mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -30,6 +30,7 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 3
|
||||
|
||||
@@ -26,6 +26,7 @@ tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Unusual Processes
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 2
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
confidence: 80
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
@@ -31,6 +31,7 @@ references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Ingress Tool Transfer
|
||||
- Log4Shell CVE-2021-44228
|
||||
|
||||
@@ -30,6 +30,7 @@ references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- HAFNIUM Group
|
||||
- Ingress Tool Transfer
|
||||
|
||||
@@ -31,6 +31,7 @@ tags:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
confidence: 100
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
@@ -37,6 +37,7 @@ references:
|
||||
- https://github.com/BC-SECURITY/Empire
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 90
|
||||
context:
|
||||
|
||||
@@ -34,6 +34,7 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 100
|
||||
context:
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
confidence: 100
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
@@ -30,6 +30,7 @@ tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Active Directory Kerberos Attacks
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 8
|
||||
|
||||
@@ -30,6 +30,7 @@ references:
|
||||
- https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Log4Shell CVE-2021-44228
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
|
||||
@@ -28,6 +28,7 @@ tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
confidence: 100
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
@@ -40,6 +40,7 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- NOBELIUM Group
|
||||
- WhisperGate
|
||||
|
||||
@@ -26,6 +26,7 @@ known_false_positives: These characters might be legitimately on the command-lin
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
|
||||
@@ -39,6 +39,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
confidence: 70
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
@@ -28,6 +28,7 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 8
|
||||
|
||||
@@ -37,6 +37,7 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1543/003/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Active Directory Lateral Movement
|
||||
- Malicious PowerShell
|
||||
confidence: 50
|
||||
|
||||
@@ -49,6 +49,7 @@ references:
|
||||
- https://hurricanelabs.com/splunk-tutorials/how-to-use-powershell-transcription-logs-in-splunk/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 100
|
||||
context:
|
||||
|
||||
@@ -36,6 +36,7 @@ references:
|
||||
- https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
|
||||
- HAFNIUM Group
|
||||
|
||||
@@ -32,6 +32,7 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 70
|
||||
context:
|
||||
|
||||
@@ -22,6 +22,7 @@ references:
|
||||
- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Ransomware
|
||||
context:
|
||||
|
||||
@@ -24,6 +24,7 @@ references:
|
||||
- https://threadreaderapp.com/thread/1423361119926816776.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Ransomware
|
||||
confidence: 50
|
||||
|
||||
@@ -35,6 +35,7 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 80
|
||||
context:
|
||||
|
||||
@@ -34,6 +34,7 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 80
|
||||
context:
|
||||
|
||||
@@ -36,6 +36,7 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 80
|
||||
context:
|
||||
|
||||
@@ -27,6 +27,7 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 80
|
||||
context:
|
||||
|
||||
@@ -27,6 +27,7 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 80
|
||||
context:
|
||||
|
||||
@@ -28,6 +28,7 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Ransomware
|
||||
- Malicious PowerShell
|
||||
confidence: 80
|
||||
|
||||
@@ -29,6 +29,7 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 80
|
||||
context:
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
- Suspicious Windows Registry Activities
|
||||
- Cloud Federated Credential Abuse
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
cis20:
|
||||
- CIS 8
|
||||
confidence: 95
|
||||
|
||||
@@ -31,6 +31,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
confidence: 50
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
@@ -32,6 +32,7 @@ tags:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
confidence: 90
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
+1
@@ -25,6 +25,7 @@ known_false_positives: Administrators may attempt to change the default executio
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Credential Dumping
|
||||
- HAFNIUM Group
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
confidence: 100
|
||||
context:
|
||||
- Source:Endpoint
|
||||
|
||||
@@ -35,6 +35,7 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 70
|
||||
context:
|
||||
|
||||
@@ -35,6 +35,7 @@ references:
|
||||
- https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- HAFNIUM Group
|
||||
- ProxyShell
|
||||
confidence: 80
|
||||
|
||||
@@ -26,6 +26,7 @@ references:
|
||||
- https://in.security/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
confidence: 100
|
||||
context:
|
||||
|
||||
@@ -32,6 +32,7 @@ known_false_positives: None at this time
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- 'Emotet Malware DHS Report TA18-201A '
|
||||
- Suspicious Emails
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -29,6 +29,7 @@ known_false_positives: None identified
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- 'Emotet Malware DHS Report TA18-201A '
|
||||
- Suspicious Emails
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -28,6 +28,7 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 5
|
||||
|
||||
@@ -32,6 +32,7 @@ tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
context:
|
||||
|
||||
Reference in New Issue
Block a user