diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index 3553ab7531..b61b044ea2 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -42,4 +42,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index c92ef2c2ee..bb27706fff 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -43,4 +43,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml b/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml index a6c0125ff5..4b8094c626 100644 --- a/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml +++ b/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml @@ -45,4 +45,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml index b53de32dbe..0ee71e4acb 100644 --- a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml +++ b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml @@ -40,4 +40,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index 397dc4e6ad..d2184163b2 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -38,4 +38,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml index 59e9fc897d..cb4a5739fb 100644 --- a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml +++ b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml @@ -44,4 +44,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml index 40840e6eaf..79df427ff6 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml @@ -39,4 +39,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index 855bd7b839..387876b9ae 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -39,4 +39,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml index 97a99a1407..ff9f038c8e 100644 --- a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml @@ -39,4 +39,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml index 980f36e277..3ddcb7e320 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml @@ -54,4 +54,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml index 19b65861ea..2180a7e17c 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml @@ -54,4 +54,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml index 74472eb6c7..00910b6a39 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml @@ -53,4 +53,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml index e1794b49e0..7fd0943492 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml @@ -54,4 +54,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/detect_aws_console_login_by_new_user.yml b/detections/cloud/detect_aws_console_login_by_new_user.yml index 0b8a1cf26f..4f972ea968 100644 --- a/detections/cloud/detect_aws_console_login_by_new_user.yml +++ b/detections/cloud/detect_aws_console_login_by_new_user.yml @@ -43,4 +43,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml index 2fd95b9c30..2d9ff5c6de 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml @@ -49,4 +49,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml index 20722d97c8..1b021ac98b 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml @@ -49,4 +49,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml index 65100bd0ca..713a9b95c6 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml @@ -49,4 +49,4 @@ tags: risk_object: user automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json diff --git a/detections/endpoint/scheduled_tasks_used_in_badrabbit_ransomware.yml b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml similarity index 96% rename from detections/endpoint/scheduled_tasks_used_in_badrabbit_ransomware.yml rename to detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml index 5e58db8caf..9935ab3bdb 100644 --- a/detections/endpoint/scheduled_tasks_used_in_badrabbit_ransomware.yml +++ b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml @@ -5,6 +5,7 @@ date: '2020-07-21' description: This search looks for flags passed to schtasks.exe on the command-line that indicate that task names related to the execution of Bad Rabbit ransomware were created or deleted. + Deprecated because we already have a similar detection how_to_implement: You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. diff --git a/detections/endpoint/access_lsass_memory_for_dump_creation.yml b/detections/endpoint/access_lsass_memory_for_dump_creation.yml index 0a71e173e1..ed0fc17aba 100644 --- a/detections/endpoint/access_lsass_memory_for_dump_creation.yml +++ b/detections/endpoint/access_lsass_memory_for_dump_creation.yml @@ -35,4 +35,4 @@ tags: asset_type: Windows automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.001/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index d44f73ed69..b44a84c732 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -39,4 +39,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1553.004/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1553.004/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index e973d7f655..09fd05ff4f 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -46,4 +46,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1562.001_custom_f3b70c45-3f9f-493d-b0b0-6be2ad9f158b/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml index a83c6ecc1c..030f1e0232 100644 --- a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -36,4 +36,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.002/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index 842c220a63..7351f5db1e 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -40,4 +40,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1204.002_custom_b0162b8c-686d-4d97-83fe-7e80ac679cf4/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log diff --git a/detections/endpoint/common_ransomware_extensions.yml b/detections/endpoint/common_ransomware_extensions.yml index 36721065e3..da77ff7675 100644 --- a/detections/endpoint/common_ransomware_extensions.yml +++ b/detections/endpoint/common_ransomware_extensions.yml @@ -51,4 +51,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1485_custom_215ee4f9-c027-4ea1-a882-d97b887d233d/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_extensions/windows-sysmon.log diff --git a/detections/endpoint/common_ransomware_notes.yml b/detections/endpoint/common_ransomware_notes.yml index 05e1439f30..19faa3b1d2 100644 --- a/detections/endpoint/common_ransomware_notes.yml +++ b/detections/endpoint/common_ransomware_notes.yml @@ -37,4 +37,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1485_custom_cc81aa13-3899-4d33-b5c5-8a6e30eca28b/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log diff --git a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml index 45ebe62b5b..2fdfd241dc 100644 --- a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml +++ b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml @@ -36,6 +36,6 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-security.log - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-system.log - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/create_remote_thread_into_lsass.yml b/detections/endpoint/create_remote_thread_into_lsass.yml index e764454434..94db3d8e12 100644 --- a/detections/endpoint/create_remote_thread_into_lsass.yml +++ b/detections/endpoint/create_remote_thread_into_lsass.yml @@ -35,4 +35,4 @@ tags: asset_type: Windows automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.001/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/creation_of_shadow_copy.yml b/detections/endpoint/creation_of_shadow_copy.yml index b966c4e48c..9f27e6a9f9 100644 --- a/detections/endpoint/creation_of_shadow_copy.yml +++ b/detections/endpoint/creation_of_shadow_copy.yml @@ -38,4 +38,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.003/windows-sysmon.log + - hhttps://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml index 85c84d0cef..e4a1570b99 100644 --- a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml +++ b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml @@ -30,4 +30,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.003/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml index 419b7be4e3..2ee2c1d029 100644 --- a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml @@ -36,4 +36,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.003/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml index 793a5d9c28..d6891fa516 100644 --- a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml @@ -34,4 +34,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.003/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml index 4bc28a6cbc..577db5492e 100644 --- a/detections/endpoint/deleting_shadow_copies.yml +++ b/detections/endpoint/deleting_shadow_copies.yml @@ -42,4 +42,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1490/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml index de2f6bcde4..8b735df584 100644 --- a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml @@ -36,4 +36,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1550.002/windows-security.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.002/atomic_red_team/windows-security.log diff --git a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml index 2b9cb6fd85..1bad92dbd3 100644 --- a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml +++ b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml @@ -42,4 +42,4 @@ tags: asset_type: Windows automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.001/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml index 142b7fc96c..f99fd34165 100644 --- a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml +++ b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml @@ -41,5 +41,5 @@ tags: asset_type: Windows automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1078.002_custom_49a0e495-4ecd-41e4-a9c7-4c0a1e841ba6/windows-security.log - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1078.002_custom_49a0e495-4ecd-41e4-a9c7-4c0a1e841ba6/windows-system.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-security.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-system.log diff --git a/detections/endpoint/detect_excessive_user_account_lockouts.yml b/detections/endpoint/detect_excessive_user_account_lockouts.yml index 8a773a22f7..2f9e622ac0 100644 --- a/detections/endpoint/detect_excessive_user_account_lockouts.yml +++ b/detections/endpoint/detect_excessive_user_account_lockouts.yml @@ -31,5 +31,5 @@ tags: asset_type: Windows automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1078.002_custom_49a0e495-4ecd-41e4-a9c7-4c0a1e841ba6/windows-security.log - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1078.002_custom_49a0e495-4ecd-41e4-a9c7-4c0a1e841ba6/windows-system.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-security.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-system.log diff --git a/detections/endpoint/detect_mshta_exe_running_scripts_in_command_line_arguments.yml b/detections/endpoint/detect_mshta_exe_running_scripts_in_command_line_arguments.yml index 6a2cd27b0a..969b649917 100644 --- a/detections/endpoint/detect_mshta_exe_running_scripts_in_command_line_arguments.yml +++ b/detections/endpoint/detect_mshta_exe_running_scripts_in_command_line_arguments.yml @@ -38,4 +38,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1218.005/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/detect_new_local_admin_account.yml b/detections/endpoint/detect_new_local_admin_account.yml index 099e2f8723..dece28c383 100644 --- a/detections/endpoint/detect_new_local_admin_account.yml +++ b/detections/endpoint/detect_new_local_admin_account.yml @@ -32,6 +32,6 @@ tags: asset_type: Windows automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-security.log - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-system.log - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml index 91a709acc4..b27260d533 100644 --- a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml +++ b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml @@ -33,4 +33,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1574.009/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.009/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml index 6610d2ca62..3acc761759 100644 --- a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml +++ b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml @@ -41,4 +41,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1016_custom_10e3118d-3785-4197-8152-1bf68a4c617e/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/discovery_commands/windows-sysmon.log diff --git a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml index 9f023430c9..a7f7cbbbac 100644 --- a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml +++ b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml @@ -38,4 +38,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1059.003_custom_5967c616-f184-4a9d-afe4-758e0745d90e/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-sysmon.log diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index 3df9e48c90..95fb5a7a2c 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -44,4 +44,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1021.002/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.002/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index 2482d00127..5d981e2785 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -37,4 +37,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1059.003_custom_a43d29e4-3a56-4208-a0a2-44e6045f3c48/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/cmd_spawns_cscript/windows-sysmon.log diff --git a/detections/endpoint/disabling_remote_user_account_control.yml b/detections/endpoint/disabling_remote_user_account_control.yml index c55ddd5ee6..27b1a12a56 100644 --- a/detections/endpoint/disabling_remote_user_account_control.yml +++ b/detections/endpoint/disabling_remote_user_account_control.yml @@ -37,4 +37,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1548.002/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml index 2507fa9869..a95e490715 100644 --- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml +++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml @@ -35,4 +35,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.001/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index 0261793d8a..583414d64b 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -37,4 +37,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1036.003/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml index 93be170242..3fc94422ab 100644 --- a/detections/endpoint/file_with_samsam_extension.yml +++ b/detections/endpoint/file_with_samsam_extension.yml @@ -34,4 +34,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1036.003_custom_b4e0d323-9d98-4092-9757-032b598652bc/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/samsam_extension/windows-sysmon.log diff --git a/detections/endpoint/first_time_seen_child_process_of_zoom.yml b/detections/endpoint/first_time_seen_child_process_of_zoom.yml index 0514f91d75..17bf6db3ce 100644 --- a/detections/endpoint/first_time_seen_child_process_of_zoom.yml +++ b/detections/endpoint/first_time_seen_child_process_of_zoom.yml @@ -46,4 +46,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1068_custom_888ee699-7f28-4c16-85e5-d5d88aa6cdcd/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/windows-sysmon.log diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index ee93c5d9f8..fca1569cef 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -37,4 +37,4 @@ tags: asset_type: '' automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1222.001/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml index cb611fc089..29541c0336 100644 --- a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml +++ b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml @@ -33,4 +33,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1558.003/windows-security.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-security.log diff --git a/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml b/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml index ddb3f84be3..43392d1336 100644 --- a/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml +++ b/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml @@ -46,4 +46,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1059.001_custom_03e301be-1bfc-4051-af4d-d0865079fb27/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/hidden_powershell/windows-sysmon.log diff --git a/detections/endpoint/malicious_powershell_process___encoded_command.yml b/detections/endpoint/malicious_powershell_process___encoded_command.yml index cd07bf1979..ad3cf74be0 100644 --- a/detections/endpoint/malicious_powershell_process___encoded_command.yml +++ b/detections/endpoint/malicious_powershell_process___encoded_command.yml @@ -40,4 +40,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1027/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml index 1471252063..3e13290e9b 100644 --- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml +++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml @@ -41,6 +41,3 @@ tags: - PR.IP security_domain: endpoint asset_type: Endpoint - automated_detection_testing: passed - dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1059.001/windows-sysmon.log diff --git a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml index 7dbe968e6b..b5bf730dbd 100644 --- a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml +++ b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml @@ -42,4 +42,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1547.010/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.010/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index e771c5c6f8..ce24129f8c 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -39,4 +39,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1546.008/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.008/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/process_execution_via_wmi.yml b/detections/endpoint/process_execution_via_wmi.yml index c312f1d580..ad68010807 100644 --- a/detections/endpoint/process_execution_via_wmi.yml +++ b/detections/endpoint/process_execution_via_wmi.yml @@ -36,4 +36,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1047/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index 6993238dae..1f2397e669 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -39,4 +39,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1562.004/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.004/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml index 3d841bd9c8..90b15bb425 100644 --- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml +++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml @@ -39,4 +39,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1574.011_custom_eb03d0db-448b-446f-8b46-d9bc39cc8cc7/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.011/change_registry_path_service/windows-sysmon.log diff --git a/detections/endpoint/registry_keys_for_creating_shim_databases.yml b/detections/endpoint/registry_keys_for_creating_shim_databases.yml index fc3c57b1c0..51e4bcfbc2 100644 --- a/detections/endpoint/registry_keys_for_creating_shim_databases.yml +++ b/detections/endpoint/registry_keys_for_creating_shim_databases.yml @@ -36,4 +36,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1546.011/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 22323aff81..bc486e1190 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -48,4 +48,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1547.001/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml index 4d54735a76..049395f3af 100644 --- a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml +++ b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml @@ -41,4 +41,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1546.012/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.012/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/remote_process_instantiation_via_wmi.yml b/detections/endpoint/remote_process_instantiation_via_wmi.yml index 29d2c73f57..df8ab52e44 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi.yml @@ -41,4 +41,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1047/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/endpoint/rundll_loading_dll_by_ordinal.yml index 0ffb35ca5e..a7d04547be 100644 --- a/detections/endpoint/rundll_loading_dll_by_ordinal.yml +++ b/detections/endpoint/rundll_loading_dll_by_ordinal.yml @@ -38,4 +38,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1218.011/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/ryuk_test_files_detected.yml b/detections/endpoint/ryuk_test_files_detected.yml index ccb6bfda5d..7d6363e5be 100644 --- a/detections/endpoint/ryuk_test_files_detected.yml +++ b/detections/endpoint/ryuk_test_files_detected.yml @@ -33,4 +33,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/malware/ryuk/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log diff --git a/detections/endpoint/samsam_test_file_write.yml b/detections/endpoint/samsam_test_file_write.yml index 7fcdf0b8c6..3908a5cae9 100644 --- a/detections/endpoint/samsam_test_file_write.yml +++ b/detections/endpoint/samsam_test_file_write.yml @@ -18,6 +18,8 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | `security_content_ctime(firstTime)` | `samsam_test_file_write_filter`' known_false_positives: No false positives have been identified. tags: + mitre_attack_id: + - T1486 analytics_story: - SamSam Ransomware kill_chain_phases: @@ -29,3 +31,6 @@ tags: - DE.CM security_domain: endpoint asset_type: Endpoint + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/sam_sam_note/windows-sysmon.log diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index dee1f2d11d..b0602294d1 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -39,3 +39,6 @@ tags: - DE.CM security_domain: endpoint asset_type: Endpoint + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/scheduled_task_name_used_by_dragonfly_threat_actors.yml b/detections/endpoint/scheduled_task_name_used_by_dragonfly_threat_actors.yml index bed8cbadfd..7e0f13f819 100644 --- a/detections/endpoint/scheduled_task_name_used_by_dragonfly_threat_actors.yml +++ b/detections/endpoint/scheduled_task_name_used_by_dragonfly_threat_actors.yml @@ -1,7 +1,7 @@ name: Scheduled Task Name Used by Dragonfly Threat Actors id: d5af132c-7c17-439c-9d31-13d55340f36c -version: 4 -date: '2020-07-21' +version: 5 +date: '2020-12-07' description: This search looks for flags passed to schtasks.exe on the command-line that indicate a task name associated with the Dragonfly threat actor was created or deleted. @@ -14,10 +14,10 @@ references: [] author: Bhavin Patel, Splunk search: '| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime - max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe by - Processes.user Processes.process_name Processes.parent_process_name Processes.dest | - `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` - | search (process=*delete* OR process=*create*) process=*reset* | `scheduled_task_name_used_by_dragonfly_threat_actors_filter` ' + max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe + (Processes.process=*delete* OR Processes.process=*create*) by Processes.user Processes.process_name + Processes.parent_process_name Processes.dest | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `scheduled_task_name_used_by_dragonfly_threat_actors_filter` ' known_false_positives: No known false positives tags: analytics_story: @@ -32,3 +32,6 @@ tags: - PR.IP security_domain: endpoint asset_type: Endpoint + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index 794b407b88..575bde45d7 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -14,10 +14,10 @@ references: [] author: David Dorsey, Splunk search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = schtasks.exe - Processes.process="*/create*" Processes.process="* /s *" by Processes.process_name - Processes.process Processes.parent_process_name Processes.dest Processes.user | - `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `schtasks_scheduling_job_on_remote_system_filter`' + Processes.process="*/create*" (Processes.process="* /s *" OR Processes.process="* + /S *") by Processes.process_name Processes.process Processes.parent_process_name + Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `schtasks_scheduling_job_on_remote_system_filter`' known_false_positives: Administrators may create jobs on remote systems, but this activity is usually limited to a small set of hosts or users. It is important to validate and investigate as appropriate. @@ -36,4 +36,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1053.005/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index f816c9c4c6..a31a1614f0 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -1,7 +1,7 @@ name: Schtasks used for forcing a reboot id: 1297fb80-f42a-4b4a-9c8a-88c066437cf6 -version: 3 -date: '2020-07-21' +version: 4 +date: '2020-12-07' description: This search looks for flags passed to schtasks.exe on the command-line that indicate that a forced reboot of system is scheduled. how_to_implement: To successfully implement this search you need to be ingesting logs @@ -12,8 +12,8 @@ references: [] author: Bhavin Patel, Splunk search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where Processes.process_name = schtasks.exe Processes.process="*shutdown*" Processes.process="*/r*" - Processes.process="*/f*" by Processes.process_name Processes.parent_process_name + where Processes.process_name=schtasks.exe Processes.process="*shutdown*" Processes.process="*/create *" + by Processes.process_name Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `schtasks_used_for_forcing_a_reboot_filter`' known_false_positives: Administrators may create jobs on systems forcing reboots to diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index 4a81b55e30..6b23449e1d 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -36,4 +36,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1546.011/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index 5290d63bed..230328d096 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -32,6 +32,6 @@ tags: asset_type: Windows automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-security.log - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-system.log - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index 4160e21447..b1539438c7 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -44,4 +44,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1112/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/system_information_discovery_detection.yml b/detections/endpoint/system_information_discovery_detection.yml index 3f3c7857ab..f387a25d9b 100644 --- a/detections/endpoint/system_information_discovery_detection.yml +++ b/detections/endpoint/system_information_discovery_detection.yml @@ -33,4 +33,4 @@ tags: security_domain: endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1082/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1082/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index 8cbf67aa71..ab71a6d9a4 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -37,4 +37,4 @@ tags: asset_type: '' automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1562.001/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log diff --git a/detections/endpoint/windows_event_log_cleared.yml b/detections/endpoint/windows_event_log_cleared.yml index 0cc3036056..80d29d1d26 100644 --- a/detections/endpoint/windows_event_log_cleared.yml +++ b/detections/endpoint/windows_event_log_cleared.yml @@ -37,5 +37,5 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1070.001/windows-security.log - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1070.001/windows-system.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-security.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-system.log diff --git a/detections/endpoint/windows_security_account_manager_stopped.yml b/detections/endpoint/windows_security_account_manager_stopped.yml index b086be3713..0135e3d661 100644 --- a/detections/endpoint/windows_security_account_manager_stopped.yml +++ b/detections/endpoint/windows_security_account_manager_stopped.yml @@ -35,4 +35,4 @@ tags: asset_type: Endpoint automated_detection_testing: passed dataset: - - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/malware/ryuk/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log diff --git a/tests/application/first_time_seen_child_process_of_zoom.test.yml b/tests/application/first_time_seen_child_process_of_zoom.test.yml index 2eca32b7b5..a6d3c1df18 100644 --- a/tests/application/first_time_seen_child_process_of_zoom.test.yml +++ b/tests/application/first_time_seen_child_process_of_zoom.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1068_custom_888ee699-7f28-4c16-85e5-d5d88aa6cdcd/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/cloud/abnormally_high_cloud_instances_destroyed.test.yml b/tests/cloud/abnormally_high_cloud_instances_destroyed.test.yml index 3f61ea9962..b8a090368e 100644 --- a/tests/cloud/abnormally_high_cloud_instances_destroyed.test.yml +++ b/tests/cloud/abnormally_high_cloud_instances_destroyed.test.yml @@ -5,17 +5,15 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Baseline Of Cloud Instances Launched file: baselines/baseline_of_cloud_instances_destroyed.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/abnormally_high_cloud_instances_launched.test.yml b/tests/cloud/abnormally_high_cloud_instances_launched.test.yml index ab15067788..3237f22696 100644 --- a/tests/cloud/abnormally_high_cloud_instances_launched.test.yml +++ b/tests/cloud/abnormally_high_cloud_instances_launched.test.yml @@ -5,17 +5,15 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Baseline Of Cloud Instances Launched file: baselines/baseline_of_cloud_instances_launched.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.test.yml b/tests/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.test.yml index ddd41ce163..c9943d8552 100644 --- a/tests/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.test.yml +++ b/tests/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.test.yml @@ -5,17 +5,15 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Baseline Of Cloud Infrastructure API Calls Per User file: baselines/baseline_of_cloud_infrastructure_api_calls_per_user.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/abnormally_high_number_of_cloud_security_group_api_calls.test.yml b/tests/cloud/abnormally_high_number_of_cloud_security_group_api_calls.test.yml index 1f23dbd74d..050d9eaf1f 100644 --- a/tests/cloud/abnormally_high_number_of_cloud_security_group_api_calls.test.yml +++ b/tests/cloud/abnormally_high_number_of_cloud_security_group_api_calls.test.yml @@ -5,17 +5,15 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Baseline Of Cloud Security Group API Calls Per User file: baselines/baseline_of_cloud_security_group_api_calls_per_user.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/aws_cross_account_activity_from_previously_unseen_account.test.yml b/tests/cloud/aws_cross_account_activity_from_previously_unseen_account.test.yml index 5f40139464..7135ebd7ae 100644 --- a/tests/cloud/aws_cross_account_activity_from_previously_unseen_account.test.yml +++ b/tests/cloud/aws_cross_account_activity_from_previously_unseen_account.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen AWS Cross Account Activity - Initial file: baselines/previously_seen_aws_cross_account_activity_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen AWS Cross Account Activity - Update file: baselines/previously_seen_aws_cross_account_activity_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/cloud_api_calls_from_previously_unseen_user_roles.test.yml b/tests/cloud/cloud_api_calls_from_previously_unseen_user_roles.test.yml index 15ea3c2a26..47371cb887 100644 --- a/tests/cloud/cloud_api_calls_from_previously_unseen_user_roles.test.yml +++ b/tests/cloud/cloud_api_calls_from_previously_unseen_user_roles.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Cloud API Calls Per User Role - Initial file: baselines/previously_seen_cloud_api_calls_per_user_role_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Cloud API Calls Per User Role - Update file: baselines/previously_seen_cloud_api_calls_per_user_role_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/cloud_compute_instance_created_by_previously_unseen_user.test.yml b/tests/cloud/cloud_compute_instance_created_by_previously_unseen_user.test.yml index 78c5c3aa3d..34ff1d2ad6 100644 --- a/tests/cloud/cloud_compute_instance_created_by_previously_unseen_user.test.yml +++ b/tests/cloud/cloud_compute_instance_created_by_previously_unseen_user.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Cloud Compute Creations By User - Initial file: baselines/previously_seen_cloud_compute_creations_by_user_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Cloud Compute Creations By User - Update file: baselines/previously_seen_cloud_compute_creations_by_user_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/cloud_compute_instance_created_in_previously_unused_region.test.yml b/tests/cloud/cloud_compute_instance_created_in_previously_unused_region.test.yml index c0fcf50a38..4aaf714aa3 100644 --- a/tests/cloud/cloud_compute_instance_created_in_previously_unused_region.test.yml +++ b/tests/cloud/cloud_compute_instance_created_in_previously_unused_region.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| outputlookup test_1.csv | stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Cloud Regions - Initial file: baselines/previously_seen_cloud_regions_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Cloud Regions - Update file: baselines/previously_seen_cloud_regions_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/cloud_compute_instance_created_with_previously_unseen_image.test.yml b/tests/cloud/cloud_compute_instance_created_with_previously_unseen_image.test.yml index 006ac5620e..22263f5b15 100644 --- a/tests/cloud/cloud_compute_instance_created_with_previously_unseen_image.test.yml +++ b/tests/cloud/cloud_compute_instance_created_with_previously_unseen_image.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Cloud Compute Images - Initial file: baselines/previously_seen_cloud_compute_images_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Cloud Compute Images - Update file: baselines/previously_seen_cloud_compute_images_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.test.yml b/tests/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.test.yml index d6415f7904..ace490888d 100644 --- a/tests/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.test.yml +++ b/tests/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.test.yml @@ -5,25 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Cloud Compute Instance Types - Initial file: baselines/previously_seen_cloud_compute_instance_types_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - - name: Previously Seen Cloud Compute Instance Types - Update file: baselines/previously_seen_cloud_compute_instance_types_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/cloud_instance_modified_with_previously_unseen_user.test.yml b/tests/cloud/cloud_instance_modified_with_previously_unseen_user.test.yml index ccbb1ff50c..bdf58b91f8 100644 --- a/tests/cloud/cloud_instance_modified_with_previously_unseen_user.test.yml +++ b/tests/cloud/cloud_instance_modified_with_previously_unseen_user.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Cloud Instance Modifications By User - Initial file: baselines/previously_seen_cloud_instance_modifications_by_user_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Cloud Instance Modifications By User - Update file: baselines/previously_seen_cloud_instance_modifications_by_user_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/cloud_provisioning_from_previously_unseen_city.test.yml b/tests/cloud/cloud_provisioning_from_previously_unseen_city.test.yml index 199cee5486..207ea9898d 100644 --- a/tests/cloud/cloud_provisioning_from_previously_unseen_city.test.yml +++ b/tests/cloud/cloud_provisioning_from_previously_unseen_city.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Cloud Provisioning Activity Sources - Initial file: baselines/previously_seen_cloud_provisioning_activity_sources_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Cloud Provisioning Activity Sources - Update file: baselines/previously_seen_cloud_provisioning_activity_sources_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/cloud_provisioning_from_previously_unseen_country.test.yml b/tests/cloud/cloud_provisioning_from_previously_unseen_country.test.yml index c0b2ea455d..d095d33251 100644 --- a/tests/cloud/cloud_provisioning_from_previously_unseen_country.test.yml +++ b/tests/cloud/cloud_provisioning_from_previously_unseen_country.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Cloud Provisioning Activity Sources - Initial file: baselines/previously_seen_cloud_provisioning_activity_sources_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Cloud Provisioning Activity Sources - Update file: baselines/previously_seen_cloud_provisioning_activity_sources_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/cloud_provisioning_from_previously_unseen_ip_address.test.yml b/tests/cloud/cloud_provisioning_from_previously_unseen_ip_address.test.yml index 1eda84d927..ee410cda1d 100644 --- a/tests/cloud/cloud_provisioning_from_previously_unseen_ip_address.test.yml +++ b/tests/cloud/cloud_provisioning_from_previously_unseen_ip_address.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Cloud Provisioning Activity Sources - Initial file: baselines/previously_seen_cloud_provisioning_activity_sources_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Cloud Provisioning Activity Sources - Update file: baselines/previously_seen_cloud_provisioning_activity_sources_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/cloud_provisioning_from_previously_unseen_region.test.yml b/tests/cloud/cloud_provisioning_from_previously_unseen_region.test.yml index e6b710eff5..d4d7c727ec 100644 --- a/tests/cloud/cloud_provisioning_from_previously_unseen_region.test.yml +++ b/tests/cloud/cloud_provisioning_from_previously_unseen_region.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Cloud Provisioning Activity Sources - Initial file: baselines/previously_seen_cloud_provisioning_activity_sources_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Cloud Provisioning Activity Sources - Update file: baselines/previously_seen_cloud_provisioning_activity_sources_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/detect_aws_console_login_by_new_user.test.yml b/tests/cloud/detect_aws_console_login_by_new_user.test.yml index 54a02cf2f3..6e0fdf4290 100644 --- a/tests/cloud/detect_aws_console_login_by_new_user.test.yml +++ b/tests/cloud/detect_aws_console_login_by_new_user.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Users In Cloudtrail - Initial file: baselines/previously_seen_users_in_cloudtrail_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Users In Cloudtrail - Update file: baselines/previously_seen_users_in_cloudtrail_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/detect_aws_console_login_by_user_from_new_city.test.yml b/tests/cloud/detect_aws_console_login_by_user_from_new_city.test.yml index 9d8b60402a..e032cbbd35 100644 --- a/tests/cloud/detect_aws_console_login_by_user_from_new_city.test.yml +++ b/tests/cloud/detect_aws_console_login_by_user_from_new_city.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Users In Cloudtrail - Initial file: baselines/previously_seen_users_in_cloudtrail_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Users In Cloudtrail - Update file: baselines/previously_seen_users_in_cloudtrail_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/detect_aws_console_login_by_user_from_new_country.test.yml b/tests/cloud/detect_aws_console_login_by_user_from_new_country.test.yml index fe3a3fa513..691c5fa5af 100644 --- a/tests/cloud/detect_aws_console_login_by_user_from_new_country.test.yml +++ b/tests/cloud/detect_aws_console_login_by_user_from_new_country.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Users In Cloudtrail - Initial file: baselines/previously_seen_users_in_cloudtrail_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Users In Cloudtrail - Update file: baselines/previously_seen_users_in_cloudtrail_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/cloud/detect_aws_console_login_by_user_from_new_region.test.yml b/tests/cloud/detect_aws_console_login_by_user_from_new_region.test.yml index 66d65a9834..9ea20d1e25 100644 --- a/tests/cloud/detect_aws_console_login_by_user_from_new_region.test.yml +++ b/tests/cloud/detect_aws_console_login_by_user_from_new_region.test.yml @@ -5,23 +5,20 @@ tests: pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' - baselines: - name: Previously Seen Users In Cloudtrail - Initial file: baselines/previously_seen_users_in_cloudtrail_initial.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - - name: Previously Seen Users In Cloudtrail - Update file: baselines/previously_seen_users_in_cloudtrail_update.yml pass_condition: '| stats count | where count > 0' earliest_time: '-30d' latest_time: '-1d' - attack_data: - file_name: cloudtrail_behavioural_detections.json - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/cloudtrail_behavioural_detections/cloudtrail_behavioural_detections.json + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json sourcetype: aws:cloudtrail source: aws_cloudtrail update_timestamp: True diff --git a/tests/endpoint/access_lsass_memory_for_dump_creation.test.yml b/tests/endpoint/access_lsass_memory_for_dump_creation.test.yml index 512a805a4c..32e5fb0e48 100644 --- a/tests/endpoint/access_lsass_memory_for_dump_creation.test.yml +++ b/tests/endpoint/access_lsass_memory_for_dump_creation.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.001/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/attempt_to_add_certificate_to_untrusted_store.test.yml b/tests/endpoint/attempt_to_add_certificate_to_untrusted_store.test.yml index c9c2999302..219a30bb77 100644 --- a/tests/endpoint/attempt_to_add_certificate_to_untrusted_store.test.yml +++ b/tests/endpoint/attempt_to_add_certificate_to_untrusted_store.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1553.004/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1553.004/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/attempt_to_stop_security_service.test.yml b/tests/endpoint/attempt_to_stop_security_service.test.yml index 111127ba6a..52c5b74a41 100644 --- a/tests/endpoint/attempt_to_stop_security_service.test.yml +++ b/tests/endpoint/attempt_to_stop_security_service.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1562.001_custom_f3b70c45-3f9f-493d-b0b0-6be2ad9f158b/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/attempted_credential_dump_from_registry_via_reg_exe.test.yml b/tests/endpoint/attempted_credential_dump_from_registry_via_reg_exe.test.yml index 0b90d591ae..e7b5427519 100644 --- a/tests/endpoint/attempted_credential_dump_from_registry_via_reg_exe.test.yml +++ b/tests/endpoint/attempted_credential_dump_from_registry_via_reg_exe.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.002/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/batch_file_write_to_system32.test.yml b/tests/endpoint/batch_file_write_to_system32.test.yml index 9cad12de4d..67c92e718f 100644 --- a/tests/endpoint/batch_file_write_to_system32.test.yml +++ b/tests/endpoint/batch_file_write_to_system32.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1204.002_custom_b0162b8c-686d-4d97-83fe-7e80ac679cf4/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/common_ransomware_extensions.test.yml b/tests/endpoint/common_ransomware_extensions.test.yml index 7b25f92a64..8b39aa3e04 100644 --- a/tests/endpoint/common_ransomware_extensions.test.yml +++ b/tests/endpoint/common_ransomware_extensions.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1485_custom_215ee4f9-c027-4ea1-a882-d97b887d233d/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_extensions/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/common_ransomware_notes.test.yml b/tests/endpoint/common_ransomware_notes.test.yml index f49e745352..e3847c089c 100644 --- a/tests/endpoint/common_ransomware_notes.test.yml +++ b/tests/endpoint/common_ransomware_notes.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1485_custom_cc81aa13-3899-4d33-b5c5-8a6e30eca28b/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/create_local_admin_accounts_using_net_exe.test.yml b/tests/endpoint/create_local_admin_accounts_using_net_exe.test.yml index db9ee558ee..59960fe704 100644 --- a/tests/endpoint/create_local_admin_accounts_using_net_exe.test.yml +++ b/tests/endpoint/create_local_admin_accounts_using_net_exe.test.yml @@ -7,16 +7,16 @@ tests: latest_time: 'now' attack_data: - file_name: windows-security.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log source: WinEventLog:Security sourcetype: WinEventLog update_timestamp: True - file_name: windows-system.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-system.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log source: WinEventLog:System sourcetype: WinEventLog update_timestamp: True - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/create_remote_thread_into_lsass.test.yml b/tests/endpoint/create_remote_thread_into_lsass.test.yml index a65d0812df..b2928902c8 100644 --- a/tests/endpoint/create_remote_thread_into_lsass.test.yml +++ b/tests/endpoint/create_remote_thread_into_lsass.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.001/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/creation_of_shadow_copy.test.yml b/tests/endpoint/creation_of_shadow_copy.test.yml index fdfef47f59..6e9ec70756 100644 --- a/tests/endpoint/creation_of_shadow_copy.test.yml +++ b/tests/endpoint/creation_of_shadow_copy.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.003/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.test.yml b/tests/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.test.yml index 1dbcceaaad..b459c7285d 100644 --- a/tests/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.test.yml +++ b/tests/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.003/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/credential_dumping_via_copy_command_from_shadow_copy.test.yml b/tests/endpoint/credential_dumping_via_copy_command_from_shadow_copy.test.yml index 57b3fb8c09..70d467b581 100644 --- a/tests/endpoint/credential_dumping_via_copy_command_from_shadow_copy.test.yml +++ b/tests/endpoint/credential_dumping_via_copy_command_from_shadow_copy.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.003/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/credential_dumping_via_symlink_to_shadow_copy.test.yml b/tests/endpoint/credential_dumping_via_symlink_to_shadow_copy.test.yml index 3ddbbefe40..9652fdc7c7 100644 --- a/tests/endpoint/credential_dumping_via_symlink_to_shadow_copy.test.yml +++ b/tests/endpoint/credential_dumping_via_symlink_to_shadow_copy.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.003/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.003/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/deleting_shadow_copies.test.yml b/tests/endpoint/deleting_shadow_copies.test.yml index 35dabdf507..90a3f3634d 100644 --- a/tests/endpoint/deleting_shadow_copies.test.yml +++ b/tests/endpoint/deleting_shadow_copies.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1490/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/detect_activity_related_to_pass_the_hash_attacks.test.yml b/tests/endpoint/detect_activity_related_to_pass_the_hash_attacks.test.yml index 9f65b07351..b25fcd573d 100644 --- a/tests/endpoint/detect_activity_related_to_pass_the_hash_attacks.test.yml +++ b/tests/endpoint/detect_activity_related_to_pass_the_hash_attacks.test.yml @@ -7,7 +7,7 @@ tests: latest_time: 'now' attack_data: - file_name: windows-security.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1550.002/windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.002/atomic_red_team/windows-security.log source: WinEventLog:Security sourcetype: WinEventLog update_timestamp: True diff --git a/tests/endpoint/detect_credential_dumping_through_lsass_access.test.yml b/tests/endpoint/detect_credential_dumping_through_lsass_access.test.yml index 0183ba29e4..5ade33c888 100644 --- a/tests/endpoint/detect_credential_dumping_through_lsass_access.test.yml +++ b/tests/endpoint/detect_credential_dumping_through_lsass_access.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.001/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/detect_excessive_account_lockouts_from_endpoint.test.yml b/tests/endpoint/detect_excessive_account_lockouts_from_endpoint.test.yml index 80eba46094..73527c9d74 100644 --- a/tests/endpoint/detect_excessive_account_lockouts_from_endpoint.test.yml +++ b/tests/endpoint/detect_excessive_account_lockouts_from_endpoint.test.yml @@ -7,12 +7,12 @@ tests: latest_time: 'now' attack_data: - file_name: windows-security.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1078.002_custom_49a0e495-4ecd-41e4-a9c7-4c0a1e841ba6/windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-security.log source: WinEventLog:Security sourcetype: WinEventLog update_timestamp: True - file_name: windows-system.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1078.002_custom_49a0e495-4ecd-41e4-a9c7-4c0a1e841ba6/windows-system.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-system.log source: WinEventLog:System sourcetype: WinEventLog update_timestamp: True diff --git a/tests/endpoint/detect_excessive_user_account_lockouts.test.yml b/tests/endpoint/detect_excessive_user_account_lockouts.test.yml index 72ec355c70..f45e293e67 100644 --- a/tests/endpoint/detect_excessive_user_account_lockouts.test.yml +++ b/tests/endpoint/detect_excessive_user_account_lockouts.test.yml @@ -7,12 +7,12 @@ tests: latest_time: 'now' attack_data: - file_name: windows-security.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1078.002_custom_49a0e495-4ecd-41e4-a9c7-4c0a1e841ba6/windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-security.log source: WinEventLog:Security sourcetype: WinEventLog update_timestamp: True - file_name: windows-system.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1078.002_custom_49a0e495-4ecd-41e4-a9c7-4c0a1e841ba6/windows-system.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/account_lockout/windows-system.log source: WinEventLog:System sourcetype: WinEventLog update_timestamp: True diff --git a/tests/endpoint/detect_mshta_exe_running_scripts_in_command_line_arguments.test.yml b/tests/endpoint/detect_mshta_exe_running_scripts_in_command_line_arguments.test.yml index efd571a90e..ae75a6fcfd 100644 --- a/tests/endpoint/detect_mshta_exe_running_scripts_in_command_line_arguments.test.yml +++ b/tests/endpoint/detect_mshta_exe_running_scripts_in_command_line_arguments.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1218.005/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/detect_new_local_admin_account.test.yml b/tests/endpoint/detect_new_local_admin_account.test.yml index 442265fd43..077dbc6c73 100644 --- a/tests/endpoint/detect_new_local_admin_account.test.yml +++ b/tests/endpoint/detect_new_local_admin_account.test.yml @@ -7,16 +7,16 @@ tests: latest_time: 'now' attack_data: - file_name: windows-security.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log source: WinEventLog:Security sourcetype: WinEventLog update_timestamp: True - file_name: windows-system.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-system.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log source: WinEventLog:System sourcetype: WinEventLog update_timestamp: True - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/detect_path_interception_by_creation_of_program_exe.test.yml b/tests/endpoint/detect_path_interception_by_creation_of_program_exe.test.yml index bce5e449dd..040deaff7d 100644 --- a/tests/endpoint/detect_path_interception_by_creation_of_program_exe.test.yml +++ b/tests/endpoint/detect_path_interception_by_creation_of_program_exe.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1574.009/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.009/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/detect_processes_used_for_system_network_configuration_discovery.test.yml b/tests/endpoint/detect_processes_used_for_system_network_configuration_discovery.test.yml index 4f06ede12e..682689415e 100644 --- a/tests/endpoint/detect_processes_used_for_system_network_configuration_discovery.test.yml +++ b/tests/endpoint/detect_processes_used_for_system_network_configuration_discovery.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1016_custom_10e3118d-3785-4197-8152-1bf68a4c617e/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/discovery_commands/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/detect_psexec_with_accepteula_flag.test.yml b/tests/endpoint/detect_psexec_with_accepteula_flag.test.yml index c4169ef67a..c922de8c5d 100644 --- a/tests/endpoint/detect_psexec_with_accepteula_flag.test.yml +++ b/tests/endpoint/detect_psexec_with_accepteula_flag.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1021.002/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.002/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.test.yml b/tests/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.test.yml index 367afcc9a9..bd3a0ee8ef 100644 --- a/tests/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.test.yml +++ b/tests/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1059.003_custom_a43d29e4-3a56-4208-a0a2-44e6045f3c48/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/cmd_spawns_cscript/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/disabling_remote_user_account_control.test.yml b/tests/endpoint/disabling_remote_user_account_control.test.yml index 1d80a5a4c8..13c931be83 100644 --- a/tests/endpoint/disabling_remote_user_account_control.test.yml +++ b/tests/endpoint/disabling_remote_user_account_control.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1548.002/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/dump_lsass_via_comsvcs_dll.test.yml b/tests/endpoint/dump_lsass_via_comsvcs_dll.test.yml index e8a0c3a3ab..595eb54e8b 100644 --- a/tests/endpoint/dump_lsass_via_comsvcs_dll.test.yml +++ b/tests/endpoint/dump_lsass_via_comsvcs_dll.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.001/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/execution_of_file_with_multiple_extensions.test.yml b/tests/endpoint/execution_of_file_with_multiple_extensions.test.yml index 1efda160c5..f32e552456 100644 --- a/tests/endpoint/execution_of_file_with_multiple_extensions.test.yml +++ b/tests/endpoint/execution_of_file_with_multiple_extensions.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1036.003/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/file_with_samsam_extension.test.yml b/tests/endpoint/file_with_samsam_extension.test.yml index dc75ea39e4..5f958265a2 100644 --- a/tests/endpoint/file_with_samsam_extension.test.yml +++ b/tests/endpoint/file_with_samsam_extension.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1036.003_custom_b4e0d323-9d98-4092-9757-032b598652bc/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/samsam_extension/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/hiding_files_and_directories_with_attrib_exe.test.yml b/tests/endpoint/hiding_files_and_directories_with_attrib_exe.test.yml index a3fdc32b1a..e8b864c8aa 100644 --- a/tests/endpoint/hiding_files_and_directories_with_attrib_exe.test.yml +++ b/tests/endpoint/hiding_files_and_directories_with_attrib_exe.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1222.001/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/kerberoasting_spn_request_with_rc4_encryption.test.yml b/tests/endpoint/kerberoasting_spn_request_with_rc4_encryption.test.yml index 4a6bafe158..5ae101f436 100644 --- a/tests/endpoint/kerberoasting_spn_request_with_rc4_encryption.test.yml +++ b/tests/endpoint/kerberoasting_spn_request_with_rc4_encryption.test.yml @@ -7,7 +7,7 @@ tests: latest_time: 'now' attack_data: - file_name: windows-security.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1558.003/windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-security.log source: WinEventLog:Security sourcetype: WinEventLog update_timestamp: True diff --git a/tests/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.test.yml b/tests/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.test.yml index 01414f4e2c..98b7dc80c1 100644 --- a/tests/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.test.yml +++ b/tests/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1059.001_custom_03e301be-1bfc-4051-af4d-d0865079fb27/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/hidden_powershell/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/malicious_powershell_process___encoded_command.test.yml b/tests/endpoint/malicious_powershell_process___encoded_command.test.yml index 7017ff779f..3dfa039f34 100644 --- a/tests/endpoint/malicious_powershell_process___encoded_command.test.yml +++ b/tests/endpoint/malicious_powershell_process___encoded_command.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1027/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1027/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/malicious_powershell_process___execution_policy_bypass.yml.test.yml b/tests/endpoint/malicious_powershell_process___execution_policy_bypass.yml.test.yml deleted file mode 100644 index d89d090d45..0000000000 --- a/tests/endpoint/malicious_powershell_process___execution_policy_bypass.yml.test.yml +++ /dev/null @@ -1,12 +0,0 @@ -name: Malicious PowerShell Process - Execution Policy Bypass Unit Test -tests: -- name: Malicious PowerShell Process - Execution Policy Bypass - file: endpoint/malicious_powershell_process___execution_policy_bypass.yml - pass_condition: '| stats count | where count > 0' - earliest_time: '-24h' - latest_time: 'now' - attack_data: - - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1059.001/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog diff --git a/tests/endpoint/monitor_registry_keys_for_print_monitors.test.yml b/tests/endpoint/monitor_registry_keys_for_print_monitors.test.yml index 3b6954f5ba..15dfacbedd 100644 --- a/tests/endpoint/monitor_registry_keys_for_print_monitors.test.yml +++ b/tests/endpoint/monitor_registry_keys_for_print_monitors.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1547.010/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/overwriting_accessibility_binaries.test.yml b/tests/endpoint/overwriting_accessibility_binaries.test.yml index acc4e24834..c6995e656d 100644 --- a/tests/endpoint/overwriting_accessibility_binaries.test.yml +++ b/tests/endpoint/overwriting_accessibility_binaries.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1546.008/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.008/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/process_execution_via_wmi.test.yml b/tests/endpoint/process_execution_via_wmi.test.yml index e91c5e6b42..3c1b9ee8b9 100644 --- a/tests/endpoint/process_execution_via_wmi.test.yml +++ b/tests/endpoint/process_execution_via_wmi.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1047/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/processes_launching_netsh.test.yml b/tests/endpoint/processes_launching_netsh.test.yml index 8a619d7cf1..e41eb12b67 100644 --- a/tests/endpoint/processes_launching_netsh.test.yml +++ b/tests/endpoint/processes_launching_netsh.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1562.004/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.004/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/reg_exe_manipulating_windows_services_registry_keys.test.yml b/tests/endpoint/reg_exe_manipulating_windows_services_registry_keys.test.yml index 755f5a9731..785d4a54d8 100644 --- a/tests/endpoint/reg_exe_manipulating_windows_services_registry_keys.test.yml +++ b/tests/endpoint/reg_exe_manipulating_windows_services_registry_keys.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1574.011_custom_eb03d0db-448b-446f-8b46-d9bc39cc8cc7/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.011/change_registry_path_service/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/registry_keys_for_creating_shim_databases.test.yml b/tests/endpoint/registry_keys_for_creating_shim_databases.test.yml index 9bf770faa5..2998d6ef4e 100644 --- a/tests/endpoint/registry_keys_for_creating_shim_databases.test.yml +++ b/tests/endpoint/registry_keys_for_creating_shim_databases.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1546.011/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/registry_keys_used_for_persistence.yml.test.yml b/tests/endpoint/registry_keys_used_for_persistence.yml.test.yml index 97fa1b2abe..c834ea65e7 100644 --- a/tests/endpoint/registry_keys_used_for_persistence.yml.test.yml +++ b/tests/endpoint/registry_keys_used_for_persistence.yml.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1547.001/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/registry_keys_used_for_privilege_escalation.test.yml b/tests/endpoint/registry_keys_used_for_privilege_escalation.test.yml index 39fa72a460..3866f1553e 100644 --- a/tests/endpoint/registry_keys_used_for_privilege_escalation.test.yml +++ b/tests/endpoint/registry_keys_used_for_privilege_escalation.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1546.012/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.012/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/remote_process_instantiation_via_wmi.test.yml b/tests/endpoint/remote_process_instantiation_via_wmi.test.yml index dcfe0863d4..f72b2f0cd2 100644 --- a/tests/endpoint/remote_process_instantiation_via_wmi.test.yml +++ b/tests/endpoint/remote_process_instantiation_via_wmi.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1047/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/rundll_loading_dll_by_ordinal.test.yml b/tests/endpoint/rundll_loading_dll_by_ordinal.test.yml index d26ebdee95..713662f1ea 100644 --- a/tests/endpoint/rundll_loading_dll_by_ordinal.test.yml +++ b/tests/endpoint/rundll_loading_dll_by_ordinal.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1218.011/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/ryuk_test_files_detected.test.yml b/tests/endpoint/ryuk_test_files_detected.test.yml index 27562c65c1..dbf2b6774a 100644 --- a/tests/endpoint/ryuk_test_files_detected.test.yml +++ b/tests/endpoint/ryuk_test_files_detected.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/malware/ryuk/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/samsam_test_file_write.test.yml b/tests/endpoint/samsam_test_file_write.test.yml new file mode 100644 index 0000000000..90c8081027 --- /dev/null +++ b/tests/endpoint/samsam_test_file_write.test.yml @@ -0,0 +1,12 @@ +name: Samsam Test File Write Unit Test +tests: +- name: Samsam Test File Write + file: endpoint/samsam_test_file_write.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/sam_sam_note/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog diff --git a/tests/endpoint/sc_exe_manipulating_windows_services.test.yml b/tests/endpoint/sc_exe_manipulating_windows_services.test.yml new file mode 100644 index 0000000000..3586ea409a --- /dev/null +++ b/tests/endpoint/sc_exe_manipulating_windows_services.test.yml @@ -0,0 +1,12 @@ +name: Sc exe Manipulating Windows Services Unit Test +tests: +- name: Sc exe Manipulating Windows Services + file: endpoint/sc_exe_manipulating_windows_services.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog diff --git a/tests/endpoint/scheduled_task_name_used_by_dragonfly_threat_actors.test.yml b/tests/endpoint/scheduled_task_name_used_by_dragonfly_threat_actors.test.yml new file mode 100644 index 0000000000..1760563c40 --- /dev/null +++ b/tests/endpoint/scheduled_task_name_used_by_dragonfly_threat_actors.test.yml @@ -0,0 +1,12 @@ +name: Scheduled Task Name Used by Dragonfly Threat Actors Unit Test +tests: +- name: Scheduled Task Name Used by Dragonfly Threat Actors + file: endpoint/scheduled_task_name_used_by_dragonfly_threat_actors.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog diff --git a/tests/endpoint/schtasks_scheduling_job_on_remote_system.test.yml b/tests/endpoint/schtasks_scheduling_job_on_remote_system.test.yml index 9c42a6ce2f..9570ac3e86 100644 --- a/tests/endpoint/schtasks_scheduling_job_on_remote_system.test.yml +++ b/tests/endpoint/schtasks_scheduling_job_on_remote_system.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1053.005/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/schtasks_used_for_forcing_a_reboot.yml.test.yml b/tests/endpoint/schtasks_used_for_forcing_a_reboot.yml.test.yml new file mode 100644 index 0000000000..57f92f5a96 --- /dev/null +++ b/tests/endpoint/schtasks_used_for_forcing_a_reboot.yml.test.yml @@ -0,0 +1,12 @@ +name: Schtasks used for forcing a reboot Unit Test +tests: +- name: Schtasks used for forcing a reboot + file: endpoint/schtasks_used_for_forcing_a_reboot.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtask_shutdown/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog diff --git a/tests/endpoint/script_execution_via_wmi.test.yml b/tests/endpoint/script_execution_via_wmi.test.yml new file mode 100644 index 0000000000..c0a08ada19 --- /dev/null +++ b/tests/endpoint/script_execution_via_wmi.test.yml @@ -0,0 +1,12 @@ +name: Script Execution via WMI Unit Test +tests: +- name: Script Execution via WMI + file: endpoint/script_execution_via_wmi.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/execution_scrcons/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog diff --git a/tests/endpoint/shim_database_installation_with_suspicious_parameters.test.yml b/tests/endpoint/shim_database_installation_with_suspicious_parameters.test.yml index 0f3991fbc0..d3b872c17a 100644 --- a/tests/endpoint/shim_database_installation_with_suspicious_parameters.test.yml +++ b/tests/endpoint/shim_database_installation_with_suspicious_parameters.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1546.011/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.011/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/short_lived_windows_accounts.test.yml b/tests/endpoint/short_lived_windows_accounts.test.yml index 3691855f20..2aa1931f9f 100644 --- a/tests/endpoint/short_lived_windows_accounts.test.yml +++ b/tests/endpoint/short_lived_windows_accounts.test.yml @@ -7,16 +7,16 @@ tests: latest_time: 'now' attack_data: - file_name: windows-security.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-security.log source: WinEventLog:Security sourcetype: WinEventLog update_timestamp: True - file_name: windows-system.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-system.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-system.log source: WinEventLog:System sourcetype: WinEventLog update_timestamp: True - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1136.001/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/suspicious_reg_exe_process.test.yml b/tests/endpoint/suspicious_reg_exe_process.test.yml index 7ea26238d7..f02a0b7dd5 100644 --- a/tests/endpoint/suspicious_reg_exe_process.test.yml +++ b/tests/endpoint/suspicious_reg_exe_process.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1112/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/system_information_discovery_detection.test.yml b/tests/endpoint/system_information_discovery_detection.test.yml index 1162909efa..be9186f74c 100644 --- a/tests/endpoint/system_information_discovery_detection.test.yml +++ b/tests/endpoint/system_information_discovery_detection.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1082/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1082/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/unload_sysmon_filter_driver.test.yml b/tests/endpoint/unload_sysmon_filter_driver.test.yml index 7eea1bea29..c86771f240 100644 --- a/tests/endpoint/unload_sysmon_filter_driver.test.yml +++ b/tests/endpoint/unload_sysmon_filter_driver.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1562.001/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/endpoint/windows_event_log_cleared.test.yml b/tests/endpoint/windows_event_log_cleared.test.yml index be6b27ea31..c12d97e04f 100644 --- a/tests/endpoint/windows_event_log_cleared.test.yml +++ b/tests/endpoint/windows_event_log_cleared.test.yml @@ -7,12 +7,12 @@ tests: latest_time: 'now' attack_data: - file_name: windows-security.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1070.001/windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-security.log source: WinEventLog:Security sourcetype: WinEventLog update_timestamp: True - file_name: windows-system.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1070.001/windows-system.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-system.log source: WinEventLog:System sourcetype: WinEventLog update_timestamp: True diff --git a/tests/endpoint/windows_security_account_manager_stopped.test.yml b/tests/endpoint/windows_security_account_manager_stopped.test.yml index b040e53d91..79977e0d89 100644 --- a/tests/endpoint/windows_security_account_manager_stopped.test.yml +++ b/tests/endpoint/windows_security_account_manager_stopped.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/malware/ryuk/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog diff --git a/tests/network/detect_ipv6_network_infrastructure_threats.test.yml b/tests/network/detect_ipv6_network_infrastructure_threats.test.yml index cd4d1b0686..47aa86911a 100644 --- a/tests/network/detect_ipv6_network_infrastructure_threats.test.yml +++ b/tests/network/detect_ipv6_network_infrastructure_threats.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: cisco_ios.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1557.002/cisco_ios.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1557.002/cisco_ios/cisco_ios.log source: udp:514 sourcetype: cisco:ios diff --git a/tests/network/detect_snicat_sni_exfiltration.test.yml b/tests/network/detect_snicat_sni_exfiltration.test.yml index 33b1ceff83..119e1f72ca 100644 --- a/tests/network/detect_snicat_sni_exfiltration.test.yml +++ b/tests/network/detect_snicat_sni_exfiltration.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: zeek-ssl.log - data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1041/zeek-ssl.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1041/zeek_ssl/zeek_ssl.log source: zeek-ssl.log sourcetype: bro:ssl:json