL AWS Network Access Control List Deleted
|
||||
id: e010ddf5-e9a5-44e5-bdd6-0c919ba8fc8b
|
||||
version: 8
|
||||
date: '2026-04-15'
|
||||
version: 9
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -49,7 +49,7 @@ tags:
|
||||
- Scattered Lapsus$ Hunters
|
||||
asset_type: AWS Instance
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1686.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Bedrock Delete GuardRails
|
||||
id: 7a5e3d62-f743-11ee-9f6e-acde48001122
|
||||
version: 5
|
||||
date: '2026-04-15'
|
||||
version: 6
|
||||
date: '2026-05-04'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -9,12 +9,12 @@ description: The following analytic identifies attempts to delete AWS Bedrock Gu
|
||||
data_source:
|
||||
- AWS CloudTrail DeleteGuardrail
|
||||
search: >-
|
||||
`cloudtrail` eventSource=bedrock.amazonaws.com eventName=DeleteGuardrail
|
||||
| rename user_name as user
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.guardrailIdentifier) as guardrailIds by src user user_agent vendor_account vendor_product dest signature vendor_region
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `aws_bedrock_delete_guardrails_filter`
|
||||
`cloudtrail` eventSource=bedrock.amazonaws.com eventName=DeleteGuardrail |
|
||||
rename user_name as user | stats count min(_time) as firstTime max(_time) as
|
||||
lastTime values(requestParameters.guardrailIdentifier) as guardrailIds by src
|
||||
user user_agent vendor_account vendor_product dest signature vendor_region |
|
||||
`security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |
|
||||
`aws_bedrock_delete_guardrails_filter`
|
||||
how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search requires AWS CloudTrail logs with Bedrock service events enabled. You must install and configure the AWS App for Splunk (version 6.0.0 or later) and Splunk Add-on for AWS (version 5.1.0 or later) to collect CloudTrail logs from AWS. Ensure the CloudTrail is capturing Bedrock GuardRails management events.
|
||||
known_false_positives: Legitimate administrators may delete GuardRails as part of normal operations, such as when replacing outdated guardrails with updated versions, cleaning up test resources, or consolidating security controls. Consider implementing an allowlist for expected administrators who regularly manage GuardRails configurations.
|
||||
references:
|
||||
@@ -44,7 +44,7 @@ tags:
|
||||
- AWS Bedrock Security
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Bedrock Delete Model Invocation Logging Configuration
|
||||
id: 9c5e3d62-f743-11ee-9f6e-acde48001124
|
||||
version: 5
|
||||
date: '2026-04-15'
|
||||
version: 6
|
||||
date: '2026-05-04'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -9,12 +9,12 @@ description: The following analytic identifies attempts to delete AWS Bedrock mo
|
||||
data_source:
|
||||
- AWS CloudTrail DeleteModelInvocationLoggingConfiguration
|
||||
search: >-
|
||||
`cloudtrail` eventSource=bedrock.amazonaws.com eventName=DeleteModelInvocationLoggingConfiguration
|
||||
| rename user_name as user
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by src user user_agent vendor_account vendor_product dest signature vendor_region
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `aws_bedrock_delete_model_invocation_logging_configuration_filter`
|
||||
`cloudtrail` eventSource=bedrock.amazonaws.com
|
||||
eventName=DeleteModelInvocationLoggingConfiguration | rename user_name as user
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by src user
|
||||
user_agent vendor_account vendor_product dest signature vendor_region |
|
||||
`security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |
|
||||
`aws_bedrock_delete_model_invocation_logging_configuration_filter`
|
||||
how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search requires AWS CloudTrail logs with Bedrock service events enabled. You must install and configure the AWS App for Splunk (version 6.0.0 or later) and Splunk Add-on for AWS (version 5.1.0 or later) to collect CloudTrail logs from AWS. Ensure the CloudTrail is capturing Bedrock model invocation logging management events.
|
||||
known_false_positives: Legitimate administrators may delete model invocation logging configurations during maintenance, when updating logging policies, or when cleaning up unused resources. Consider implementing an allowlist for expected administrators who regularly manage logging configurations.
|
||||
references:
|
||||
@@ -43,7 +43,7 @@ tags:
|
||||
- AWS Bedrock Security
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion Delete Cloudtrail
|
||||
id: 82092925-9ca1-4e06-98b8-85a2d3889552
|
||||
version: 10
|
||||
date: '2026-04-15'
|
||||
version: 11
|
||||
date: '2026-05-04'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -45,7 +45,7 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion Delete CloudWatch Log Group
|
||||
id: d308b0f1-edb7-4a62-a614-af321160710f
|
||||
version: 10
|
||||
date: '2026-04-15'
|
||||
version: 11
|
||||
date: '2026-05-04'
|
||||
author: Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -45,7 +45,7 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion Impair Security Services
|
||||
id: b28c4957-96a6-47e0-a965-6c767aac1458
|
||||
version: 12
|
||||
date: '2026-04-15'
|
||||
version: 13
|
||||
date: '2026-05-04'
|
||||
author: Bhavin Patel, Gowthamaraj Rajendran, Splunk, PashFW, Github Community
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -52,7 +52,7 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion PutBucketLifecycle
|
||||
id: ce1c0e2b-9303-4903-818b-0d9002fc6ea4
|
||||
version: 8
|
||||
date: '2026-02-25'
|
||||
version: 9
|
||||
date: '2026-05-04'
|
||||
author: Bhavin Patel
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -31,7 +31,7 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1485.001
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion Stop Logging Cloudtrail
|
||||
id: 8a2f3ca2-4eb5-4389-a549-14063882e537
|
||||
version: 10
|
||||
date: '2026-04-15'
|
||||
version: 11
|
||||
date: '2026-05-04'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -45,7 +45,7 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion Update Cloudtrail
|
||||
id: 7c921d28-ef48-4f1b-85b3-0af8af7697db
|
||||
version: 10
|
||||
date: '2026-04-15'
|
||||
version: 11
|
||||
date: '2026-05-04'
|
||||
author: Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -45,7 +45,7 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Network Access Control List Created with All Open Ports
|
||||
id: ada0f478-84a8-4641-a3f1-d82362d6bd75
|
||||
version: 11
|
||||
date: '2026-04-15'
|
||||
version: 12
|
||||
date: '2026-05-04'
|
||||
author: Bhavin Patel, Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -51,7 +51,7 @@ tags:
|
||||
- AWS Network ACL Activity
|
||||
asset_type: AWS Instance
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1686.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Network Access Control List Deleted
|
||||
id: ada0f478-84a8-4641-a3f1-d82362d6fd75
|
||||
version: 11
|
||||
date: '2026-04-15'
|
||||
version: 12
|
||||
date: '2026-05-04'
|
||||
author: Bhavin Patel, Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -45,7 +45,7 @@ tags:
|
||||
- AWS Network ACL Activity
|
||||
asset_type: AWS Instance
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1686.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD Block User Consent For Risky Apps Disabled
|
||||
id: 875de3d7-09bc-4916-8c0a-0929f4ced3d8
|
||||
version: 11
|
||||
date: '2026-04-15'
|
||||
version: 12
|
||||
date: '2026-05-04'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -37,7 +37,7 @@ tags:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Tenant
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Enterprise Delete Branch Ruleset
|
||||
id: 6169ea23-3719-439f-957a-0ea5174b70e2
|
||||
version: 7
|
||||
date: '2026-04-15'
|
||||
version: 8
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -50,7 +50,7 @@ tags:
|
||||
- NPM Supply Chain Compromise
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Enterprise Disable 2FA Requirement
|
||||
id: 5a773226-ebd7-480c-a819-fccacfeddcd9
|
||||
version: 6
|
||||
date: '2026-04-15'
|
||||
version: 7
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -47,7 +47,7 @@ tags:
|
||||
- GitHub Malicious Activity
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Enterprise Disable Audit Log Event Stream
|
||||
id: 7bc111cc-7f1b-4be7-99fa-50cf8d2e7564
|
||||
version: 7
|
||||
date: '2026-04-15'
|
||||
version: 8
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -48,7 +48,7 @@ tags:
|
||||
- NPM Supply Chain Compromise
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Enterprise Disable Classic Branch Protection Rule
|
||||
id: 372176ba-450c-4abd-9b86-419bb44c1b76
|
||||
version: 6
|
||||
date: '2026-04-15'
|
||||
version: 7
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -49,7 +49,7 @@ tags:
|
||||
- GitHub Malicious Activity
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Enterprise Disable Dependabot
|
||||
id: 787dd1c1-eb3a-4a31-8e8c-2ad24b214bc8
|
||||
version: 6
|
||||
date: '2026-04-15'
|
||||
version: 7
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -48,7 +48,7 @@ tags:
|
||||
- GitHub Malicious Activity
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Enterprise Disable IP Allow List
|
||||
id: afed020e-edcd-4913-a675-cebedf81d4fb
|
||||
version: 6
|
||||
date: '2026-04-15'
|
||||
version: 7
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -47,7 +47,7 @@ tags:
|
||||
- GitHub Malicious Activity
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Enterprise Modify Audit Log Event Stream
|
||||
id: 99abf2e1-863c-4ec6-82f8-714391590a4c
|
||||
version: 7
|
||||
date: '2026-04-15'
|
||||
version: 8
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -48,7 +48,7 @@ tags:
|
||||
- NPM Supply Chain Compromise
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Enterprise Pause Audit Log Event Stream
|
||||
id: 21083dcb-276d-4ef9-8f7e-2113ca5e8094
|
||||
version: 7
|
||||
date: '2026-04-15'
|
||||
version: 8
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -49,7 +49,7 @@ tags:
|
||||
- NPM Supply Chain Compromise
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Enterprise Register Self Hosted Runner
|
||||
id: b27685a2-8826-4123-ab78-2d9d0d419ed0
|
||||
version: 7
|
||||
date: '2026-04-15'
|
||||
version: 8
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -49,7 +49,7 @@ tags:
|
||||
- NPM Supply Chain Compromise
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Organizations Delete Branch Ruleset
|
||||
id: 8e454f64-4bd6-45e6-8a94-1b482593d721
|
||||
version: 8
|
||||
date: '2026-04-15'
|
||||
version: 9
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -50,7 +50,7 @@ tags:
|
||||
- NPM Supply Chain Compromise
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Organizations Disable 2FA Requirement
|
||||
id: 3ed0d6ba-4791-4fa8-a1ef-403e438c7033
|
||||
version: 7
|
||||
date: '2026-04-15'
|
||||
version: 8
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -48,7 +48,7 @@ tags:
|
||||
- GitHub Malicious Activity
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Organizations Disable Classic Branch Protection Rule
|
||||
id: 33cffee0-41ee-402e-a238-d37825f2d788
|
||||
version: 7
|
||||
date: '2026-04-15'
|
||||
version: 8
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -49,7 +49,7 @@ tags:
|
||||
- GitHub Malicious Activity
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GitHub Organizations Disable Dependabot
|
||||
id: 69078d8c-0de6-45de-bb00-14e78e042fd6
|
||||
version: 7
|
||||
date: '2026-04-15'
|
||||
version: 8
|
||||
date: '2026-05-04'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -48,7 +48,7 @@ tags:
|
||||
- GitHub Malicious Activity
|
||||
asset_type: GitHub
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
- T1195
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,27 +1,38 @@
|
||||
name: Microsoft Intune DeviceManagementConfigurationPolicies
|
||||
id: 3c49e5ed-625c-408c-a2c7-8e2b524efb2c
|
||||
version: 3
|
||||
date: '2026-02-25'
|
||||
version: 4
|
||||
date: '2026-05-04'
|
||||
author: Dean Luxton
|
||||
data_source:
|
||||
- Azure Monitor Activity
|
||||
type: Hunting
|
||||
status: production
|
||||
description: >-
|
||||
Microsoft Intune device management configuration policies are a tool administrators can use to remotely manage policies and settings on intune managed devices.
|
||||
This functionality can also be abused to disable defences & evade detection.
|
||||
This detection identifies when a new device management configuration policy has been created.
|
||||
Microsoft Intune device management configuration policies are a tool
|
||||
administrators can use to remotely manage policies and settings on intune
|
||||
managed devices. This functionality can also be abused to disable defences &
|
||||
evade detection. This detection identifies when a new device management
|
||||
configuration policy has been created.
|
||||
search: >-
|
||||
`azure_monitor_activity` operationName="* DeviceManagementConfigurationPolicy*"
|
||||
| rename identity as user, properties.TargetObjectIds{} as TargetObjectId, properties.TargetDisplayNames{} as TargetDisplayName, properties.Actor.IsDelegatedAdmin as user_isDelegatedAdmin
|
||||
| eval details=mvzip('properties.Targets{}.ModifiedProperties{}.Name','properties.Targets{}.ModifiedProperties{}.New',": ")
|
||||
| rex field="operationName" "^(?P<action>\w+)\s" | replace "Patch" with "updated", "Create" with "created", "Delete", with "deleted", "assign", with "assigned" IN action
|
||||
| eval action=if(match(operationName ,"Assignment$"),"assigned",'action')
|
||||
| table _time operationName action user user_type user_isDelegatedAdmin TargetDisplayName TargetObjectId details status tenantId correlationId | `microsoft_intune_devicemanagementconfigurationpolicies_filter`
|
||||
`azure_monitor_activity` operationName="*
|
||||
DeviceManagementConfigurationPolicy*" | rename identity as user,
|
||||
properties.TargetObjectIds{} as TargetObjectId,
|
||||
properties.TargetDisplayNames{} as TargetDisplayName,
|
||||
properties.Actor.IsDelegatedAdmin as user_isDelegatedAdmin | eval
|
||||
details=mvzip('properties.Targets{}.ModifiedProperties{}.Name','properties.Targets{}.ModifiedProperties{}.New',":
|
||||
") | rex field="operationName" "^(?P<action>\w+)\s" | replace "Patch" with
|
||||
"updated", "Create" with "created", "Delete", with "deleted", "assign", with
|
||||
"assigned" IN action | eval action=if(match(operationName
|
||||
,"Assignment$"),"assigned",'action') | table _time operationName action user
|
||||
user_type user_isDelegatedAdmin TargetDisplayName TargetObjectId details
|
||||
status tenantId correlationId |
|
||||
`microsoft_intune_devicemanagementconfigurationpolicies_filter`
|
||||
how_to_implement: >-
|
||||
The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub.
|
||||
To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic settings & send events to the activity audit event hub.
|
||||
Deploy as a risk based alerting rule for quick deployment or perform baselining & tune accordingly.
|
||||
The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest
|
||||
In-Tune audit logs via Azure EventHub. To configure this logging, visit Intune
|
||||
> Tenant administration > Diagnostic settings > Add diagnostic settings & send
|
||||
events to the activity audit event hub. Deploy as a risk based alerting rule
|
||||
for quick deployment or perform baselining & tune accordingly.
|
||||
known_false_positives: Legitimate adminstrative usage of this functionality will trigger this detection.
|
||||
references:
|
||||
- https://posts.specterops.io/death-from-above-lateral-movement-from-azure-to-on-prem-ad-d18cb3959d4d
|
||||
@@ -35,8 +46,8 @@ tags:
|
||||
- T1072
|
||||
- T1484
|
||||
- T1021.007
|
||||
- T1562.001
|
||||
- T1562.004
|
||||
- T1685
|
||||
- T1686
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Advanced Audit Disabled
|
||||
id: 49862dd4-9cb2-4c48-a542-8c8a588d9361
|
||||
version: 9
|
||||
date: '2026-04-15'
|
||||
version: 10
|
||||
date: '2026-05-04'
|
||||
author: Mauricio Velazco, Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -36,7 +36,7 @@ tags:
|
||||
- Office 365 Persistence Mechanisms
|
||||
asset_type: O365 Tenant
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Block User Consent For Risky Apps Disabled
|
||||
id: 12a23592-e3da-4344-8545-205d3290647c
|
||||
version: 8
|
||||
date: '2026-04-15'
|
||||
version: 9
|
||||
date: '2026-05-04'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -38,7 +38,7 @@ tags:
|
||||
asset_type: O365 Tenant
|
||||
atomic_guid: []
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Bypass MFA via Trusted IP
|
||||
id: c783dd98-c703-4252-9e8a-f19d9f66949e
|
||||
version: 11
|
||||
date: '2026-04-15'
|
||||
version: 12
|
||||
date: '2026-05-04'
|
||||
author: Bhavin Patel, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -36,7 +36,7 @@ tags:
|
||||
- Office 365 Persistence Mechanisms
|
||||
asset_type: O365 Tenant
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1686.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Email Security Feature Changed
|
||||
id: 4d28013d-3a0f-4d65-a33f-4e8009fee0ae
|
||||
version: 10
|
||||
date: '2026-04-15'
|
||||
version: 11
|
||||
date: '2026-05-04'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -46,8 +46,7 @@ tags:
|
||||
- Office 365 Account Takeover
|
||||
asset_type: O365 Tenant
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562.008
|
||||
- T1685.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Processes launching netsh
|
||||
id: b89919ed-fe5f-492c-b139-95dbb162040e
|
||||
version: 14
|
||||
date: '2026-03-26'
|
||||
version: 15
|
||||
date: '2026-05-04'
|
||||
author: Michael Haag, Josef Kuepker, Splunk
|
||||
status: deprecated
|
||||
type: Anomaly
|
||||
@@ -59,7 +59,7 @@ tags:
|
||||
- Hellcat Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.004
|
||||
- T1686
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Add or Set Windows Defender Exclusion
|
||||
id: 773b66fe-4dd9-11ec-8289-acde48001122
|
||||
version: 15
|
||||
date: '2026-04-15'
|
||||
version: 16
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Nasreddine Bencherchali, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -91,7 +91,7 @@ tags:
|
||||
- NetSupport RMM Tool Abuse
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Allow File And Printing Sharing In Firewall
|
||||
id: ce27646e-d411-11eb-8a00-acde48001122
|
||||
version: 13
|
||||
date: '2026-04-15'
|
||||
version: 14
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -58,7 +58,7 @@ tags:
|
||||
- Hellcat Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1686.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Allow Network Discovery In Firewall
|
||||
id: ccd6a38c-d40b-11eb-85a5-acde48001122
|
||||
version: 12
|
||||
date: '2026-04-15'
|
||||
version: 13
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -55,7 +55,7 @@ tags:
|
||||
- Hellcat Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1686.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable AMSI Through Registry
|
||||
id: 9c27ec42-d338-11eb-9044-acde48001122
|
||||
version: 13
|
||||
date: '2026-04-15'
|
||||
version: 14
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -37,7 +37,7 @@ tags:
|
||||
- Windows Registry Abuse
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Defender AntiVirus Registry
|
||||
id: aa4f695a-3024-11ec-9987-acde48001122
|
||||
version: 16
|
||||
date: '2026-04-15'
|
||||
version: 17
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -42,7 +42,7 @@ tags:
|
||||
- Cactus Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Defender BlockAtFirstSeen Feature
|
||||
id: 2dd719ac-3021-11ec-97b4-acde48001122
|
||||
version: 14
|
||||
date: '2026-04-15'
|
||||
version: 15
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -41,7 +41,7 @@ tags:
|
||||
- Windows Registry Abuse
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Defender Enhanced Notification
|
||||
id: dc65678c-301f-11ec-8e30-acde48001122
|
||||
version: 13
|
||||
date: '2026-04-15'
|
||||
version: 14
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -40,7 +40,7 @@ tags:
|
||||
- Windows Registry Abuse
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Defender MpEngine Registry
|
||||
id: cc391750-3024-11ec-955a-acde48001122
|
||||
version: 14
|
||||
date: '2026-04-15'
|
||||
version: 15
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -38,7 +38,7 @@ tags:
|
||||
- Windows Registry Abuse
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Defender Spynet Reporting
|
||||
id: 898debf4-3021-11ec-ba7c-acde48001122
|
||||
version: 13
|
||||
date: '2026-04-15'
|
||||
version: 14
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -41,7 +41,7 @@ tags:
|
||||
- CISA AA23-347A
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Defender Submit Samples Consent Feature
|
||||
id: 73922ff8-3022-11ec-bf5e-acde48001122
|
||||
version: 13
|
||||
date: '2026-04-15'
|
||||
version: 14
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -41,7 +41,7 @@ tags:
|
||||
- BlankGrabber Stealer
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable ETW Through Registry
|
||||
id: f0eacfa4-d33f-11eb-8f9d-acde48001122
|
||||
version: 13
|
||||
date: '2026-04-15'
|
||||
version: 14
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -36,7 +36,7 @@ tags:
|
||||
- Windows Registry Abuse
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Logs Using WevtUtil
|
||||
id: 236e7c8e-c9d9-11eb-a824-acde48001122
|
||||
version: 13
|
||||
date: '2026-04-15'
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -55,7 +55,7 @@ tags:
|
||||
- Rhysida Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1070.001
|
||||
- T1685.005
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Registry Tool
|
||||
id: cd2cf33c-9201-11eb-a10a-acde48001122
|
||||
version: 15
|
||||
date: '2026-04-15'
|
||||
version: 16
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -37,7 +37,7 @@ tags:
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1112
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Schedule Task
|
||||
id: db596056-3019-11ec-a9ff-acde48001122
|
||||
version: 11
|
||||
date: '2026-04-15'
|
||||
version: 12
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -50,7 +50,7 @@ tags:
|
||||
- Living Off The Land
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Show Hidden Files
|
||||
id: 6f3ccfa2-91fe-11eb-8f9b-acde48001122
|
||||
version: 16
|
||||
date: '2026-04-15'
|
||||
version: 17
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -37,7 +37,7 @@ tags:
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1112
|
||||
- T1562.001
|
||||
- T1685
|
||||
- T1564.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Windows App Hotkeys
|
||||
id: 1490f224-ad8b-11eb-8c4f-acde48001122
|
||||
version: 15
|
||||
date: '2026-04-15'
|
||||
version: 16
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -36,7 +36,7 @@ tags:
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1112
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Windows Behavior Monitoring
|
||||
id: 79439cae-9200-11eb-a4d3-acde48001122
|
||||
version: 21
|
||||
date: '2026-04-15'
|
||||
version: 22
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -47,7 +47,7 @@ tags:
|
||||
- BlankGrabber Stealer
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disable Windows SmartScreen Protection
|
||||
id: 664f0fd0-91ff-11eb-a56f-acde48001122
|
||||
version: 14
|
||||
date: '2026-04-15'
|
||||
version: 15
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -39,7 +39,7 @@ tags:
|
||||
- Windows Registry Abuse
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disabling CMD Application
|
||||
id: ff86077c-9212-11eb-a1e6-acde48001122
|
||||
version: 15
|
||||
date: '2026-04-15'
|
||||
version: 16
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -40,7 +40,7 @@ tags:
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1112
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disabling ControlPanel
|
||||
id: 6ae0148e-9215-11eb-a94a-acde48001122
|
||||
version: 15
|
||||
date: '2026-04-15'
|
||||
version: 16
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -39,7 +39,7 @@ tags:
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1112
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disabling Defender Services
|
||||
id: 911eacdc-317f-11ec-ad30-acde48001122
|
||||
version: 13
|
||||
date: '2026-04-15'
|
||||
version: 14
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -39,7 +39,7 @@ tags:
|
||||
- RedLine Stealer
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disabling Firewall with Netsh
|
||||
id: 6860a62c-9203-11eb-9e05-acde48001122
|
||||
version: 12
|
||||
date: '2026-04-15'
|
||||
version: 13
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -55,7 +55,7 @@ tags:
|
||||
- BlackByte Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disabling FolderOptions Windows Feature
|
||||
id: 83776de4-921a-11eb-868a-acde48001122
|
||||
version: 14
|
||||
date: '2026-04-15'
|
||||
version: 15
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -39,7 +39,7 @@ tags:
|
||||
- Windows Registry Abuse
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disabling NoRun Windows App
|
||||
id: de81bc46-9213-11eb-adc9-acde48001122
|
||||
version: 15
|
||||
date: '2026-04-15'
|
||||
version: 16
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -40,7 +40,7 @@ tags:
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1112
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Disabling Task Manager
|
||||
id: dac279bc-9202-11eb-b7fb-acde48001122
|
||||
version: 14
|
||||
date: '2026-04-15'
|
||||
version: 15
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -40,7 +40,7 @@ tags:
|
||||
- NjRAT
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ETW Registry Disabled
|
||||
id: 8ed523ac-276b-11ec-ac39-acde48001122
|
||||
version: 16
|
||||
date: '2026-04-15'
|
||||
version: 17
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -44,7 +44,7 @@ tags:
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1127
|
||||
- T1562.006
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Excessive number of service control start as disabled
|
||||
id: 77592bec-d5cc-11eb-9e60-acde48001122
|
||||
version: 11
|
||||
date: '2026-04-15'
|
||||
version: 12
|
||||
date: '2026-05-04'
|
||||
author: Michael Hart, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -51,7 +51,7 @@ tags:
|
||||
- Windows Defense Evasion Tactics
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Excessive Usage Of Taskkill
|
||||
id: fe5bca48-accb-11eb-a67c-acde48001122
|
||||
version: 12
|
||||
date: '2026-04-15'
|
||||
version: 13
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -55,7 +55,7 @@ tags:
|
||||
- BlankGrabber Stealer
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Firewall Allowed Program Enable
|
||||
id: 9a8f63a8-43ac-11ec-904c-acde48001122
|
||||
version: 10
|
||||
date: '2026-04-15'
|
||||
version: 11
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -54,7 +54,7 @@ tags:
|
||||
- Azorult
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.004
|
||||
- T1686
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Hide User Account From Sign-In Screen
|
||||
id: 834ba832-ad89-11eb-937d-acde48001122
|
||||
version: 14
|
||||
date: '2026-04-15'
|
||||
version: 15
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -42,7 +42,7 @@ tags:
|
||||
- Warzone RAT
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Auditd Auditd Daemon Abort
|
||||
id: 76d6573f-c4ab-4fa1-8390-c036416d4add
|
||||
version: 4
|
||||
date: '2026-04-15'
|
||||
version: 5
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -42,7 +42,7 @@ tags:
|
||||
- Compromised Linux Host
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.012
|
||||
- T1685.004
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Auditd Auditd Daemon Shutdown
|
||||
id: 6e2574b3-e24b-4321-ae3c-ba83a75bb714
|
||||
version: 4
|
||||
date: '2026-04-15'
|
||||
version: 5
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -42,7 +42,7 @@ tags:
|
||||
- Compromised Linux Host
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.012
|
||||
- T1685.004
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Auditd Auditd Daemon Start
|
||||
id: 6b0cb0ff-9a7e-4475-a687-43827fdb31d6
|
||||
version: 4
|
||||
date: '2026-04-15'
|
||||
version: 5
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -42,7 +42,7 @@ tags:
|
||||
- Compromised Linux Host
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.012
|
||||
- T1685.004
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Auditd Disable Or Modify System Firewall
|
||||
id: 07052556-d4b5-4bae-89aa-cbdc1bb11250
|
||||
version: 10
|
||||
date: '2026-04-15'
|
||||
version: 11
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -45,7 +45,7 @@ tags:
|
||||
- Compromised Linux Host
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.004
|
||||
- T1686
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Impair Defenses Process Kill
|
||||
id: 435c6b33-adf9-47fe-be87-8e29fd6654f5
|
||||
version: 9
|
||||
date: '2026-02-25'
|
||||
version: 10
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -33,7 +33,7 @@ tags:
|
||||
- Scattered Lapsus$ Hunters
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Iptables Firewall Modification
|
||||
id: 309d59dc-1e1b-49b2-9800-7cf18d12f7b7
|
||||
version: 14
|
||||
date: '2026-04-15'
|
||||
version: 15
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -69,7 +69,7 @@ tags:
|
||||
- Sandworm Tools
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.004
|
||||
- T1686
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Stdout Redirection To Dev Null File
|
||||
id: de62b809-a04d-46b5-9a15-8298d330f0c8
|
||||
version: 12
|
||||
date: '2026-04-15'
|
||||
version: 13
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -50,7 +50,7 @@ tags:
|
||||
- Industroyer2
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.004
|
||||
- T1686
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: MSBuild Suspicious Spawned By Script Process
|
||||
id: 213b3148-24ea-11ec-93a2-acde48001122
|
||||
version: 11
|
||||
date: '2026-04-15'
|
||||
version: 12
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Powershell Disable Security Monitoring
|
||||
id: c148a894-dd93-11eb-bf2a-acde48001122
|
||||
version: 14
|
||||
date: '2026-04-15'
|
||||
version: 15
|
||||
date: '2026-05-04'
|
||||
author: Michael Haag, Nasreddine Bencherchali, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -115,7 +115,7 @@ tags:
|
||||
- BlankGrabber Stealer
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Powershell Remove Windows Defender Directory
|
||||
id: adf47620-79fa-11ec-b248-acde48001122
|
||||
version: 14
|
||||
date: '2026-04-15'
|
||||
version: 15
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -38,7 +38,7 @@ tags:
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Powershell Windows Defender Exclusion Commands
|
||||
id: 907ac95c-4dd9-11ec-ba2c-acde48001122
|
||||
version: 13
|
||||
date: '2026-04-15'
|
||||
version: 14
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -58,7 +58,7 @@ tags:
|
||||
- BlankGrabber Stealer
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Process Kill Base On File Path
|
||||
id: 5ffaa42c-acdb-11eb-9ad3-acde48001122
|
||||
version: 13
|
||||
date: '2026-04-15'
|
||||
version: 14
|
||||
date: '2026-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -58,7 +58,7 @@ tags:
|
||||
- XMRig
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1685
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user