mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
renaming analytic story
This commit is contained in:
@@ -29,7 +29,7 @@ references:
|
||||
- https://medium.com/@cryps1s/detecting-windows-endpoint-compromise-with-sacls-cd748e10950
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 3
|
||||
|
||||
@@ -26,7 +26,7 @@ references:
|
||||
- https://learn.microsoft.com/en-us/defender-for-identity/security-assessment-unsecure-sid-history-attribute
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 4
|
||||
|
||||
@@ -27,7 +27,7 @@ references:
|
||||
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4719
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 4
|
||||
|
||||
@@ -29,7 +29,7 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1207/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 4
|
||||
|
||||
@@ -43,7 +43,7 @@ references:
|
||||
- https://github.com/SigmaHQ/sigma/blob/29a5c62784faf986dc03952ae3e90e3df3294284/rules/windows/builtin/security/win_security_account_backdoor_dcsync_rights.yml
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 6
|
||||
|
||||
@@ -32,7 +32,7 @@ references:
|
||||
- https://adsecurity.org/?p=1714
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
- Windows Registry Abuse
|
||||
- Windows Persistence Techniques
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -22,7 +22,7 @@ references:
|
||||
- https://adsecurity.org/?p=1714
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 6
|
||||
|
||||
@@ -29,7 +29,7 @@ references:
|
||||
- https://github.com/SigmaHQ/sigma/blob/0.22-699-g29a5c6278/rules/windows/builtin/security/win_security_dcsync.yml
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
- Credential Dumping
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
|
||||
+1
-1
@@ -46,7 +46,7 @@ references:
|
||||
- https://github.com/SigmaHQ/sigma/blob/0.22-699-g29a5c6278/rules/windows/builtin/security/win_security_dcsync.yml
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
- Credential Dumping
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
|
||||
@@ -29,7 +29,7 @@ references:
|
||||
- https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
- Windows Persistence Techniques
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
|
||||
@@ -26,7 +26,7 @@ references:
|
||||
- https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 3
|
||||
|
||||
@@ -31,7 +31,7 @@ references:
|
||||
- https://blog.alsid.eu/dcshadow-explained-4510f52fc19d
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 4
|
||||
|
||||
@@ -30,7 +30,7 @@ references:
|
||||
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5141
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 3
|
||||
|
||||
@@ -22,7 +22,7 @@ references:
|
||||
- https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 3
|
||||
|
||||
+1
-1
@@ -28,7 +28,7 @@ references:
|
||||
- https://adsecurity.org/?p=1772
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 4
|
||||
|
||||
@@ -17,7 +17,7 @@ references:
|
||||
- https://adsecurity.org/?p=1729
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 4
|
||||
|
||||
@@ -28,7 +28,7 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1207/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Domain Controller Attacks
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: endpoint
|
||||
cis20:
|
||||
- CIS 3
|
||||
|
||||
+2
-2
@@ -1,8 +1,8 @@
|
||||
name: Windows Domain Controller Attacks
|
||||
name: Sneaky Active Directory Persistence Tricks
|
||||
id: f676c4c1-c769-4ecb-9611-5fd85b497c56
|
||||
version: 1
|
||||
date: '2022-08-29'
|
||||
author: Dean Luxton, Mauricio Velazco
|
||||
author: Dean Luxton, Mauricio Velazco, Splunk
|
||||
description: Monitor for activities and techniques associated with replication based attacks which target domain controllers and post-exploitation active directory persistence techniques.
|
||||
narrative: This analytic story provides detections for some of the highest impact attacks which can be performed against an Active Directory network.
|
||||
Featuring attacks which leverage flaws within replication (MS probably wont fix these any time soon), enabling backdoor accounts and other stealthy persistence techniques.
|
||||
Reference in New Issue
Block a user