From 343ceae12f99c3e76b1cfb3a148d6a158614344c Mon Sep 17 00:00:00 2001 From: tlangalia Date: Tue, 14 Dec 2021 13:27:55 +0550 Subject: [PATCH 01/25] Updated detection files with supported TA list. --- ...mber_of_cloud_infrastructure_api_calls.yml | 17 ++++++ ...mber_of_cloud_security_group_api_calls.yml | 16 +++++ ...alls_from_previously_unseen_user_roles.yml | 10 ++++ ...ance_created_by_previously_unseen_user.yml | 5 ++ ...ce_created_in_previously_unused_region.yml | 5 ++ ...e_created_with_previously_unseen_image.yml | 5 ++ ...d_with_previously_unseen_instance_type.yml | 5 ++ ...e_modified_with_previously_unseen_user.yml | 15 +++++ ...ovisioning_from_previously_unseen_city.yml | 15 +++++ ...sioning_from_previously_unseen_country.yml | 15 +++++ ...ning_from_previously_unseen_ip_address.yml | 13 ++++ ...isioning_from_previously_unseen_region.yml | 15 +++++ .../active_setup_registry_autostart.yml | 3 + ...d_defaultuser_and_password_in_registry.yml | 3 + ...ound_traffic_by_firewall_rule_registry.yml | 3 + .../allow_operation_with_consent_admin.yml | 3 + .../endpoint/anomalous_usage_of_7zip.yml | 3 + .../endpoint/attacker_tools_on_endpoint.yml | 4 ++ ..._to_add_certificate_to_untrusted_store.yml | 3 + .../auto_admin_logon_registry_entry.yml | 3 + .../endpoint/batch_file_write_to_system32.yml | 6 ++ ...dedit_command_back_to_normal_mode_boot.yml | 3 + .../bcdedit_failure_recovery_modification.yml | 4 ++ .../change_default_file_association.yml | 3 + ...hange_to_safe_mode_with_network_config.yml | 3 + .../check_elevated_cmd_using_whoami.yml | 3 + .../endpoint/detect_exchange_web_shell.yml | 4 ++ .../detect_rclone_command_line_usage.yml | 3 + .../detect_regasm_spawning_a_process.yml | 3 + .../detect_regsvcs_spawning_a_process.yml | 3 + ...tect_sharphound_command_line_arguments.yml | 3 + ..._cmd_exe_to_launch_script_interpreters.yml | 3 + .../disable_amsi_through_registry.yml | 3 + .../endpoint/disable_etw_through_registry.yml | 3 + .../endpoint/disable_logs_using_wevtutil.yml | 3 + detections/endpoint/disable_registry_tool.yml | 3 + detections/endpoint/disable_schedule_task.yml | 4 ++ .../endpoint/disable_windows_app_hotkeys.yml | 3 + .../disable_windows_behavior_monitoring.yml | 3 + .../endpoint/disabling_cmd_application.yml | 3 + .../endpoint/disabling_controlpanel.yml | 3 + ...isabling_folderoptions_windows_feature.yml | 3 + .../endpoint/disabling_norun_windows_app.yml | 3 + .../disabling_systemrestore_in_registry.yml | 3 + .../endpoint/disabling_task_manager.yml | 3 + .../domain_account_discovery_with_net_app.yml | 3 + .../domain_account_discovery_with_wmic.yml | 3 + .../endpoint/dsquery_domain_discovery.yml | 4 ++ .../endpoint/dump_lsass_via_procdump.yml | 4 ++ .../enable_rdp_in_other_port_number.yml | 3 + detections/endpoint/eventvwr_uac_bypass.yml | 3 + .../excessive_attempt_to_disable_services.yml | 4 ++ ...ocesses_created_in_windows_temp_folder.yml | 9 +++ ...r_of_service_control_start_as_disabled.yml | 3 + ...excessive_number_of_taskhost_processes.yml | 8 +++ .../endpoint/excessive_usage_of_cacls_app.yml | 4 ++ .../endpoint/excessive_usage_of_taskkill.yml | 4 ++ ..._or_script_creation_in_suspicious_path.yml | 4 ++ ...cute_javascript_with_jscript_com_clsid.yml | 3 + ...ution_of_file_with_multiple_extensions.yml | 4 ++ .../endpoint/file_with_samsam_extension.yml | 9 +++ .../firewall_allowed_program_enable.yml | 3 + detections/endpoint/fodhelper_uac_bypass.yml | 3 + detections/endpoint/fsutil_zeroing_file.yml | 3 + ...esultantpasswordpolicy_with_powershell.yml | 3 + .../get_domainpolicy_with_powershell.yml | 3 + .../get_domainuser_with_powershell.yml | 3 + .../getwmiobject_ds_user_with_powershell.yml | 3 + .../hide_user_account_from_sign_in_screen.yml | 3 + ..._files_and_directories_with_attrib_exe.yml | 4 ++ detections/endpoint/icacls_deny_command.yml | 4 ++ detections/endpoint/icacls_grant_command.yml | 4 ++ .../jscript_execution_using_cscript_app.yml | 3 + .../logon_script_event_trigger_execution.yml | 3 + ...dify_acl_permission_to_files_or_folder.yml | 4 ++ .../msmpeng_application_dll_side_loading.yml | 4 ++ .../endpoint/net_profiler_uac_bypass.yml | 3 + .../nltest_domain_trust_discovery.yml | 3 + detections/endpoint/ntdsutil_export_ntds.yml | 3 + .../overwriting_accessibility_binaries.yml | 10 ++++ ...mission_modification_using_takeown_app.yml | 3 + .../powershell_execute_com_object.yml | 59 +++++++++++++++++++ ...nt_automatic_repair_mode_using_bcdedit.yml | 3 + ...eating_lnk_file_in_suspicious_location.yml | 4 ++ .../endpoint/process_execution_via_wmi.yml | 4 ++ .../endpoint/processes_launching_netsh.yml | 3 + ...ulating_windows_services_registry_keys.yml | 4 ++ .../registry_keys_used_for_persistence.yml | 3 + .../endpoint/remote_wmi_command_attempt.yml | 3 + .../endpoint/resize_shadowstorage_volume.yml | 4 ++ .../endpoint/revil_common_exec_parameter.yml | 3 + detections/endpoint/revil_registry_entry.yml | 3 + .../endpoint/ryuk_wake_on_lan_command.yml | 3 + .../endpoint/samsam_test_file_write.yml | 9 +++ .../sc_exe_manipulating_windows_services.yml | 4 ++ ...eduled_task_deleted_or_created_via_cmd.yml | 3 + .../endpoint/schtasks_run_task_on_demand.yml | 4 ++ ...htasks_scheduling_job_on_remote_system.yml | 4 ++ .../schtasks_used_for_forcing_a_reboot.yml | 4 ++ .../screensaver_event_trigger_execution.yml | 3 + .../endpoint/script_execution_via_wmi.yml | 7 +++ detections/endpoint/sdclt_uac_bypass.yml | 3 + .../secretdumps_offline_ntds_dumping_tool.yml | 3 + detections/endpoint/services_escalate_exe.yml | 3 + ...ution_policy_to_unrestricted_or_bypass.yml | 3 + ...nstallation_with_suspicious_parameters.yml | 4 ++ .../endpoint/short_lived_windows_accounts.yml | 5 ++ .../endpoint/silentcleanup_uac_bypass.yml | 3 + .../single_letter_process_on_endpoint.yml | 7 +++ detections/endpoint/slui_runas_elevated.yml | 3 + .../endpoint/slui_spawning_a_process.yml | 3 + detections/endpoint/spoolsv_writing_a_dll.yml | 6 ++ .../start_up_during_safe_mode_boot.yml | 3 + .../suspicious_mshta_child_process.yml | 3 + .../endpoint/suspicious_process_file_path.yml | 3 + .../endpoint/suspicious_reg_exe_process.yml | 4 ++ ...s_scheduled_task_from_public_directory.yml | 3 + .../endpoint/suspicious_wevtutil_usage.yml | 4 ++ ...system_information_discovery_detection.yml | 7 +++ ...rocesses_run_from_unexpected_locations.yml | 4 ++ .../time_provider_persistence_registry.yml | 3 + ...d_messaging_service_spawning_a_process.yml | 3 + .../endpoint/uninstall_app_using_msiexec.yml | 3 + .../endpoint/unload_sysmon_filter_driver.yml | 4 ++ detections/endpoint/usn_journal_deletion.yml | 3 + .../wbadmin_delete_system_backups.yml | 4 ++ detections/endpoint/windows_adfind_exe.yml | 3 + .../windows_disableantispyware_reg.yml | 3 + detections/endpoint/wsreset_uac_bypass.yml | 3 + .../xsl_script_execution_with_wmic.yml | 10 +++- ...ormally_high_cloud_instances_destroyed.yml | 17 ++++++ ...normally_high_cloud_instances_launched.yml | 17 ++++++ .../print_processor_registry_autostart.yml | 3 + ...ry_length_with_high_standard_deviation.yml | 5 ++ 134 files changed, 672 insertions(+), 3 deletions(-) diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index 71e463fbf9..c1ebe53022 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -66,3 +66,20 @@ tags: - All_Changes.status risk_score: 15 security_domain: network + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_ossec + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_cisco-asa + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index 1228ec4926..b11de42774 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -72,3 +72,19 @@ tags: - All_Changes.user risk_score: 15 security_domain: network + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_ossec + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml index 0e1e20e231..c0858b13a2 100644 --- a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml +++ b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml @@ -68,3 +68,13 @@ tags: - All_Changes.object risk_score: 36 security_domain: threat + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - splunk_ta_o365 + - Splunk_TA_box + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index 43c8ea2de0..e800d33873 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -69,3 +69,8 @@ tags: - All_Changes.vendor_region risk_score: 18 security_domain: threat + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml index d8eace9970..40125905fe 100644 --- a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml +++ b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml @@ -74,3 +74,8 @@ tags: - All_Changes.user risk_score: 42 security_domain: threat + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml index 2fba8e45a1..f256ba5606 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml @@ -69,3 +69,8 @@ tags: - All_Changes.user risk_score: 36 security_domain: threat + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index b9c490d31a..a369dcf23b 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -69,3 +69,8 @@ tags: - All_Changes.user risk_score: 30 security_domain: threat + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml index f05c111905..7d6b9bc75b 100644 --- a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml @@ -71,3 +71,18 @@ tags: - All_Changes.user risk_score: 42 security_domain: threat + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_ossec + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml index f7bd2b975f..7b1253cf57 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml @@ -90,3 +90,18 @@ tags: - All_Changes.command risk_score: 18 security_domain: threat + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_cisco-asa + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml index 55f253f01f..7513be4a01 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml @@ -90,3 +90,18 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_cisco-asa + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml index d2bf729211..7253d82d62 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml @@ -89,3 +89,16 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml index b6b89f2f7a..b426a4c520 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml @@ -90,3 +90,18 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_cisco-asa + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index 424bc13108..cf08e122ac 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -69,3 +69,6 @@ tags: - Registry.registry_value_name risk_score: 64 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml index 45b22bb7bd..698637479a 100644 --- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml +++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml @@ -60,3 +60,6 @@ tags: - Registry.dest risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index c82db7194b..d871783719 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -65,3 +65,6 @@ tags: - Registry.user risk_score: 3 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/allow_operation_with_consent_admin.yml b/detections/endpoint/allow_operation_with_consent_admin.yml index 4826d617e7..8b6006e29b 100644 --- a/detections/endpoint/allow_operation_with_consent_admin.yml +++ b/detections/endpoint/allow_operation_with_consent_admin.yml @@ -65,3 +65,6 @@ tags: - Registry.dest risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index a9e51c4f46..f4a55cfc12 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -82,3 +82,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 31c92eb788..195090090c 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -86,3 +86,7 @@ tags: - Processes.parent_process risk_score: 64 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index 2d327cc01e..63d027ddea 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/auto_admin_logon_registry_entry.yml b/detections/endpoint/auto_admin_logon_registry_entry.yml index 0ce8b228ee..a856efd514 100644 --- a/detections/endpoint/auto_admin_logon_registry_entry.yml +++ b/detections/endpoint/auto_admin_logon_registry_entry.yml @@ -60,3 +60,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index 1e1cceeded..6c658858f5 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -83,3 +83,9 @@ tags: - Processes.dest risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml index 2240c701d5..fcad216378 100644 --- a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml +++ b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml @@ -65,3 +65,6 @@ tags: - Processes.user risk_score: 35 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/bcdedit_failure_recovery_modification.yml b/detections/endpoint/bcdedit_failure_recovery_modification.yml index 789fe40bca..f9e5592b67 100644 --- a/detections/endpoint/bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/bcdedit_failure_recovery_modification.yml @@ -75,3 +75,7 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/change_default_file_association.yml b/detections/endpoint/change_default_file_association.yml index a64c0c0597..28852856ab 100644 --- a/detections/endpoint/change_default_file_association.yml +++ b/detections/endpoint/change_default_file_association.yml @@ -66,3 +66,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/change_to_safe_mode_with_network_config.yml b/detections/endpoint/change_to_safe_mode_with_network_config.yml index 0b1d96da8b..98783372ba 100644 --- a/detections/endpoint/change_to_safe_mode_with_network_config.yml +++ b/detections/endpoint/change_to_safe_mode_with_network_config.yml @@ -64,3 +64,6 @@ tags: - Processes.user risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/check_elevated_cmd_using_whoami.yml b/detections/endpoint/check_elevated_cmd_using_whoami.yml index e43834eb01..e7d6338b01 100644 --- a/detections/endpoint/check_elevated_cmd_using_whoami.yml +++ b/detections/endpoint/check_elevated_cmd_using_whoami.yml @@ -65,3 +65,6 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml index ef48bc9c3b..62661201c4 100644 --- a/detections/endpoint/detect_exchange_web_shell.yml +++ b/detections/endpoint/detect_exchange_web_shell.yml @@ -93,3 +93,7 @@ tags: - Filesystem.user risk_score: 81 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml index 08e0895696..a79b3cdc22 100644 --- a/detections/endpoint/detect_rclone_command_line_usage.yml +++ b/detections/endpoint/detect_rclone_command_line_usage.yml @@ -80,3 +80,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml index 5ced5f0e85..1d746a0217 100644 --- a/detections/endpoint/detect_regasm_spawning_a_process.yml +++ b/detections/endpoint/detect_regasm_spawning_a_process.yml @@ -87,3 +87,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_regsvcs_spawning_a_process.yml b/detections/endpoint/detect_regsvcs_spawning_a_process.yml index 489c891e99..579a25f2c2 100644 --- a/detections/endpoint/detect_regsvcs_spawning_a_process.yml +++ b/detections/endpoint/detect_regsvcs_spawning_a_process.yml @@ -86,3 +86,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_sharphound_command_line_arguments.yml b/detections/endpoint/detect_sharphound_command_line_arguments.yml index ae13c1ce47..d2e9777751 100644 --- a/detections/endpoint/detect_sharphound_command_line_arguments.yml +++ b/detections/endpoint/detect_sharphound_command_line_arguments.yml @@ -71,3 +71,6 @@ tags: - Processes.parent_process_id risk_score: 24 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index 134409ee6a..9174e9c7ef 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -67,3 +67,6 @@ tags: - Processes.dest risk_score: 35 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_amsi_through_registry.yml b/detections/endpoint/disable_amsi_through_registry.yml index b3234563e7..47c411b349 100644 --- a/detections/endpoint/disable_amsi_through_registry.yml +++ b/detections/endpoint/disable_amsi_through_registry.yml @@ -48,3 +48,6 @@ tags: - Registry.dest - Registry.registry_value_name security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_etw_through_registry.yml b/detections/endpoint/disable_etw_through_registry.yml index 15fc3b41a4..7122094fe2 100644 --- a/detections/endpoint/disable_etw_through_registry.yml +++ b/detections/endpoint/disable_etw_through_registry.yml @@ -46,3 +46,6 @@ tags: - Registry.dest - Registry.registry_value_name security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_logs_using_wevtutil.yml b/detections/endpoint/disable_logs_using_wevtutil.yml index e4f7d51475..9a157c43c9 100644 --- a/detections/endpoint/disable_logs_using_wevtutil.yml +++ b/detections/endpoint/disable_logs_using_wevtutil.yml @@ -61,3 +61,6 @@ tags: - Processes.process_guid risk_score: 24 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_registry_tool.yml b/detections/endpoint/disable_registry_tool.yml index c4a9d34f67..d46b2d5663 100644 --- a/detections/endpoint/disable_registry_tool.yml +++ b/detections/endpoint/disable_registry_tool.yml @@ -60,3 +60,6 @@ tags: - Registry.registry_value_name risk_score: 40 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_schedule_task.yml b/detections/endpoint/disable_schedule_task.yml index 282f5f47ce..6848545090 100644 --- a/detections/endpoint/disable_schedule_task.yml +++ b/detections/endpoint/disable_schedule_task.yml @@ -60,3 +60,7 @@ tags: - Processes.dest risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/disable_windows_app_hotkeys.yml b/detections/endpoint/disable_windows_app_hotkeys.yml index 9f5f3fcfa4..8c99a673a6 100644 --- a/detections/endpoint/disable_windows_app_hotkeys.yml +++ b/detections/endpoint/disable_windows_app_hotkeys.yml @@ -61,3 +61,6 @@ tags: - Registry.dest Registry.user risk_score: 40 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index 70d9ef034a..710a2e021a 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -68,3 +68,6 @@ tags: - Registry.registry_value_name risk_score: 40 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_cmd_application.yml b/detections/endpoint/disabling_cmd_application.yml index da42de93a5..7ec6ab33a6 100644 --- a/detections/endpoint/disabling_cmd_application.yml +++ b/detections/endpoint/disabling_cmd_application.yml @@ -63,3 +63,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_controlpanel.yml b/detections/endpoint/disabling_controlpanel.yml index af3b83aa32..28cc8b8c37 100644 --- a/detections/endpoint/disabling_controlpanel.yml +++ b/detections/endpoint/disabling_controlpanel.yml @@ -62,3 +62,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_folderoptions_windows_feature.yml b/detections/endpoint/disabling_folderoptions_windows_feature.yml index b7c827178f..120f68a170 100644 --- a/detections/endpoint/disabling_folderoptions_windows_feature.yml +++ b/detections/endpoint/disabling_folderoptions_windows_feature.yml @@ -64,3 +64,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_norun_windows_app.yml b/detections/endpoint/disabling_norun_windows_app.yml index e64e16287e..3e74739458 100644 --- a/detections/endpoint/disabling_norun_windows_app.yml +++ b/detections/endpoint/disabling_norun_windows_app.yml @@ -66,3 +66,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_systemrestore_in_registry.yml b/detections/endpoint/disabling_systemrestore_in_registry.yml index 1447e5c71e..e1078baec0 100644 --- a/detections/endpoint/disabling_systemrestore_in_registry.yml +++ b/detections/endpoint/disabling_systemrestore_in_registry.yml @@ -66,3 +66,6 @@ tags: - Registry.registry_value_name risk_score: 49 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_task_manager.yml b/detections/endpoint/disabling_task_manager.yml index 7e09a87f91..145bb67c16 100644 --- a/detections/endpoint/disabling_task_manager.yml +++ b/detections/endpoint/disabling_task_manager.yml @@ -64,3 +64,6 @@ tags: - Registry.registry_value_name risk_score: 42 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/domain_account_discovery_with_net_app.yml b/detections/endpoint/domain_account_discovery_with_net_app.yml index a7d03f7b80..7ebff9754f 100644 --- a/detections/endpoint/domain_account_discovery_with_net_app.yml +++ b/detections/endpoint/domain_account_discovery_with_net_app.yml @@ -70,3 +70,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index 040d016318..00c446e74b 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -71,3 +71,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/dsquery_domain_discovery.yml b/detections/endpoint/dsquery_domain_discovery.yml index 030da0c875..a4501bd74e 100644 --- a/detections/endpoint/dsquery_domain_discovery.yml +++ b/detections/endpoint/dsquery_domain_discovery.yml @@ -93,3 +93,7 @@ tags: - Processes.parent_process_id risk_score: 72 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/dump_lsass_via_procdump.yml b/detections/endpoint/dump_lsass_via_procdump.yml index c8b3d080d8..b5a487bac6 100644 --- a/detections/endpoint/dump_lsass_via_procdump.yml +++ b/detections/endpoint/dump_lsass_via_procdump.yml @@ -89,3 +89,7 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/enable_rdp_in_other_port_number.yml b/detections/endpoint/enable_rdp_in_other_port_number.yml index e17acbf201..f052b8a46f 100644 --- a/detections/endpoint/enable_rdp_in_other_port_number.yml +++ b/detections/endpoint/enable_rdp_in_other_port_number.yml @@ -60,3 +60,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/eventvwr_uac_bypass.yml b/detections/endpoint/eventvwr_uac_bypass.yml index c9fc2acc9d..7b5152224c 100644 --- a/detections/endpoint/eventvwr_uac_bypass.yml +++ b/detections/endpoint/eventvwr_uac_bypass.yml @@ -68,3 +68,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/excessive_attempt_to_disable_services.yml b/detections/endpoint/excessive_attempt_to_disable_services.yml index f4b3a41258..55c5cbf810 100644 --- a/detections/endpoint/excessive_attempt_to_disable_services.yml +++ b/detections/endpoint/excessive_attempt_to_disable_services.yml @@ -64,3 +64,7 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml b/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml index 2e5c421b97..9035ec59de 100644 --- a/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml +++ b/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml @@ -58,3 +58,12 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cyberark_epm + tas_with_data: + - Splunk_TA_windows diff --git a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml index 13477b9ca3..9b0632b21e 100644 --- a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml +++ b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml @@ -73,3 +73,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/excessive_number_of_taskhost_processes.yml b/detections/endpoint/excessive_number_of_taskhost_processes.yml index d993f89216..ee6836d2d4 100644 --- a/detections/endpoint/excessive_number_of_taskhost_processes.yml +++ b/detections/endpoint/excessive_number_of_taskhost_processes.yml @@ -67,3 +67,11 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR + tas_with_data: + - Splunk_TA_windows diff --git a/detections/endpoint/excessive_usage_of_cacls_app.yml b/detections/endpoint/excessive_usage_of_cacls_app.yml index 2875822434..3ad750937d 100644 --- a/detections/endpoint/excessive_usage_of_cacls_app.yml +++ b/detections/endpoint/excessive_usage_of_cacls_app.yml @@ -64,3 +64,7 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/excessive_usage_of_taskkill.yml b/detections/endpoint/excessive_usage_of_taskkill.yml index 116d72a6d9..ce6646f241 100644 --- a/detections/endpoint/excessive_usage_of_taskkill.yml +++ b/detections/endpoint/excessive_usage_of_taskkill.yml @@ -68,3 +68,7 @@ tags: - Processes.process_id risk_score: 28 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index 097f5f9978..5c21d00cdb 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -76,3 +76,7 @@ tags: - Filesystem.user risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml index 2ca3561bc3..035aa05ecb 100644 --- a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml +++ b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml @@ -74,3 +74,6 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index fdecc0cb1d..cf895798c4 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -74,3 +74,7 @@ tags: - Processes.parent_process risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml index df1c06f03b..530082af39 100644 --- a/detections/endpoint/file_with_samsam_extension.yml +++ b/detections/endpoint/file_with_samsam_extension.yml @@ -69,3 +69,12 @@ tags: - Filesystem.file_name risk_score: 90 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - splunk_ta_o365 + - Splunk_TA_sophos + - Splunk_TA_cyberark + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/firewall_allowed_program_enable.yml b/detections/endpoint/firewall_allowed_program_enable.yml index daef9a0a4b..907cd62dc3 100644 --- a/detections/endpoint/firewall_allowed_program_enable.yml +++ b/detections/endpoint/firewall_allowed_program_enable.yml @@ -67,3 +67,6 @@ tags: role: - Victim automated_detection_testing: passed + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/fodhelper_uac_bypass.yml b/detections/endpoint/fodhelper_uac_bypass.yml index 6586eae065..83fa82db93 100644 --- a/detections/endpoint/fodhelper_uac_bypass.yml +++ b/detections/endpoint/fodhelper_uac_bypass.yml @@ -86,3 +86,6 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/fsutil_zeroing_file.yml b/detections/endpoint/fsutil_zeroing_file.yml index cc936a0de6..286a681650 100644 --- a/detections/endpoint/fsutil_zeroing_file.yml +++ b/detections/endpoint/fsutil_zeroing_file.yml @@ -57,3 +57,6 @@ tags: - Processes.parent_process risk_score: 54 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml index cfc2477bea..e820d5fd23 100644 --- a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml +++ b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml @@ -71,3 +71,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/get_domainpolicy_with_powershell.yml b/detections/endpoint/get_domainpolicy_with_powershell.yml index e14cb2c8ee..82927d2691 100644 --- a/detections/endpoint/get_domainpolicy_with_powershell.yml +++ b/detections/endpoint/get_domainpolicy_with_powershell.yml @@ -71,3 +71,6 @@ tags: - Processes.parent_process_name risk_score: 30 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml index 6ec2b802dc..0c30eebf20 100644 --- a/detections/endpoint/get_domainuser_with_powershell.yml +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -71,3 +71,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml index 26e14b6cd0..4f23fcd739 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -73,3 +73,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/hide_user_account_from_sign_in_screen.yml b/detections/endpoint/hide_user_account_from_sign_in_screen.yml index a25bd2c490..d697eb4b7c 100644 --- a/detections/endpoint/hide_user_account_from_sign_in_screen.yml +++ b/detections/endpoint/hide_user_account_from_sign_in_screen.yml @@ -71,3 +71,6 @@ tags: - Registry.dest Registry.user risk_score: 72 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index ba70ca1892..4858103347 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -74,3 +74,7 @@ tags: - Processes.dest risk_score: 72 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows diff --git a/detections/endpoint/icacls_deny_command.yml b/detections/endpoint/icacls_deny_command.yml index a1ca235169..e93ceb4a9c 100644 --- a/detections/endpoint/icacls_deny_command.yml +++ b/detections/endpoint/icacls_deny_command.yml @@ -65,3 +65,7 @@ tags: - Processes.process risk_score: 72 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/icacls_grant_command.yml b/detections/endpoint/icacls_grant_command.yml index f4634552a4..c7c7162b89 100644 --- a/detections/endpoint/icacls_grant_command.yml +++ b/detections/endpoint/icacls_grant_command.yml @@ -65,3 +65,7 @@ tags: - Processes.process risk_score: 49 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/jscript_execution_using_cscript_app.yml b/detections/endpoint/jscript_execution_using_cscript_app.yml index af8f30ae12..8b5e7a416f 100644 --- a/detections/endpoint/jscript_execution_using_cscript_app.yml +++ b/detections/endpoint/jscript_execution_using_cscript_app.yml @@ -68,3 +68,6 @@ tags: - Processes.user risk_score: 49 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/logon_script_event_trigger_execution.yml b/detections/endpoint/logon_script_event_trigger_execution.yml index 9c14a26fb5..cf278ff252 100644 --- a/detections/endpoint/logon_script_event_trigger_execution.yml +++ b/detections/endpoint/logon_script_event_trigger_execution.yml @@ -64,3 +64,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/modify_acl_permission_to_files_or_folder.yml b/detections/endpoint/modify_acl_permission_to_files_or_folder.yml index 5ab781c9ea..f64bd1247a 100644 --- a/detections/endpoint/modify_acl_permission_to_files_or_folder.yml +++ b/detections/endpoint/modify_acl_permission_to_files_or_folder.yml @@ -62,3 +62,7 @@ tags: - Processes.process_id risk_score: 32 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/msmpeng_application_dll_side_loading.yml b/detections/endpoint/msmpeng_application_dll_side_loading.yml index c172950f46..08485a7c0b 100644 --- a/detections/endpoint/msmpeng_application_dll_side_loading.yml +++ b/detections/endpoint/msmpeng_application_dll_side_loading.yml @@ -47,3 +47,7 @@ tags: - Filesystem.user - Filesystem.file_path security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/net_profiler_uac_bypass.yml b/detections/endpoint/net_profiler_uac_bypass.yml index 1bbe6e2656..2f135b26cc 100644 --- a/detections/endpoint/net_profiler_uac_bypass.yml +++ b/detections/endpoint/net_profiler_uac_bypass.yml @@ -62,3 +62,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/nltest_domain_trust_discovery.yml b/detections/endpoint/nltest_domain_trust_discovery.yml index bc0b860d30..6c8759a4c8 100644 --- a/detections/endpoint/nltest_domain_trust_discovery.yml +++ b/detections/endpoint/nltest_domain_trust_discovery.yml @@ -75,3 +75,6 @@ tags: - Processes.parent_process_id risk_score: 15 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/ntdsutil_export_ntds.yml b/detections/endpoint/ntdsutil_export_ntds.yml index 0b7c18eac7..17b11c6400 100644 --- a/detections/endpoint/ntdsutil_export_ntds.yml +++ b/detections/endpoint/ntdsutil_export_ntds.yml @@ -78,3 +78,6 @@ tags: - Processes.parent_process_id risk_score: 50 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index a61cab427c..e495daff75 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -69,3 +69,13 @@ tags: - Filesystem.dest risk_score: 72 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_ossec + - Splunk_TA_bit9-carbonblack + - splunk_ta_o365 + - Splunk_TA_sophos + - Splunk_TA_cyberark + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/permission_modification_using_takeown_app.yml b/detections/endpoint/permission_modification_using_takeown_app.yml index fd1514f692..603c2571b7 100644 --- a/detections/endpoint/permission_modification_using_takeown_app.yml +++ b/detections/endpoint/permission_modification_using_takeown_app.yml @@ -65,3 +65,6 @@ tags: - Processes.process_guid risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/powershell_execute_com_object.yml b/detections/endpoint/powershell_execute_com_object.yml index 30626cd311..b0f0eb78c4 100644 --- a/detections/endpoint/powershell_execute_com_object.yml +++ b/detections/endpoint/powershell_execute_com_object.yml @@ -58,3 +58,62 @@ tags: - _time risk_score: 5 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_cisco-ucs + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_nginx + - Splunk_TA_microsoft-iis + - Splunk_TA_microsoft-sqlserver + - Splunk_TA_rsa-securid + - Splunk_TA_remedy + - Splunk_TA_bluecoat-proxysg + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_jboss + - Splunk_TA_websense-cg + - Splunk_TA_ossec + - Splunk_TA_bromium + - Splunk_TA_nagios-core + - Splunk_TA_isc-bind + - Splunk_TA_bit9-carbonblack + - Splunk_TA_snow + - Splunk_TA_squid + - Splunk_TA_apache + - Splunk_TA_imperva-waf + - Splunk_TA_juniper + - Splunk_TA_cisco-esa + - Splunk_TA_microsoft_sysmon + - Splunk_TA_cisco-ise + - splunk_ta_o365 + - Splunk_TA_f5-bigip + - Splunk_TA_symantec-ep + - Splunk_TA_google-cloudplatform + - Splunk_TA_sophos + - Splunk_TA_mcafee_epo_syslog + - Splunk_TA_haproxy + - Splunk_TA_tomcat + - Splunk_TA_jmx + - Splunk_TA_cyberark + - Splunk_TA_symantec-dlp + - Splunk_TA_ibm-was + - Splunk_TA_microsoft-hyperv + - Splunk_TA_windows + - Splunk_TA_mcafee-wg + - Splunk_TA_isc-dhcp + - Splunk_TA_websense-dlp + - Splunk_TA_box + - Splunk_TA_microsoft-scom + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_rsa-dlp + - Splunk_TA_cisco-wsa + - Splunk_TA_mysql + - Splunk_TA_cisco-asa + - Splunk_TA_infoblox + - Splunk_TA_salesforce + - Splunk_TA_cyberark_epm + - Splunk_TA_linux + - Splunk_TA_oracle + tas_with_data: + - Splunk_TA_windows diff --git a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml index 03204c0738..a1af36ee5e 100644 --- a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml +++ b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml @@ -66,3 +66,6 @@ tags: - Processes.process_guid risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml index debc480234..3ba02a6da5 100644 --- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml +++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml @@ -80,3 +80,7 @@ tags: - Filesystem.user risk_score: 63 security_domain: network + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/process_execution_via_wmi.yml b/detections/endpoint/process_execution_via_wmi.yml index fa7813c41a..fe64565740 100644 --- a/detections/endpoint/process_execution_via_wmi.yml +++ b/detections/endpoint/process_execution_via_wmi.yml @@ -71,3 +71,7 @@ tags: - Processes.process_name risk_score: 49 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index faf4444a75..f04102be6d 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -76,3 +76,6 @@ tags: - Processes.dest risk_score: 42 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml index ffd507fbab..4c3d4e8d5a 100644 --- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml +++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml @@ -79,3 +79,7 @@ tags: - Processes.dest risk_score: 45 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 19cfceef0d..5cd4452822 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -89,3 +89,6 @@ tags: - Registry.user risk_score: 76 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/remote_wmi_command_attempt.yml b/detections/endpoint/remote_wmi_command_attempt.yml index d0af4cc9ed..d15eacc6b9 100644 --- a/detections/endpoint/remote_wmi_command_attempt.yml +++ b/detections/endpoint/remote_wmi_command_attempt.yml @@ -76,3 +76,6 @@ tags: - Processes.process_id risk_score: 36 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/resize_shadowstorage_volume.yml b/detections/endpoint/resize_shadowstorage_volume.yml index 13d606a8f9..b03dfd2fb3 100644 --- a/detections/endpoint/resize_shadowstorage_volume.yml +++ b/detections/endpoint/resize_shadowstorage_volume.yml @@ -70,3 +70,7 @@ tags: - Processes.user risk_score: 72 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/revil_common_exec_parameter.yml b/detections/endpoint/revil_common_exec_parameter.yml index 1e798edac9..df8f8a92f4 100644 --- a/detections/endpoint/revil_common_exec_parameter.yml +++ b/detections/endpoint/revil_common_exec_parameter.yml @@ -67,3 +67,6 @@ tags: - Processes.process_guid risk_score: 54 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/revil_registry_entry.yml b/detections/endpoint/revil_registry_entry.yml index cebc65361d..9194596c10 100644 --- a/detections/endpoint/revil_registry_entry.yml +++ b/detections/endpoint/revil_registry_entry.yml @@ -65,3 +65,6 @@ tags: - Registry.registry_key_name risk_score: 60 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/ryuk_wake_on_lan_command.yml b/detections/endpoint/ryuk_wake_on_lan_command.yml index 3785dc0563..bc6f63b705 100644 --- a/detections/endpoint/ryuk_wake_on_lan_command.yml +++ b/detections/endpoint/ryuk_wake_on_lan_command.yml @@ -73,3 +73,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/samsam_test_file_write.yml b/detections/endpoint/samsam_test_file_write.yml index d69c4ab3dd..38c0eda594 100644 --- a/detections/endpoint/samsam_test_file_write.yml +++ b/detections/endpoint/samsam_test_file_write.yml @@ -62,3 +62,12 @@ tags: - Filesystem.file_path risk_score: 12 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - splunk_ta_o365 + - Splunk_TA_sophos + - Splunk_TA_cyberark + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index fe0205380e..5e592ab93f 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -78,3 +78,7 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index 96a6b392d3..dd19378fd8 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -71,3 +71,6 @@ tags: - Processes.dest risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/schtasks_run_task_on_demand.yml b/detections/endpoint/schtasks_run_task_on_demand.yml index 0db0a14019..a0afe191f3 100644 --- a/detections/endpoint/schtasks_run_task_on_demand.yml +++ b/detections/endpoint/schtasks_run_task_on_demand.yml @@ -66,3 +66,7 @@ tags: - Processes.user risk_score: 48 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index 06696828bb..b8b13aa3c3 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -73,3 +73,7 @@ tags: - Processes.user risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index c6fd3a72f5..4e9caf787c 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -70,3 +70,7 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml index 277ac32080..e60baa369f 100644 --- a/detections/endpoint/screensaver_event_trigger_execution.yml +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -67,3 +67,6 @@ tags: - Registry.registry_value_name risk_score: 72 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/script_execution_via_wmi.yml b/detections/endpoint/script_execution_via_wmi.yml index 08d251df74..b416c6d5d0 100644 --- a/detections/endpoint/script_execution_via_wmi.yml +++ b/detections/endpoint/script_execution_via_wmi.yml @@ -65,3 +65,10 @@ tags: - Processes.dest risk_score: 36 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cyberark_epm diff --git a/detections/endpoint/sdclt_uac_bypass.yml b/detections/endpoint/sdclt_uac_bypass.yml index db3b46956c..f0a888a33e 100644 --- a/detections/endpoint/sdclt_uac_bypass.yml +++ b/detections/endpoint/sdclt_uac_bypass.yml @@ -62,3 +62,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index e404794b9e..784c131d63 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -68,3 +68,6 @@ tags: - Processes.process_guid risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/services_escalate_exe.yml b/detections/endpoint/services_escalate_exe.yml index 4d3d83aa66..321c001e97 100644 --- a/detections/endpoint/services_escalate_exe.yml +++ b/detections/endpoint/services_escalate_exe.yml @@ -75,3 +75,6 @@ tags: - Processes.parent_process_id risk_score: 76 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index 61f741ddab..5ed48ac68f 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -71,3 +71,6 @@ tags: - Registry.dest risk_score: 48 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index 6ac4dc6618..01a3b5597f 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -68,3 +68,7 @@ tags: - Processes.user risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index 41eaafaaab..6422c9604a 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -63,3 +63,8 @@ tags: - All_Changes.dest risk_score: 63 security_domain: access + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_cyberark diff --git a/detections/endpoint/silentcleanup_uac_bypass.yml b/detections/endpoint/silentcleanup_uac_bypass.yml index bbd46535fb..4f3f15f425 100644 --- a/detections/endpoint/silentcleanup_uac_bypass.yml +++ b/detections/endpoint/silentcleanup_uac_bypass.yml @@ -60,3 +60,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index 48f1c3eba6..ce7437f33e 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -66,3 +66,10 @@ tags: - Processes.process_name risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cyberark_epm diff --git a/detections/endpoint/slui_runas_elevated.yml b/detections/endpoint/slui_runas_elevated.yml index 214b13ac1c..5924a2739c 100644 --- a/detections/endpoint/slui_runas_elevated.yml +++ b/detections/endpoint/slui_runas_elevated.yml @@ -72,3 +72,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/slui_spawning_a_process.yml b/detections/endpoint/slui_spawning_a_process.yml index da332eedf0..359cfdab49 100644 --- a/detections/endpoint/slui_spawning_a_process.yml +++ b/detections/endpoint/slui_spawning_a_process.yml @@ -70,3 +70,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml index e9a8d089b5..eb762b451b 100644 --- a/detections/endpoint/spoolsv_writing_a_dll.yml +++ b/detections/endpoint/spoolsv_writing_a_dll.yml @@ -81,3 +81,9 @@ tags: - Processes.dest risk_score: 72 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/start_up_during_safe_mode_boot.yml b/detections/endpoint/start_up_during_safe_mode_boot.yml index b4f49a32f1..3b9a982235 100644 --- a/detections/endpoint/start_up_during_safe_mode_boot.yml +++ b/detections/endpoint/start_up_during_safe_mode_boot.yml @@ -59,3 +59,6 @@ tags: - Registry.dest risk_score: 42 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index 76e082bafe..a3e71a37f0 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -79,3 +79,6 @@ tags: - Processes.user risk_score: 40 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index 58aa39e8dd..f6067ee1a8 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -72,3 +72,6 @@ tags: - Processes.user risk_score: 35 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index d107f795d0..70fc81d7dd 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -78,3 +78,7 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index f27fec7309..567be79aab 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -73,3 +73,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index 1cf511bf39..9446d60e10 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -77,3 +77,7 @@ tags: - Processes.user risk_score: 28 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/system_information_discovery_detection.yml b/detections/endpoint/system_information_discovery_detection.yml index b7d0bd81a8..9713ae4a3a 100644 --- a/detections/endpoint/system_information_discovery_detection.yml +++ b/detections/endpoint/system_information_discovery_detection.yml @@ -66,3 +66,10 @@ tags: - Processes.dest risk_score: 15 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cyberark_epm diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index 559d66164c..e02f6ccab4 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -82,3 +82,7 @@ tags: - Processes.process_hash risk_score: 49 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml index e27d0729a9..00a42c0dc4 100644 --- a/detections/endpoint/time_provider_persistence_registry.yml +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -67,3 +67,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/unified_messaging_service_spawning_a_process.yml b/detections/endpoint/unified_messaging_service_spawning_a_process.yml index f6537474ca..fb7c90a9dd 100644 --- a/detections/endpoint/unified_messaging_service_spawning_a_process.yml +++ b/detections/endpoint/unified_messaging_service_spawning_a_process.yml @@ -71,3 +71,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/uninstall_app_using_msiexec.yml b/detections/endpoint/uninstall_app_using_msiexec.yml index fc2c1b0fec..a59f0d1633 100644 --- a/detections/endpoint/uninstall_app_using_msiexec.yml +++ b/detections/endpoint/uninstall_app_using_msiexec.yml @@ -65,3 +65,6 @@ tags: - Processes.parent_process_id risk_score: 30 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index a22640a966..a465998c71 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -65,3 +65,7 @@ tags: - Processes.user risk_score: 45 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/usn_journal_deletion.yml b/detections/endpoint/usn_journal_deletion.yml index a7a18b8cb4..d125cb69e3 100644 --- a/detections/endpoint/usn_journal_deletion.yml +++ b/detections/endpoint/usn_journal_deletion.yml @@ -70,3 +70,6 @@ tags: - Processes.dest risk_score: 45 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/wbadmin_delete_system_backups.yml b/detections/endpoint/wbadmin_delete_system_backups.yml index 3b5d951b2f..2f5add7e12 100644 --- a/detections/endpoint/wbadmin_delete_system_backups.yml +++ b/detections/endpoint/wbadmin_delete_system_backups.yml @@ -64,3 +64,7 @@ tags: - Processes.user risk_score: 15 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/windows_adfind_exe.yml b/detections/endpoint/windows_adfind_exe.yml index 4563793a1a..90fa0367a7 100644 --- a/detections/endpoint/windows_adfind_exe.yml +++ b/detections/endpoint/windows_adfind_exe.yml @@ -58,3 +58,6 @@ tags: - Processes.process_id - Processes.parent_process_id security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/windows_disableantispyware_reg.yml b/detections/endpoint/windows_disableantispyware_reg.yml index bb539c4ea0..f0fdddb081 100644 --- a/detections/endpoint/windows_disableantispyware_reg.yml +++ b/detections/endpoint/windows_disableantispyware_reg.yml @@ -68,3 +68,6 @@ tags: - Registry.registry_path risk_score: 24 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/wsreset_uac_bypass.yml b/detections/endpoint/wsreset_uac_bypass.yml index 6b4a5762ea..aee3a9f687 100644 --- a/detections/endpoint/wsreset_uac_bypass.yml +++ b/detections/endpoint/wsreset_uac_bypass.yml @@ -61,3 +61,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/xsl_script_execution_with_wmic.yml b/detections/endpoint/xsl_script_execution_with_wmic.yml index a2d658b7ef..e0a0028be5 100644 --- a/detections/endpoint/xsl_script_execution_with_wmic.yml +++ b/detections/endpoint/xsl_script_execution_with_wmic.yml @@ -12,8 +12,8 @@ description: This search is to detect a suspicious wmic.exe process or renamed w This TTP is really a good indicator for you to hunt further for FIN7 or other attacker that known to used this technique. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_wmic` Processes.process = "*os get*" - Processes.process="*/format:*" Processes.process = "*.xsl*" by Processes.parent_process_name + as lastTime from datamodel=Endpoint.Processes where `process_wmic` Processes.process + = "*os get*" Processes.process="*/format:*" Processes.process = "*.xsl*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process_id Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `xsl_script_execution_with_wmic_filter`' @@ -41,7 +41,8 @@ tags: impact: 70 kill_chain_phases: - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing wmic to load a XSL script. + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$ utilizing wmic to load a XSL script. mitre_attack_id: - T1220 observable: @@ -76,3 +77,6 @@ tags: - Processes.user risk_score: 49 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/experimental/cloud/abnormally_high_cloud_instances_destroyed.yml b/detections/experimental/cloud/abnormally_high_cloud_instances_destroyed.yml index 5f5357037d..79d8ffec04 100644 --- a/detections/experimental/cloud/abnormally_high_cloud_instances_destroyed.yml +++ b/detections/experimental/cloud/abnormally_high_cloud_instances_destroyed.yml @@ -59,3 +59,20 @@ tags: risk_object_type: user risk_score: 10 security_domain: Cloud + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_ossec + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cisco-asa + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/experimental/cloud/abnormally_high_cloud_instances_launched.yml b/detections/experimental/cloud/abnormally_high_cloud_instances_launched.yml index fdaff07d65..641cd30cf3 100644 --- a/detections/experimental/cloud/abnormally_high_cloud_instances_launched.yml +++ b/detections/experimental/cloud/abnormally_high_cloud_instances_launched.yml @@ -60,3 +60,20 @@ tags: risk_object_type: user risk_score: 40 security_domain: Cloud + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_ossec + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cisco-asa + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose diff --git a/detections/experimental/endpoint/print_processor_registry_autostart.yml b/detections/experimental/endpoint/print_processor_registry_autostart.yml index bb3b2100fd..0bf18cd094 100644 --- a/detections/experimental/endpoint/print_processor_registry_autostart.yml +++ b/detections/experimental/endpoint/print_processor_registry_autostart.yml @@ -67,3 +67,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/network/dns_query_length_with_high_standard_deviation.yml b/detections/network/dns_query_length_with_high_standard_deviation.yml index 85230e4b87..8c559cabaa 100644 --- a/detections/network/dns_query_length_with_high_standard_deviation.yml +++ b/detections/network/dns_query_length_with_high_standard_deviation.yml @@ -66,3 +66,8 @@ tags: - DNS.query risk_score: 56 security_domain: network + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_isc-bind + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_infoblox From bb06f84f614be59e1b49d8cb58e43c3cb103bc92 Mon Sep 17 00:00:00 2001 From: Detection Testing Service Date: Tue, 14 Dec 2021 14:21:31 +0530 Subject: [PATCH 02/25] test:added enriched detections and script for the same --- .../detection_ta_mapping.yaml | 802 ++++++++++++++++++ .../enrich_detections.py | 270 ++++++ security_content_automation/requirements.txt | 2 + 3 files changed, 1074 insertions(+) create mode 100644 security_content_automation/detection_ta_mapping.yaml create mode 100644 security_content_automation/enrich_detections.py create mode 100644 security_content_automation/requirements.txt diff --git a/security_content_automation/detection_ta_mapping.yaml b/security_content_automation/detection_ta_mapping.yaml new file mode 100644 index 0000000000..9491fb6ae4 --- /dev/null +++ b/security_content_automation/detection_ta_mapping.yaml @@ -0,0 +1,802 @@ +Abnormally High Number Of Cloud Infrastructure API Calls Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_ossec + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_cisco-asa + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Abnormally High Number Of Cloud Instances Destroyed Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_ossec + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cisco-asa + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Abnormally High Number Of Cloud Security Group API Calls Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_ossec + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Abnormally High Number of Cloud Instances Launched Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_ossec + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cisco-asa + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Active Setup Registry Autostart Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Add DefaultUser And Password In Registry Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Allow Inbound Traffic By Firewall Rule Registry Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Allow Operation with Consent Admin Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Anomalous usage of 7zip Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Attacker Tools On Endpoint Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows +Attempt To Add Certificate To Untrusted Store Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Auto Admin Logon Registry Entry Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +BCDEdit Failure Recovery Modification: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Batch File Write to System32 Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR +Bcdedit Command Back To Normal Mode Boot Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Change Default File Association Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Change To Safe Mode With Network Config Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Check Elevated CMD using whoami Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Cloud API Calls From Previously Unseen User Roles Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - splunk_ta_o365 + - Splunk_TA_box + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Cloud Compute Instance Created By Previously Unseen User Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Cloud Compute Instance Created In Previously Unused Region Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Cloud Compute Instance Created With Previously Unseen Image Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Cloud Compute Instance Created With Previously Unseen Instance Type Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Cloud Instance Modified By Previously Unseen User Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_ossec + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Cloud Provisioning Activity From Previously Unseen City Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_cisco-asa + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Cloud Provisioning Activity From Previously Unseen Country Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_cisco-asa + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Cloud Provisioning Activity From Previously Unseen IP Address Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +Cloud Provisioning Activity From Previously Unseen Region Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_juniper + - splunk_ta_o365 + - Splunk_TA_cyberark + - Splunk_TA_box + - Splunk_TA_cisco-asa + - Splunk_TA_infoblox + - Splunk_TA_salesforce + tas_with_data: + - Splunk_TA_aws-kinesis-firehose +DNS Query Length With High Standard Deviation Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_isc-bind + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_infoblox +DSQuery Domain Discovery Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Detect Exchange Web Shell Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Detect RClone Command-Line Usage Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Detect Regasm Spawning a Process Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Detect Regsvcs Regasm Spawning a Process Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Detect SharpHound Command-Line Arguments Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Detect Use of cmd exe to Launch Script Interpreters Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disable AMSI Through Registry Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disable ETW Through Registry Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disable Logs Using WevtUtil Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disable Registry Tool Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disable Schedule Task Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Disable Windows App Hotkeys Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disable Windows Behavior Monitoring Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disabling CMD Application Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disabling ControlPanel Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disabling FolderOptions Windows Feature Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disabling NoRun Windows App Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disabling SystemRestore In Registry Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Disabling Task Manager Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Domain Account Discovery With Net App Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Domain Account Discovery with Wmic Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Dump LSASS via procdump Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Enable RDP In Other Port Number Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Eventvwr UAC Bypass Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Excessive Attempt To Disable Services Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Excessive Usage Of Cacls App Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Excessive Usage Of Taskkill Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Excessive number of distinct processes created in Windows Temp folder Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cyberark_epm + tas_with_data: + - Splunk_TA_windows +Excessive number of service control start as disabled Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Excessive number of taskhost processes Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR + tas_with_data: + - Splunk_TA_windows +Executables Or Script Creation In Suspicious Path Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Execute Javascript With Jscript COM CLSID Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Execution of File with Multiple Extensions Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows +File with Samsam Extension Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - splunk_ta_o365 + - Splunk_TA_sophos + - Splunk_TA_cyberark + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR +Firewall Allowed Program Enable Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +FodHelper UAC Bypass Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Fsutil Zeroing File Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Get ADUserResultantPasswordPolicy with Powershell Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Get DomainPolicy with Powershell Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Get DomainUser with PowerShell Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +GetWmiObject DS User with PowerShell Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Hide User Account From Sign-In Screen Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Hiding Files And Directories With Attrib exe Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows +ICACLS Grant Command Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Icacls Deny Command Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Jscript Execution Using Cscript App Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Logon Script Event Trigger Execution Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Modify ACL permission To Files Or Folder Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Msmpeng Application DLL Side Loading Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +NET Profiler UAC bypass Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +NLTest Domain Trust Discovery: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +NTdsutil export ntds dit Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Overwriting Accessibility Binaries Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_ossec + - Splunk_TA_bit9-carbonblack + - splunk_ta_o365 + - Splunk_TA_sophos + - Splunk_TA_cyberark + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR +Permission Modification using Takeown App Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Powershell Execute COM Object Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_cisco-ucs + - Splunk_TA_citrix-netscaler + - Splunk_TA_nix + - Splunk_TA_nginx + - Splunk_TA_microsoft-iis + - Splunk_TA_microsoft-sqlserver + - Splunk_TA_rsa-securid + - Splunk_TA_remedy + - Splunk_TA_bluecoat-proxysg + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_rsa_securid_cas + - Splunk_TA_jboss + - Splunk_TA_websense-cg + - Splunk_TA_ossec + - Splunk_TA_bromium + - Splunk_TA_nagios-core + - Splunk_TA_isc-bind + - Splunk_TA_bit9-carbonblack + - Splunk_TA_snow + - Splunk_TA_squid + - Splunk_TA_apache + - Splunk_TA_imperva-waf + - Splunk_TA_juniper + - Splunk_TA_cisco-esa + - Splunk_TA_microsoft_sysmon + - Splunk_TA_cisco-ise + - splunk_ta_o365 + - Splunk_TA_f5-bigip + - Splunk_TA_symantec-ep + - Splunk_TA_google-cloudplatform + - Splunk_TA_sophos + - Splunk_TA_mcafee_epo_syslog + - Splunk_TA_haproxy + - Splunk_TA_tomcat + - Splunk_TA_jmx + - Splunk_TA_cyberark + - Splunk_TA_symantec-dlp + - Splunk_TA_ibm-was + - Splunk_TA_microsoft-hyperv + - Splunk_TA_windows + - Splunk_TA_mcafee-wg + - Splunk_TA_isc-dhcp + - Splunk_TA_websense-dlp + - Splunk_TA_box + - Splunk_TA_microsoft-scom + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_rsa-dlp + - Splunk_TA_cisco-wsa + - Splunk_TA_mysql + - Splunk_TA_cisco-asa + - Splunk_TA_infoblox + - Splunk_TA_salesforce + - Splunk_TA_cyberark_epm + - Splunk_TA_linux + - Splunk_TA_oracle + tas_with_data: + - Splunk_TA_windows +Prevent Automatic Repair Mode using Bcdedit Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Print Processor Registry Autostart Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Process Creating LNK file in Suspicious location Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Process execution via wmi Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Processes created by netsh Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Reg exe Manipulating Windows Services Registry Keys Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Registry Keys Used For Persistence Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Remote WMI Command Attempt Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Resize ShadowStorage volume Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Revil Common Exec Parameter Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Revil Registry Entry Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Ryuk Wake on LAN Command Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +SLUI RunAs Elevated Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +SLUI Spawning a Process Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Samsam Test File Write Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - splunk_ta_o365 + - Splunk_TA_sophos + - Splunk_TA_cyberark + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR +Sc exe Manipulating Windows Services Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Scheduled Task Deleted Or Created Via CMD: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Schtasks Run Task On Demand Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Schtasks scheduling job on remote system Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Schtasks used for forcing a reboot Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Screensaver Event Trigger Execution Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Script Execution via WMI Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cyberark_epm +Sdclt UAC Bypass Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +SecretDumps Offline NTDS Dumping Tool Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Services Escalate Exe Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Set Default PowerShell Execution Policy To Unrestricted or Bypass Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Shim Database Installation With Suspicious Parameters Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Short Lived Windows Accounts Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_rsa-securid + - Splunk_TA_aws-kinesis-firehose + - Splunk_TA_cyberark +SilentCleanup UAC Bypass Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Single Letter Process On Endpoint Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cyberark_epm +Spoolsv Writing a DLL Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR +Start Up During Safe Mode Boot Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Suspicious File Write Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Suspicious Process File Path Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Suspicious Reg exe Process Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Suspicious Scheduled Task from Public Directory Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Suspicious mshta child process Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +System Information Discovery Detection Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_nix + - Splunk_TA_bit9-carbonblack + - Splunk_TA_windows + - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_cyberark_epm +System Processes Run From Unexpected Locations Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +Time Provider Persistence Registry Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +USN Journal Deletion Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Unified Messaging Service Spawning a Process Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Uninstall App Using MsiExec Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Unload Sysmon Filter Driver Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +WBAdmin Delete System Backups Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +WSReset UAC Bypass Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Windows AdFind Exe Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +Windows Disable Antispyware Reg Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +XSL Script Execution With WMIC Unit Test: + CIM_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py new file mode 100644 index 0000000000..9bd3569e75 --- /dev/null +++ b/security_content_automation/enrich_detections.py @@ -0,0 +1,270 @@ +# 1. Take github token, branch_name from user to raise a PR for enriched detection of security_content repo +# 2. Iterate through each detection file +# 3. For each detection iterate through ta_cim_mapping report +# 4. map detection file and ta_cim_mapping reports and finalise the TA required for particular detection +# 5. Add the list of TA's in detection file +# 6. Create a new branch and raise an MR for it + +import os +import git +import sys +import shutil +import yaml +import json +import time +import argparse +import logging +import io +import re +from github import Github + + +def fetch_ta_cim_mapping_report(file_name): + try: + with open(file_name) as file_content: + cim_field_report = json.load(file_content) + return cim_field_report + except Exception as error: + error_message = f"Unexpected error occurred while reading file. Error: {error}" + logging.error(error_message) + + +def load_file(file_path): + with open(file_path, "r", encoding="utf-8") as stream: + try: + file = list(yaml.safe_load_all(stream))[0] + except yaml.YAMLError as exc: + sys.exit("ERROR: reading {0}".format(file_path)) + return file + + +def map_required_fields(cim_summary, datamodel, required_fields): + datasets_fields = {} + add_addon = True + flag = 0 + for item in required_fields: + if re.match("^[A-Za-z0-9_.]*$", item): + if item == "_time" or item == "_times": + continue + else: + dataset_field = item.split(".") + length = len(dataset_field) + if length == 1: + dataset = datamodel[0] + field = dataset_field[0] + else: + dataset = dataset_field[length - 2] + field = dataset_field[length - 1] + if dataset not in datasets_fields: + datasets_fields[dataset] = [] + datasets_fields[dataset].append(field) + + for dataset in datasets_fields: + add_addon = False + mapping_set = datamodel[0] + ":" + dataset + for item in cim_summary: + if mapping_set in item: + for eventtype in cim_summary[item].values(): + for e_type in eventtype: + cim_fields = e_type.get("fields", []) + if set(datasets_fields[dataset]).issubset(set(cim_fields)): + add_addon = True + + return add_addon + + +def is_valid_detection_file(filepath) -> bool: + """ + check if detection file have valid analytic type and have valid + data-model name. + :param detection_test_path: detection test path i.e. security_content/tests/cloud + :param test_file: detection test file name + :param detection_products: detection tag product list for which detection test will filterised + :return: boolean + """ + detection_analytic_type = ["ttp", "anomaly"] + detection_with_valid_analytic_type = False + detection_with_valid_datamodel = False + detection_file_path = load_file(filepath) + + if detection_file_path.get("type", "").lower() in detection_analytic_type: + detection_with_valid_analytic_type = True + + if detection_file_path.get("datamodel", []): + detection_with_valid_datamodel = True + + return detection_with_valid_analytic_type & detection_with_valid_datamodel + + +def enrich_detection_file(file, ta_list, keyname): + # file_path = 'security_content/detections/' + test['detection_result']['detection_file'] + detection_obj = load_file(file) + detection_obj["tags"][keyname] = ta_list + + with open(file, "w") as f: + yaml.dump(detection_obj, f, sort_keys=False, allow_unicode=True) + + +def main(): + + parser = argparse.ArgumentParser( + description="Enrich detections with relevant TA names" + ) + parser.add_argument( + "-scr", + "--security_content_repo", + required=False, + default="kirtankhatana-crest/security_content", + help="specify the url of the security content repository", + ) + parser.add_argument( + "-scb", + "--security_content_branch", + required=False, + default="develop", + help="specify the security content branch", + ) + parser.add_argument( + "-gt", + "--github_token", + required=False, + default=os.environ.get("GIT_TOKEN"), + help="specify the github token for the PR", + ) + + args = parser.parse_args() + security_content_repo = args.security_content_repo + security_content_branch = args.security_content_branch + github_token = args.github_token + g = Github(github_token) + detection_types = ["cloud", "endpoint", "network"] + + # clone security content repository + security_content_repo_obj = git.Repo.clone_from( + "https://" + + github_token + + ":x-oauth-basic@github.com/" + + security_content_repo, + "security_content", + branch=security_content_branch, + ) + + # clone ta cim field reports repository + ta_cim_field_reports_obj = git.Repo.clone_from( + "https://" + + github_token + + ":x-oauth-basic@github.com/" + + "splunk/ta-cim-field-reports", + "ta_cim_mapping_reports", + branch="feat/cim-field-mapping", + ) + + # iterate for every detection types + detection_ta_mapping = {} + for detection_type in detection_types: + + for subdir, _, files in os.walk(f"security_content/tests/{detection_type}"): + print(subdir) + for file in files: + filepath = subdir + os.sep + file + supported_ta_list = [] + tas_with_data_list = [] + detection_obj = load_file(filepath) + detection_name = detection_obj["name"] + source_type = ( + detection_obj.get("tests")[0] + .get("attack_data")[0] + .get("sourcetype") + ) + filepath = "security_content/detections/" + detection_obj.get("tests")[ + 0 + ].get("file") + if is_valid_detection_file(filepath): + for ta_cim_mapping_file in os.listdir( + "./ta_cim_mapping_reports/ta_cim_mapping/cim_mapping_reports/latest/" + ): + + ta_cim_map = fetch_ta_cim_mapping_report( + "./ta_cim_mapping_reports/ta_cim_mapping/cim_mapping_reports/latest/" + + ta_cim_mapping_file + ) + + detection_obj = load_file(filepath) + required_fields = detection_obj.get("tags", {}).get( + "required_fields" + ) + datamodel = detection_obj.get("datamodel", []) + result = map_required_fields( + ta_cim_map["cimsummary"], datamodel, required_fields + ) + cim_version = ta_cim_map["cim_version"] + + if result: + supported_ta_list.append( + ta_cim_map.get("ta_name").get("name") + ) + ta_sourcetype = ta_cim_map["sourcetypes"] + if source_type in ta_sourcetype: + tas_with_data_list.append( + ta_cim_map.get("ta_name").get("name") + ) + detection_ta_mapping[detection_name] = {} + + if supported_ta_list: + keyname = "supported_tas" + print(filepath) + enrich_detection_file(filepath, cim_version, "CIM_version") + enrich_detection_file(filepath, supported_ta_list, keyname) + detection_ta_mapping[detection_name][ + "CIM_version" + ] = cim_version + detection_ta_mapping[detection_name][ + keyname + ] = supported_ta_list + + if tas_with_data_list: + keyname = "tas_with_data" + enrich_detection_file(filepath, tas_with_data_list, keyname) + detection_ta_mapping[detection_name][ + keyname + ] = tas_with_data_list + + security_content_repo_obj.index.add( + [filepath.strip("security_content/")] + ) + + print("done") + with io.open( + r"./security_content_automation/detection_ta_mapping.yaml", "w", encoding="utf8" + ) as outfile: + yaml.safe_dump( + detection_ta_mapping, outfile, default_flow_style=False, allow_unicode=True + ) + + security_content_repo_obj.index.commit( + "Updated detection files with supported TA list." + ) + + epoch_time = str(int(time.time())) + branch_name = "security_content_automation_" + epoch_time + security_content_repo_obj.git.checkout("-b", branch_name) + + security_content_repo_obj.git.push("--set-upstream", "origin", branch_name) + repo = g.get_repo("kirtankhatana-crest/security_content") + + pr = repo.create_pull( + title="Enrich Detection PR " + branch_name, + body="This is a dummy PR", + head=branch_name, + base="develop", + ) + + try: + shutil.rmtree("./security_content") + shutil.rmtree("./ta_cim_mapping_reports") + except OSError as e: + print("Error: %s - %s." % (e.filename, e.strerror)) + + +if __name__ == "__main__": + main() diff --git a/security_content_automation/requirements.txt b/security_content_automation/requirements.txt new file mode 100644 index 0000000000..8552a5cfcb --- /dev/null +++ b/security_content_automation/requirements.txt @@ -0,0 +1,2 @@ +GitPython==3.1.24 +PyYAML==6.0 \ No newline at end of file From a2b6fff739feffc6b700058c9938ccff6cb3a388 Mon Sep 17 00:00:00 2001 From: Detection Testing Service Date: Wed, 15 Dec 2021 21:15:02 +0530 Subject: [PATCH 03/25] test:updated ymls --- ...mber_of_cloud_infrastructure_api_calls.yml | 2 +- ...mber_of_cloud_security_group_api_calls.yml | 2 +- ...alls_from_previously_unseen_user_roles.yml | 2 +- ...ance_created_by_previously_unseen_user.yml | 2 +- ...ce_created_in_previously_unused_region.yml | 2 +- ...e_created_with_previously_unseen_image.yml | 2 +- ...d_with_previously_unseen_instance_type.yml | 2 +- ...e_modified_with_previously_unseen_user.yml | 2 +- ...ovisioning_from_previously_unseen_city.yml | 2 +- ...sioning_from_previously_unseen_country.yml | 2 +- ...ning_from_previously_unseen_ip_address.yml | 2 +- ...isioning_from_previously_unseen_region.yml | 2 +- .../detect_aws_console_login_by_new_user.yml | 10 +- ...ws_console_login_by_user_from_new_city.yml | 4 +- ...console_login_by_user_from_new_country.yml | 6 +- ..._console_login_by_user_from_new_region.yml | 10 +- ...tolen_credentials_via_mimikatz_modules.yml | 105 +++ ...en_credentials_via_powersploit_modules.yml | 31 +- ...ntial_strength_via_dsinternals_modules.yml | 25 +- ...raction_dsinternals_conversion_modules.yml | 40 +- ...dential_extraction_dsinternals_modules.yml | 35 +- ...l_extraction_fgdump_cachedump_s_option.yml | 40 +- ...l_extraction_fgdump_cachedump_v_option.yml | 34 +- ...al_extraction_getaddbaccount_from_dump.yml | 3 +- ...ial_extraction_lazagne_command_options.yml | 3 +- ...credential_extraction_mimikatz_modules.yml | 3 +- ...al_extraction_ms_debuggers_kernel_peek.yml | 3 +- ...ntial_extraction_ms_debuggers_z_option.yml | 3 +- ...dential_extraction_powersploit_modules.yml | 3 +- .../deprecated/ssa___detect_pass_hash.yml | 3 +- ...s_user_content_via_powersploit_modules.yml | 3 +- ...count_creation_via_powersploit_modules.yml | 3 +- ...enable_disable_via_dsinternals_modules.yml | 3 +- ...egal_log_deletion_via_mimikatz_modules.yml | 3 +- ...s_and_policies_via_dsinternals_modules.yml | 3 +- ...nd_AD_elements_via_powersploit_modules.yml | 3 +- ...nd_persistence_via_powersploit_modules.yml | 3 +- ...ivilege_elevation_via_mimikatz_modules.yml | 3 +- ...d_process_control_via_mimikatz_modules.yml | 3 +- ...rocess_control_via_powersploit_modules.yml | 3 +- ...en_credentials_via_powersploit_modules.yml | 3 +- ..._opportunities_via_powersploit_modules.yml | 3 +- ...roups_policies_via_powersploit_modules.yml | 3 +- ...e_accounts_groups_via_mimikatz_modules.yml | 3 +- ...infrastructure_via_powersploit_modules.yml | 3 +- ...puters_domains_via_powersploit_modules.yml | 3 +- ...and_use_computers_via_mimikatz_modules.yml | 3 +- ...ystem_elements_via_powersploit_modules.yml | 3 +- ...on_and_use_shares_via_mimikatz_modules.yml | 3 +- ...and_use_shares_via_powersploit_modules.yml | 3 +- ...n_connectivity_via_powersploit_modules.yml | 3 +- ...ores_and_services_via_mimikatz_modules.yml | 3 +- ...efensive_tools_via_powersploit_modules.yml | 3 +- ..._opportunities_via_powersploit_modules.yml | 3 +- ...service_hijacking_via_mimikatz_modules.yml | 3 +- ...sses_and_services_via_mimikatz_modules.yml | 3 +- ...ng_credentials_via_dsinternals_modules.yml | 3 +- ...tting_credentials_via_mimikatz_modules.yml | 3 +- ...ng_credentials_via_powersploit_modules.yml | 3 +- .../active_setup_registry_autostart.yml | 2 +- ...d_defaultuser_and_password_in_registry.yml | 6 +- .../add_or_set_windows_defender_exclusion.yml | 75 ++ ...ound_traffic_by_firewall_rule_registry.yml | 2 +- .../allow_operation_with_consent_admin.yml | 6 +- .../endpoint/anomalous_usage_of_7zip.yml | 2 +- .../endpoint/any_powershell_downloadfile.yml | 3 + .../endpoint/attacker_tools_on_endpoint.yml | 2 +- ..._to_add_certificate_to_untrusted_store.yml | 2 +- .../auto_admin_logon_registry_entry.yml | 2 +- .../endpoint/batch_file_write_to_system32.yml | 2 +- ...dedit_command_back_to_normal_mode_boot.yml | 2 +- .../bcdedit_failure_recovery_modification.yml | 2 +- .../change_default_file_association.yml | 2 +- ...hange_to_safe_mode_with_network_config.yml | 2 +- .../check_elevated_cmd_using_whoami.yml | 2 +- ...cmd_carry_out_string_command_parameter.yml | 35 +- .../csc_net_on_the_fly_compilation.yml | 26 +- .../curl_download_and_bash_execution.yml | 82 ++ ...ivity_related_to_pass_the_hash_attacks.yml | 2 +- .../endpoint/detect_exchange_web_shell.yml | 2 +- .../endpoint/detect_html_help_renamed.yml | 5 +- .../detect_psexec_with_accepteula_flag.yml | 2 +- .../detect_rclone_command_line_usage.yml | 27 +- .../detect_regasm_spawning_a_process.yml | 2 +- .../detect_regsvcs_spawning_a_process.yml | 2 +- detections/endpoint/detect_renamed_psexec.yml | 2 +- ...tect_sharphound_command_line_arguments.yml | 2 +- ..._cmd_exe_to_launch_script_interpreters.yml | 2 +- .../disable_amsi_through_registry.yml | 9 +- .../endpoint/disable_etw_through_registry.yml | 6 +- .../endpoint/disable_logs_using_wevtutil.yml | 2 +- detections/endpoint/disable_registry_tool.yml | 6 +- detections/endpoint/disable_schedule_task.yml | 2 +- .../endpoint/disable_show_hidden_files.yml | 7 +- .../endpoint/disable_windows_app_hotkeys.yml | 2 +- .../disable_windows_behavior_monitoring.yml | 10 +- .../endpoint/disabling_cmd_application.yml | 6 +- .../endpoint/disabling_controlpanel.yml | 6 +- ...isabling_folderoptions_windows_feature.yml | 6 +- .../endpoint/disabling_norun_windows_app.yml | 6 +- .../disabling_remote_user_account_control.yml | 4 +- .../disabling_systemrestore_in_registry.yml | 6 +- .../endpoint/disabling_task_manager.yml | 6 +- .../domain_account_discovery_with_net_app.yml | 2 +- .../domain_account_discovery_with_wmic.yml | 2 +- .../endpoint/dsquery_domain_discovery.yml | 2 +- .../endpoint/dump_lsass_via_procdump.yml | 2 +- .../enable_rdp_in_other_port_number.yml | 4 +- detections/endpoint/eventvwr_uac_bypass.yml | 2 +- .../excessive_attempt_to_disable_services.yml | 2 +- ...ocesses_created_in_windows_temp_folder.yml | 2 +- ...r_of_service_control_start_as_disabled.yml | 2 +- ...excessive_number_of_taskhost_processes.yml | 2 +- .../endpoint/excessive_usage_of_cacls_app.yml | 2 +- .../endpoint/excessive_usage_of_taskkill.yml | 2 +- ...le_written_in_administrative_smb_share.yml | 4 +- ..._or_script_creation_in_suspicious_path.yml | 2 +- ...cute_javascript_with_jscript_com_clsid.yml | 2 +- ...ution_of_file_with_multiple_extensions.yml | 2 +- .../endpoint/file_with_samsam_extension.yml | 2 +- .../firewall_allowed_program_enable.yml | 30 +- detections/endpoint/fodhelper_uac_bypass.yml | 2 +- detections/endpoint/fsutil_zeroing_file.yml | 2 +- ...esultantpasswordpolicy_with_powershell.yml | 2 +- .../get_domainpolicy_with_powershell.yml | 2 +- .../get_domainuser_with_powershell.yml | 2 +- .../getwmiobject_ds_user_with_powershell.yml | 2 +- .../hide_user_account_from_sign_in_screen.yml | 9 +- ..._files_and_directories_with_attrib_exe.yml | 2 +- ...equency_copy_of_files_in_network_share.yml | 28 +- detections/endpoint/hunting_for_log4shell.yml | 118 +++ detections/endpoint/icacls_deny_command.yml | 2 +- detections/endpoint/icacls_grant_command.yml | 2 +- ...ateral_movement_commandline_parameters.yml | 81 ++ ...ion_on_remote_endpoint_with_powershell.yml | 42 +- ...cessful_remote_desktop_authentications.yml | 2 +- ...class_file_download_by_java_user_agent.yml | 79 ++ .../jscript_execution_using_cscript_app.yml | 3 +- .../endpoint/loading_of_dynwrapx_module.yml | 26 +- .../logon_script_event_trigger_execution.yml | 2 +- ...connect_to_internet_with_hidden_window.yml | 4 + ...mmc_exe_lolbas_execution_process_spawn.yml | 81 ++ ...dify_acl_permission_to_files_or_folder.yml | 2 +- .../msmpeng_application_dll_side_loading.yml | 2 +- .../endpoint/net_localgroup_discovery.yml | 1 + .../endpoint/net_profiler_uac_bypass.yml | 2 +- ...work_discovery_using_route_windows_app.yml | 28 +- .../nltest_domain_trust_discovery.yml | 2 +- ...e_process_accessing_chrome_default_dir.yml | 1 + ...fox_process_access_firefox_profile_dir.yml | 1 + detections/endpoint/ntdsutil_export_ntds.yml | 2 +- ...ice_application_spawn_rundll32_process.yml | 12 +- ...nnection_from_java_using_default_ports.yml | 64 ++ .../overwriting_accessibility_binaries.yml | 2 +- ...mission_modification_using_takeown_app.yml | 2 +- .../possible_browser_pass_view_parameter.yml | 80 ++ ...ible_lateral_movement_powershell_spawn.yml | 86 +++ .../powershell_execute_com_object.yml | 2 +- ...ll_windows_defender_exclusion_commands.yml | 65 ++ ...nt_automatic_repair_mode_using_bcdedit.yml | 2 +- ...eating_lnk_file_in_suspicious_location.yml | 2 +- .../endpoint/process_execution_via_wmi.yml | 2 +- .../endpoint/processes_launching_netsh.yml | 2 +- ...ulating_windows_services_registry_keys.yml | 2 +- .../registry_keys_used_for_persistence.yml | 2 +- ...try_keys_used_for_privilege_escalation.yml | 6 +- ...2_silent_and_install_param_dll_loading.yml | 1 + ...svr32_with_known_silent_switch_cmdline.yml | 4 +- ..._instantiation_via_dcom_and_powershell.yml | 30 +- ...n_via_dcom_and_powershell_script_block.yml | 30 +- ...instantiation_via_winrm_and_powershell.yml | 30 +- ..._via_winrm_and_powershell_script_block.yml | 35 +- ...cess_instantiation_via_winrm_and_winrs.yml | 28 +- .../remote_process_instantiation_via_wmi.yml | 2 +- ...s_instantiation_via_wmi_and_powershell.yml | 30 +- ...on_via_wmi_and_powershell_script_block.yml | 30 +- .../endpoint/remote_wmi_command_attempt.yml | 2 +- .../endpoint/resize_shadowstorage_volume.yml | 2 +- .../endpoint/revil_common_exec_parameter.yml | 2 +- detections/endpoint/revil_registry_entry.yml | 2 +- .../runas_execution_in_commandline.yml | 26 +- .../endpoint/ryuk_wake_on_lan_command.yml | 2 +- .../endpoint/samsam_test_file_write.yml | 2 +- .../sc_exe_manipulating_windows_services.yml | 2 +- ...k_creation_on_remote_endpoint_using_at.yml | 28 +- ...eduled_task_deleted_or_created_via_cmd.yml | 2 +- ...led_task_initiation_on_remote_endpoint.yml | 28 +- .../endpoint/schtasks_run_task_on_demand.yml | 2 +- ...htasks_scheduling_job_on_remote_system.yml | 4 +- .../schtasks_used_for_forcing_a_reboot.yml | 2 +- .../screensaver_event_trigger_execution.yml | 2 +- .../endpoint/script_execution_via_wmi.yml | 2 +- detections/endpoint/sdclt_uac_bypass.yml | 4 +- .../secretdumps_offline_ntds_dumping_tool.yml | 2 +- detections/endpoint/services_escalate_exe.yml | 2 +- ...ces_exe_lolbas_execution_process_spawn.yml | 81 ++ ...ution_policy_to_unrestricted_or_bypass.yml | 2 +- ...nstallation_with_suspicious_parameters.yml | 2 +- .../endpoint/short_lived_scheduled_task.yml | 67 ++ .../endpoint/short_lived_windows_accounts.yml | 2 +- .../endpoint/silentcleanup_uac_bypass.yml | 2 +- .../single_letter_process_on_endpoint.yml | 2 +- detections/endpoint/slui_runas_elevated.yml | 2 +- .../endpoint/slui_spawning_a_process.yml | 2 +- detections/endpoint/spoolsv_writing_a_dll.yml | 2 +- ...ssa___anomalous_usage_of_archive_tools.yml | 79 ++ ...tolen_credentials_via_mimikatz_modules.yml | 85 --- .../ssa___attempt_to_delete_services.yml | 52 +- .../ssa___attempt_to_disable_services.yml | 47 +- ...dential_dump_from_registry_via_reg_exe.yml | 32 +- ..._bcdedit_failure_recovery_modification.yml | 83 ++ .../endpoint/ssa___delete_a_net_user.yml | 44 +- ...___deny_permission_using_cacls_utility.yml | 19 +- ...detect_dump_lsass_memory_using_comsvcs.yml | 24 +- .../endpoint/ssa___detect_kerberoasting.yml | 9 +- ...ssa___detect_rclone_command_line_usage.yml | 91 +++ .../ssa___disable_net_user_account.yml | 56 +- ...___dns_exfiltration_using_nslookup_app.yml | 88 +++ ...xcessive_number_of_office_files_copied.yml | 49 ++ .../ssa___first_time_seen_cmd_line.yml | 33 +- .../endpoint/ssa___fsutil_zeroing_file.yml | 82 ++ ...__grant_permission_using_cacls_utility.yml | 19 +- .../ssa___high_file_deletion_frequency.yml | 70 ++ ...fy_acls_permission_of_files_or_folders.yml | 11 +- ...a___prohibited_apps_spawning_cmdprompt.yml | 48 +- .../ssa___ptt_pth_kerb_ntlm_dest_device.yml | 34 +- .../ssa___ptt_pth_kerb_ntlm_origin_device.yml | 23 +- ...are_parent_process_relationship_lolbas.yml | 25 +- .../ssa___resize_shadowstorage_volume.yml | 46 +- .../ssa___sdelete_application_execution.yml | 104 +-- ...em_process_running_unexpected_location.yml | 3 +- ...unusual_lolbas_in_short_period_of_time.yml | 3 +- .../ssa___unusually_long_command_line.yml | 3 +- .../ssa___wbadmin_delete_system_backups.yml | 86 +++ .../ssa___wevtutil_usage_to_clear_logs.yml | 21 +- .../ssa___wevtutil_usage_to_disable_logs.yml | 21 +- ...dows_curl_upload_to_remote_destination.yml | 99 +++ .../start_up_during_safe_mode_boot.yml | 2 +- .../suspicious_mshta_child_process.yml | 2 +- ...ess_dns_query_known_abuse_web_services.yml | 34 +- .../endpoint/suspicious_process_file_path.yml | 2 +- .../endpoint/suspicious_reg_exe_process.yml | 2 +- ...s_scheduled_task_from_public_directory.yml | 2 +- .../endpoint/suspicious_wevtutil_usage.yml | 2 +- ...ost_exe_lolbas_execution_process_spawn.yml | 80 ++ ...nfo_gathering_using_dxdiag_application.yml | 73 ++ ...system_information_discovery_detection.yml | 2 +- ...rocesses_run_from_unexpected_locations.yml | 2 +- .../time_provider_persistence_registry.yml | 2 +- ...d_messaging_service_spawning_a_process.yml | 2 +- .../endpoint/uninstall_app_using_msiexec.yml | 2 +- .../endpoint/unload_sysmon_filter_driver.yml | 2 +- detections/endpoint/usn_journal_deletion.yml | 2 +- .../wbadmin_delete_system_backups.yml | 2 +- .../wget_download_and_bash_execution.yml | 83 ++ detections/endpoint/windows_adfind_exe.yml | 2 +- ...ndows_curl_download_to_suspicious_path.yml | 54 +- ...dows_curl_upload_to_remote_destination.yml | 54 +- ...dows_defender_exclusion_registry_entry.yml | 68 ++ .../windows_disableantispyware_reg.yml | 10 +- .../endpoint/windows_diskcryptor_usage.yml | 54 +- .../windows_installutil_credential_theft.yml | 58 +- ..._installutil_remote_network_connection.yml | 52 +- .../windows_installutil_uninstall_option.yml | 58 +- ...tallutil_uninstall_option_with_network.yml | 52 +- ...indows_installutil_url_in_command_line.yml | 58 +- ..._created_with_suspicious_service_path.yml} | 30 +- ...ows_service_created_within_public_path.yml | 66 ++ ...ws_service_creation_on_remote_endpoint.yml | 28 +- ..._service_initiation_on_remote_endpoint.yml | 28 +- ...eduled_task_created_within_public_path.yml | 2 +- ...ws_task_scheduler_event_action_started.yml | 26 +- .../endpoint/wmic_xsl_execution_via_url.yml | 54 +- ...sve_exe_lolbas_execution_process_spawn.yml | 80 ++ ...ost_exe_lolbas_execution_process_spawn.yml | 81 ++ detections/endpoint/wsreset_uac_bypass.yml | 4 +- .../xsl_script_execution_with_wmic.yml | 2 +- ...ormally_high_cloud_instances_destroyed.yml | 17 - ...normally_high_cloud_instances_launched.yml | 17 - ...omputer_changed_with_anonymous_account.yml | 0 .../first_time_seen_child_process_of_zoom.yml | 0 .../endpoint/linux_java_spawning_shell.yml | 79 ++ .../print_processor_registry_autostart.yml | 2 +- ...randomly_generated_scheduled_task_name.yml | 64 ++ ...andomly_generated_windows_service_name.yml | 68 ++ ...mote_desktop_process_running_on_system.yml | 2 +- ..._of_computer_service_tickets_requested.yml | 70 ++ ..._remote_endpoint_authentication_events.yml | 69 ++ .../endpoint/windows_java_spawning_shells.yml | 79 ++ .../remote_desktop_network_traffic.yml | 2 +- .../network/detect_outbound_ldap_traffic.yml | 78 ++ ...ry_length_with_high_standard_deviation.yml | 2 +- ...g4shell_jndi_payload_injection_attempt.yml | 89 +++ ...oad_injection_with_outbound_connection.yml | 86 +++ ..._mapping.yaml => detection_ta_mapping.yml} | 719 +++++++++--------- .../enrich_detections.py | 113 +-- 296 files changed, 4868 insertions(+), 1692 deletions(-) create mode 100644 detections/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml rename detections/{endpoint => deprecated}/ssa___applying_stolen_credentials_via_powersploit_modules.yml (65%) rename detections/{endpoint => deprecated}/ssa___assess_credential_strength_via_dsinternals_modules.yml (69%) rename detections/{endpoint => deprecated}/ssa___credential_extraction_dsinternals_conversion_modules.yml (68%) rename detections/{endpoint => deprecated}/ssa___credential_extraction_dsinternals_modules.yml (77%) rename detections/{endpoint => deprecated}/ssa___credential_extraction_fgdump_cachedump_s_option.yml (70%) rename detections/{endpoint => deprecated}/ssa___credential_extraction_fgdump_cachedump_v_option.yml (72%) rename detections/{endpoint => deprecated}/ssa___credential_extraction_getaddbaccount_from_dump.yml (98%) rename detections/{endpoint => deprecated}/ssa___credential_extraction_lazagne_command_options.yml (98%) rename detections/{endpoint => deprecated}/ssa___credential_extraction_mimikatz_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___credential_extraction_ms_debuggers_kernel_peek.yml (99%) rename detections/{endpoint => deprecated}/ssa___credential_extraction_ms_debuggers_z_option.yml (98%) rename detections/{endpoint => deprecated}/ssa___credential_extraction_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___illegal_access_user_content_via_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___illegal_account_creation_via_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___illegal_log_deletion_via_mimikatz_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___illegal_service_and_process_control_via_powersploit_modules.yml (99%) rename detections/{endpoint => deprecated}/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml (99%) rename detections/{endpoint => deprecated}/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml (99%) rename detections/{endpoint => deprecated}/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml (99%) rename detections/{endpoint => deprecated}/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_and_use_computers_via_mimikatz_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_and_use_shares_via_mimikatz_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_and_use_shares_via_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_connectivity_via_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_defensive_tools_via_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___recon_processes_and_services_via_mimikatz_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___setting_credentials_via_dsinternals_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___setting_credentials_via_mimikatz_modules.yml (98%) rename detections/{endpoint => deprecated}/ssa___setting_credentials_via_powersploit_modules.yml (98%) create mode 100644 detections/endpoint/add_or_set_windows_defender_exclusion.yml create mode 100644 detections/endpoint/curl_download_and_bash_execution.yml create mode 100644 detections/endpoint/hunting_for_log4shell.yml create mode 100644 detections/endpoint/impacket_lateral_movement_commandline_parameters.yml create mode 100644 detections/endpoint/java_class_file_download_by_java_user_agent.yml create mode 100644 detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml create mode 100644 detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml create mode 100644 detections/endpoint/possible_browser_pass_view_parameter.yml create mode 100644 detections/endpoint/possible_lateral_movement_powershell_spawn.yml create mode 100644 detections/endpoint/powershell_windows_defender_exclusion_commands.yml create mode 100644 detections/endpoint/services_exe_lolbas_execution_process_spawn.yml create mode 100644 detections/endpoint/short_lived_scheduled_task.yml create mode 100644 detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml delete mode 100644 detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml create mode 100644 detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml create mode 100644 detections/endpoint/ssa___detect_rclone_command_line_usage.yml create mode 100644 detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml create mode 100644 detections/endpoint/ssa___excessive_number_of_office_files_copied.yml create mode 100644 detections/endpoint/ssa___fsutil_zeroing_file.yml create mode 100644 detections/endpoint/ssa___high_file_deletion_frequency.yml create mode 100644 detections/endpoint/ssa___wbadmin_delete_system_backups.yml create mode 100644 detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml create mode 100644 detections/endpoint/svchost_exe_lolbas_execution_process_spawn.yml create mode 100644 detections/endpoint/system_info_gathering_using_dxdiag_application.yml create mode 100644 detections/endpoint/wget_download_and_bash_execution.yml create mode 100644 detections/endpoint/windows_defender_exclusion_registry_entry.yml rename detections/endpoint/{create_service_in_suspicious_file_path.yml => windows_service_created_with_suspicious_service_path.yml} (58%) create mode 100644 detections/endpoint/windows_service_created_within_public_path.yml create mode 100644 detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml create mode 100644 detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml rename detections/{ => experimental}/endpoint/detect_computer_changed_with_anonymous_account.yml (100%) rename detections/{ => experimental}/endpoint/first_time_seen_child_process_of_zoom.yml (100%) create mode 100644 detections/experimental/endpoint/linux_java_spawning_shell.yml create mode 100644 detections/experimental/endpoint/randomly_generated_scheduled_task_name.yml create mode 100644 detections/experimental/endpoint/randomly_generated_windows_service_name.yml create mode 100644 detections/experimental/endpoint/unusual_number_of_computer_service_tickets_requested.yml create mode 100644 detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml create mode 100644 detections/experimental/endpoint/windows_java_spawning_shells.yml create mode 100644 detections/network/detect_outbound_ldap_traffic.yml create mode 100644 detections/web/log4shell_jndi_payload_injection_attempt.yml create mode 100644 detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml rename security_content_automation/{detection_ta_mapping.yaml => detection_ta_mapping.yml} (55%) diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index c1ebe53022..d8cf44e97d 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -66,7 +66,7 @@ tags: - All_Changes.status risk_score: 15 security_domain: network - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_nix diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index b11de42774..cd98ed56be 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -72,7 +72,7 @@ tags: - All_Changes.user risk_score: 15 security_domain: network - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_nix diff --git a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml index c0858b13a2..67fca34b3f 100644 --- a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml +++ b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml @@ -68,7 +68,7 @@ tags: - All_Changes.object risk_score: 36 security_domain: threat - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_aws-kinesis-firehose - Splunk_TA_rsa_securid_cas diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index e800d33873..8b24e673f2 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -69,7 +69,7 @@ tags: - All_Changes.vendor_region risk_score: 18 security_domain: threat - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: diff --git a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml index 40125905fe..05c8aca596 100644 --- a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml +++ b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml @@ -74,7 +74,7 @@ tags: - All_Changes.user risk_score: 42 security_domain: threat - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml index f256ba5606..a98e27c661 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml @@ -69,7 +69,7 @@ tags: - All_Changes.user risk_score: 36 security_domain: threat - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index a369dcf23b..0d63084016 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -69,7 +69,7 @@ tags: - All_Changes.user risk_score: 30 security_domain: threat - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: diff --git a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml index 7d6b9bc75b..eab8044aff 100644 --- a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml @@ -71,7 +71,7 @@ tags: - All_Changes.user risk_score: 42 security_domain: threat - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_nix diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml index 7b1253cf57..be22dff240 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml @@ -90,7 +90,7 @@ tags: - All_Changes.command risk_score: 18 security_domain: threat - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml index 7513be4a01..e75d9325c3 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml @@ -90,7 +90,7 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml index 7253d82d62..572740fc52 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml @@ -89,7 +89,7 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml index b426a4c520..7ca098bbcc 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml @@ -90,7 +90,7 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid diff --git a/detections/cloud/detect_aws_console_login_by_new_user.yml b/detections/cloud/detect_aws_console_login_by_new_user.yml index 406cfcff48..a9a758834d 100644 --- a/detections/cloud/detect_aws_console_login_by_new_user.yml +++ b/detections/cloud/detect_aws_console_login_by_new_user.yml @@ -13,11 +13,11 @@ description: This search looks for AWS CloudTrail events wherein a console login the last hour search: '| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user | `drop_dm_object_name(Authentication)` - | inputlookup append=t previously_seen_users_console_logins | stats min(firstTime) - as firstTime max(lastTime) as lastTime by user | eval userStatus=if(firstTime >=relative_time(now(),"-24h@h"), - "First Time Logging into AWS Console", "Previously Seen User") |where userStatus="First - Time Logging into AWS Console" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| - `detect_aws_console_login_by_new_user_filter`' + | join user type=outer [ inputlookup previously_seen_users_console_logins | stats + min(firstTime) as earliestseen by user] | eval userStatus=if(earliestseen >= relative_time(now(), + "-24h@h") OR isnull(earliestseen), "First Time Logging into AWS Console", "Previously + Seen User") | where userStatus="First Time Logging into AWS Console" | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `detect_aws_console_login_by_new_user_filter`' how_to_implement: You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Run the `Previously Seen Users diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml index e4cc5ea1a1..eee269a1eb 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml @@ -15,8 +15,8 @@ search: '| tstats earliest(_time) as firstTime latest(_time) as lastTime from da where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src | iplocation Authentication.src | `drop_dm_object_name(Authentication)` | table firstTime lastTime user City | join user type=outer [| inputlookup previously_seen_users_console_logins - | stats earliest(firstTime) AS earliestseen by user City | fields earliestseen user - City] | eval userCity=if(firstTime >= relative_time(now(), "-24h@h"), "New City","Previously + | stats min(firstTime) AS earliestseen by user City | fields earliestseen user City] + | eval userCity=if(firstTime >= relative_time(now(), "-24h@h"), "New City","Previously Seen City") | eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") OR isnull(earliestseen), "New User","Old User") | where userCity = "New City" AND userStatus != "Old User" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml index e0de730c05..8c672eef83 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml @@ -15,9 +15,9 @@ search: '| tstats earliest(_time) as firstTime latest(_time) as lastTime from da where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src | iplocation Authentication.src | `drop_dm_object_name(Authentication)` | table firstTime lastTime user Country | join user type=outer [| inputlookup previously_seen_users_console_logins - | stats earliest(firstTime) AS earliestseen by user Country | fields earliestseen - user Country] | eval userCountry=if(firstTime >= relative_time(now(), "-24h@h"), - "New Country","Previously Seen Country") | eval userStatus=if(earliestseen >= relative_time(now(),"-24h@h") + | stats min(firstTime) AS earliestseen by user Country | fields earliestseen user + Country] | eval userCountry=if(firstTime >= relative_time(now(), "-24h@h"), "New + Country","Previously Seen Country") | eval userStatus=if(earliestseen >= relative_time(now(),"-24h@h") OR isnull(earliestseen), "New User","Old User") | where userCountry = "New Country" AND userStatus != "Old User" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table firstTime lastTime user Country userStatus userCountry | `detect_aws_console_login_by_user_from_new_country_filter`' diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml index 806537ad99..e9f51bd972 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml @@ -15,11 +15,11 @@ search: '| tstats earliest(_time) as firstTime latest(_time) as lastTime from da where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src | iplocation Authentication.src | `drop_dm_object_name(Authentication)` | table firstTime lastTime user Region | join user type=outer [| inputlookup previously_seen_users_console_logins - | stats earliest(firstTime) AS earliestseen by user Region | fields earliestseen - user Region] | eval userRegion=if(firstTime >= relative_time(now(), "-24h@h"), "New - Region","Previously Seen Region") | eval userStatus=if(earliestseen >= relative_time(now(), - "-24h@h") OR isnull(earliestseen), "New User","Old User") | where userRegion = "New - Region" AND userStatus != "Old User" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | stats min(firstTime) AS earliestseen by user Region | fields earliestseen user + Region] | eval userRegion=if(firstTime >= relative_time(now(), "-24h@h"), "New Region","Previously + Seen Region") | eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") + OR isnull(earliestseen), "New User","Old User") | where userRegion = "New Region" + AND userStatus != "Old User" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table firstTime lastTime user Region userStatus userRegion | `detect_aws_console_login_by_user_from_new_region_filter`' how_to_implement: You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates diff --git a/detections/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml b/detections/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml new file mode 100644 index 0000000000..1ab52f5e28 --- /dev/null +++ b/detections/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml @@ -0,0 +1,105 @@ +name: Applying Stolen Credentials via Mimikatz modules +id: 759a653f-cb92-40f9-94c9-ec4e47b0f709 +version: 2 +date: '2021-11-24' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: The following analytic identifites the use of Mimikatz modules attempting + to perform Pass-the-Ticket, Golden or Silver Kerberos ticket attacks and Skeleton + Key attack. This behavior is typically performed within interactive Mimikatz memory + space, however it may be identified on the command-line. A Pass-the-Ticket (ptt) + attack is performed once an adversary has established access to a single endpoint + and retrieved the kerberos ticket to now begin moving laterally using this method. + Typically, it blends in with logon activity as the ticket can be copied to another + system and passed into the current session effectively simulating a logon without + any communication with the Domain Controller. A Golden or Silver ticket attack requires + some setup by the adversary, but once performed it will simulate lateral based authentication + to additional endpoints. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line != null AND ( match_regex(cmd_line, /(?i)kerberos::ptt/)=true OR match_regex(cmd_line, + /(?i)kerberos::golden/)=true OR match_regex(cmd_line, /(?i)kerberos::silver/)=true + OR match_regex(cmd_line, /(?i)misc::skeleton/)=true ) | eval start_time = timestamp, + end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to Mimikatz. +references: +- https://github.com/gentilkiwi/mimikatz +- https://adsecurity.org/?p=1275 +- https://adsecurity.org/?p=1515 +- https://adsecurity.org/?page_id=1821#KERBEROSPTT +- https://attack.mitre.org/software/S0002/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1550.002/T1550.002.md#atomic-test-1---mimikatz-pass-the-hash +tags: + analytic_story: + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is violating authentication processes by injecting golden + or silver Kerberos tickets or passing stolen authentication tokens. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1055 + - T1068 + - T1078 + - T1098 + - T1134 + - T1543 + - T1547 + - T1548 + - T1554 + - T1556 + - T1558 + - T1558.002 + - T1558.001 + - T1003 + - T1003.001 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + - cmd_line + risk_score: 90 + risk_severity: high + security_domain: endpoint diff --git a/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml b/detections/deprecated/ssa___applying_stolen_credentials_via_powersploit_modules.yml similarity index 65% rename from detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml rename to detections/deprecated/ssa___applying_stolen_credentials_via_powersploit_modules.yml index 5835d34f11..080e134e90 100644 --- a/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___applying_stolen_credentials_via_powersploit_modules.yml @@ -1,14 +1,19 @@ name: Applying Stolen Credentials via PowerSploit modules id: 270b482d-2af2-448f-9923-9cf005f61be4 -version: 1 -date: '2020-11-03' +version: 2 +date: '2021-11-24' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] -description: Stolen credentials are applied by methods such as user impersonation, - credential injection, spoofing of authentication processes or getting hold of critical - accounts. This detection indicates such activities carried out by PowerSploit exploit - kit APIs. +datamodel: +- Endpoint_Processes +description: The following analytic identifies commonly used PowerSploit modules that + perform credential access, spoofing of authentication processes, user impersonation + and attempting to manipulate tokens. Specifically, the following modules `Invoke-CredentialInjection`, + `Invoke-TokenManipulation`, `Invoke-UserImpersonation`, `Get-System`, and `Invoke-RevertToSelf` + were identfiied as modules used to access credentials. PowerSploit is an archived + project on GitHub, but much of its modules and scripts are still utilized today + by adversaries. This behavior is typically performed within interactive PowerShell + sessions or injected into processes, however it may be identified on the command-line. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -23,11 +28,15 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to PowerSploit. references: - https://github.com/PowerShellMafia/PowerSploit +- https://attack.mitre.org/software/S0194/ tags: analytic_story: - Credential Dumping @@ -61,6 +70,7 @@ tags: - T1554 - T1555 - T1558 + - T1059.001 nist: - PR.AC - PR.IP @@ -84,6 +94,7 @@ tags: - dest_user_id - process - _time + - cmd_line risk_score: 90 risk_severity: high security_domain: endpoint diff --git a/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml b/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml similarity index 69% rename from detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml rename to detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml index 9fb311d807..6fb960b256 100644 --- a/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml +++ b/detections/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml @@ -1,12 +1,14 @@ name: Assessment of Credential Strength via DSInternals modules id: 5526d3a4-2497-4e8d-9d3c-7a34c9aace2f -version: 1 -date: '2020-11-03' +version: 2 +date: '2021-11-24' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] -description: This detection identifies use of DSInternals modules that verify password - strength, i.e., identify week accounts that would be easily compromised. +datamodel: +- Endpoint_Processes +description: The following analytic identifies the use of a DSInternals module, `Test-PasswordQuality`, + that verifies password strength. Adversaries have utilized this module to determine + password complexity or to identify accounts with weak passwords. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -18,11 +20,15 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. references: - https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ tags: analytic_story: - Credential Dumping @@ -48,6 +54,8 @@ tags: - T1201 - T1552 - T1555 + - T1059.001 + - T1059 nist: - PR.AC - PR.IP @@ -71,6 +79,7 @@ tags: - process - dest_device_id - dest_user_id + - cmd_line risk_score: 25 risk_severity: high security_domain: endpoint diff --git a/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml b/detections/deprecated/ssa___credential_extraction_dsinternals_conversion_modules.yml similarity index 68% rename from detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml rename to detections/deprecated/ssa___credential_extraction_dsinternals_conversion_modules.yml index 5b5086bcea..e929f5a744 100644 --- a/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml +++ b/detections/deprecated/ssa___credential_extraction_dsinternals_conversion_modules.yml @@ -1,15 +1,17 @@ name: Credential Extraction indicative of use of DSInternals credential conversion modules id: 73e23834-c7ad-4860-bfd0-7d8ffe6527c2 -version: 1 -date: '2020-10-21' +version: 2 +date: '2021-11-29' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] -description: Credential extraction is often an illegal recovery of credential material - from secured authentication resources and repositories. This process may also involve - decryption or other transformations of the stored credential material. DSInternals - is a collection of PowerShell modules commonly employed in exploits. +datamodel: +- Endpoint_Processes +description: The following analytic identifies modules within DSInternals that are + used for extracting credentials from Active Directory. Modules include `ConvertFrom-ADManagedPasswordBlob`, + `ConvertFrom-GPPrefPassword`, `ConvertFrom-UnicodePasswor`, `ConvertTo-GPPrefPassword`,`ConvertTo-KerberosKey`, + `ConvertTo-LMHash`, `ConvertTo-NTHash` `ConvertTo-OrgIdHash` or `ConvertTo-UnicodePassword`. + Adversaries may use these modules for decrypting or transforming the stored credentials. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -29,11 +31,15 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. references: - https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ tags: analytic_story: - Credential Dumping @@ -52,10 +58,12 @@ tags: kill_chain_phases: - Actions on Objectives message: DSInternals tool kit is converting stolen credential material to a form - applicable to authentications. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ + applicable to authentications. Operation is performed on the device $dest_device_id$, + by the account $dest_user_id$ via process $process_name$. mitre_attack_id: - T1003 + - T1003.002 + - T1059.001 nist: - PR.AC - PR.IP @@ -68,10 +76,10 @@ tags: type: Hostname role: - Victim - - name: cmd_line - type: processname + - name: process_name + type: process role: - - Others + - Child Process product: - Splunk Behavioral Analytics required_fields: @@ -81,7 +89,7 @@ tags: - _time - process_path - dest_user_id - - process + - cmd_line risk_score: 70 risk_severity: high security_domain: endpoint diff --git a/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml b/detections/deprecated/ssa___credential_extraction_dsinternals_modules.yml similarity index 77% rename from detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml rename to detections/deprecated/ssa___credential_extraction_dsinternals_modules.yml index ebfa2cf9b0..131eca2eec 100644 --- a/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml +++ b/detections/deprecated/ssa___credential_extraction_dsinternals_modules.yml @@ -1,14 +1,14 @@ name: Credential Extraction indicative of use of DSInternals modules id: 5d2172f0-8a7d-4ecd-aad9-2dcc95699e0d -version: 1 -date: '2020-10-21' +version: 2 +date: '2021-11-29' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] -description: Credential extraction is often an illegal recovery of credential material - from secured authentication resources and repositories. This process may also involve - decryption or other transformations of the stored credential material. DSInternals - is a collection of PowerShell modules commonly employed in exploits. +datamodel: +- Endpoint_Processes +description: The following analytic identifies modules of DSInternals being used on + the associated endpoint. Adversaries may use these modules for manipulating data + related to Active Directory and credentials. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -30,11 +30,15 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. references: - https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ tags: analytic_story: - Credential Dumping @@ -55,9 +59,11 @@ tags: message: DSInternals tool kit is accessing sensitive credential material such as KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ + via process $process_name$ mitre_attack_id: - T1003 + - T1003.002 + - T1059.001 nist: - PR.AC - PR.IP @@ -70,10 +76,10 @@ tags: type: Hostname role: - Victim - - name: cmd_line - type: processname + - name: process_name + type: Process role: - - Others + - Child Process product: - Splunk Behavioral Analytics required_fields: @@ -84,6 +90,7 @@ tags: - process_path - dest_user_id - process + - cmd_line risk_score: 70 risk_severity: high security_domain: endpoint diff --git a/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml b/detections/deprecated/ssa___credential_extraction_fgdump_cachedump_s_option.yml similarity index 70% rename from detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml rename to detections/deprecated/ssa___credential_extraction_fgdump_cachedump_s_option.yml index 97f3faaa8f..9c28659f43 100644 --- a/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml +++ b/detections/deprecated/ssa___credential_extraction_fgdump_cachedump_s_option.yml @@ -1,15 +1,14 @@ name: Credential Extraction indicative of FGDump and CacheDump with s option id: 312582f2-5e91-42c1-a275-cd67f31373c8 -version: 1 -date: '2020-10-18' +version: 2 +date: '2021-11-29' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] -description: Credential extraction is often an illegal recovery of credential material - from secured authentication resources and repositories. This process may also involve - decryption or other transformations of the stored credential material. FGdump is - a newer version of pwdump tool that extracts NTLM and LanMan password hashes from - Windows. Cachedump is a publicly-available tool that extracts cached password hashes +datamodel: +- Endpoint_Processes +description: The following analytic identifies the use of CacheDump with the `-s` + parameter to dump cached credentials on the associated endpoint. Adversaries use + Cachedump as it is a publicly-available tool that extracts cached password hashes from a system's registry. search: ' | from read_ssa_enriched_events() @@ -27,10 +26,17 @@ search: ' | from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: [] +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: False positives will be limited as this analytic targets specific + credential dumping process names. Filter as needed. +references: +- https://attack.mitre.org/software/S0119/ +- https://en.kali.tools/all/?tool=182 +- http://foofus.net/goons/fizzgig/fgdump/ +- https://attack.mitre.org/software/S0120/ tags: analytic_story: - Unusual Processes @@ -50,9 +56,10 @@ tags: - Actions on Objectives message: Malicious actor is accessing stored credentials via FGDump or CacheDump tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ + via process $process_name$. mitre_attack_id: - T1003 + - T1003.002 nist: - PR.AC - PR.IP @@ -65,10 +72,10 @@ tags: type: Hostname role: - Victim - - name: cmd_line - type: processname + - name: process_name + type: Process role: - - Others + - Child Process product: - Splunk Behavioral Analytics required_fields: @@ -79,6 +86,7 @@ tags: - process_path - dest_user_id - process + - cmd_line risk_score: 70 risk_severity: high security_domain: endpoint diff --git a/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml b/detections/deprecated/ssa___credential_extraction_fgdump_cachedump_v_option.yml similarity index 72% rename from detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml rename to detections/deprecated/ssa___credential_extraction_fgdump_cachedump_v_option.yml index cd0b392e95..b1f22d6bb8 100644 --- a/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml +++ b/detections/deprecated/ssa___credential_extraction_fgdump_cachedump_v_option.yml @@ -1,15 +1,14 @@ name: Credential Extraction indicative of FGDump and CacheDump with v option id: 3c40b0ef-a03f-460a-9484-e4b9117cbb38 -version: 1 -date: '2020-10-18' +version: 2 +date: '2021-11-29' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] -description: Credential extraction is often an illegal recovery of credential material - from secured authentication resources and repositories. This process may also involve - decryption or other transformations of the stored credential material. FGdump is - a newer version of pwdump tool that extracts NTLM and LanMan password hashes from - Windows. Cachedump is a publicly-available tool that extracts cached password hashes +datamodel: +- Endpoint_Processes +description: The following analytic identifies the use of CacheDump with the `-v` + parameter to dump cached credentials on the associated endpoint. Adversaries use + Cachedump as it is a publicly-available tool that extracts cached password hashes from a system's registry. search: ' | from read_ssa_enriched_events() @@ -25,9 +24,12 @@ search: ' | from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: False positives will be limited as this analytic targets specific + credential dumping process names. Filter as needed. references: [] tags: analytic_story: @@ -48,9 +50,10 @@ tags: - Actions on Objectives message: Malicious actor is accessing stored credentials via FGDump or CacheDump tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ + via process $process_name$ mitre_attack_id: - T1003 + - T1003.002 nist: - PR.AC - PR.IP @@ -63,10 +66,10 @@ tags: type: Hostname role: - Victim - - name: cmd_line - type: processname + - name: process_name + type: Process role: - - Others + - Child Process product: - Splunk Behavioral Analytics required_fields: @@ -76,6 +79,7 @@ tags: - process_path - dest_user_id - process + - cmd_line risk_score: 63 risk_severity: high security_domain: endpoint diff --git a/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml b/detections/deprecated/ssa___credential_extraction_getaddbaccount_from_dump.yml similarity index 98% rename from detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml rename to detections/deprecated/ssa___credential_extraction_getaddbaccount_from_dump.yml index ee2e8d7e10..f7d42f0841 100644 --- a/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml +++ b/detections/deprecated/ssa___credential_extraction_getaddbaccount_from_dump.yml @@ -5,7 +5,8 @@ version: 1 date: '2020-10-18' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. PowerSploit diff --git a/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml b/detections/deprecated/ssa___credential_extraction_lazagne_command_options.yml similarity index 98% rename from detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml rename to detections/deprecated/ssa___credential_extraction_lazagne_command_options.yml index de232ad83f..e18d3f48ad 100644 --- a/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml +++ b/detections/deprecated/ssa___credential_extraction_lazagne_command_options.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-18' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. LaZagne is diff --git a/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml b/detections/deprecated/ssa___credential_extraction_mimikatz_modules.yml similarity index 98% rename from detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml rename to detections/deprecated/ssa___credential_extraction_mimikatz_modules.yml index bc0cc3c8a1..719e5d50f1 100644 --- a/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml +++ b/detections/deprecated/ssa___credential_extraction_mimikatz_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-21' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Mimikatz diff --git a/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml b/detections/deprecated/ssa___credential_extraction_ms_debuggers_kernel_peek.yml similarity index 99% rename from detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml rename to detections/deprecated/ssa___credential_extraction_ms_debuggers_kernel_peek.yml index 75a194325c..b5ad8dfcc2 100644 --- a/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml +++ b/detections/deprecated/ssa___credential_extraction_ms_debuggers_kernel_peek.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-18' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Native Microsoft diff --git a/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml b/detections/deprecated/ssa___credential_extraction_ms_debuggers_z_option.yml similarity index 98% rename from detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml rename to detections/deprecated/ssa___credential_extraction_ms_debuggers_z_option.yml index 3820b3a887..a8c42624e1 100644 --- a/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml +++ b/detections/deprecated/ssa___credential_extraction_ms_debuggers_z_option.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-18' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Native Microsoft diff --git a/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml b/detections/deprecated/ssa___credential_extraction_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___credential_extraction_powersploit_modules.yml rename to detections/deprecated/ssa___credential_extraction_powersploit_modules.yml index feca60030d..04ff3f2af3 100644 --- a/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml +++ b/detections/deprecated/ssa___credential_extraction_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-21' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. PowerSploit diff --git a/detections/deprecated/ssa___detect_pass_hash.yml b/detections/deprecated/ssa___detect_pass_hash.yml index 49ae7ca771..cd076b5e12 100644 --- a/detections/deprecated/ssa___detect_pass_hash.yml +++ b/detections/deprecated/ssa___detect_pass_hash.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-21' author: Xiao Lin, Splunk type: TTP -datamodel: [] +datamodel: +- Authentication description: This search looks for specific authentication events from the Windows Security Event logs to detect potential attempts using Pass-the-Hash technique. search: ' | from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml b/detections/deprecated/ssa___illegal_access_user_content_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml rename to detections/deprecated/ssa___illegal_access_user_content_via_powersploit_modules.yml index f2d3a42c59..fda8390475 100644 --- a/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___illegal_access_user_content_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules that enable illegaly access user content, such as key logging, audio recording, screenshots, tapping into http and RDP sessions, etc. diff --git a/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml b/detections/deprecated/ssa___illegal_account_creation_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml rename to detections/deprecated/ssa___illegal_account_creation_via_powersploit_modules.yml index 5706bc23ef..08bb1ad9fc 100644 --- a/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___illegal_account_creation_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules that create accounts illegaly. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml b/detections/deprecated/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml similarity index 98% rename from detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml rename to detections/deprecated/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml index 19ddea7678..afdf84bcac 100644 --- a/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml +++ b/detections/deprecated/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of DSInternals modules that enable or disable accounts illegaly. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml b/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml similarity index 98% rename from detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml rename to detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml index 34cbfa9e81..24be672979 100644 --- a/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml +++ b/detections/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules that delete event logs. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml b/detections/deprecated/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml similarity index 98% rename from detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml rename to detections/deprecated/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml index b3d2019c91..85fa7639e5 100644 --- a/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml +++ b/detections/deprecated/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml @@ -5,7 +5,8 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of DSInternals modules for illegal management of Active Directoty elements and policies. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml b/detections/deprecated/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml rename to detections/deprecated/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml index ebebdf9258..3a54457131 100644 --- a/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml @@ -5,7 +5,8 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules that enable illegal management of computers and Active Directory elements. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml b/detections/deprecated/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml rename to detections/deprecated/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml index 93ebd26c4e..254a2292a9 100644 --- a/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules that illegaly elevate general privileges or ensure persistence, e.g., enable manipulation of registry, task scheduling, persistent WMI, access to OS objects under desired identities. diff --git a/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml b/detections/deprecated/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml similarity index 98% rename from detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml rename to detections/deprecated/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml index 43af6b051f..54f6aec7bb 100644 --- a/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml +++ b/detections/deprecated/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of Mimikatz modules for illegal privilege elevation. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml b/detections/deprecated/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml similarity index 98% rename from detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml rename to detections/deprecated/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml index 053e04b3ec..c94e7c2c1f 100644 --- a/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml +++ b/detections/deprecated/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of Mimikatz modules for illegal control over services and processes, including the authentication service. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml b/detections/deprecated/ssa___illegal_service_and_process_control_via_powersploit_modules.yml similarity index 99% rename from detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml rename to detections/deprecated/ssa___illegal_service_and_process_control_via_powersploit_modules.yml index f1a19ab5ac..835cbc4e6c 100644 --- a/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___illegal_service_and_process_control_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules that enable illegal control of services and processes, such as installing or spoofing of malicious services, injecting malicious code in DLLs and EXEs, invoking shell code and WMI commands, diff --git a/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml b/detections/deprecated/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml rename to detections/deprecated/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml index fc96b2948a..afcded581a 100644 --- a/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-04' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of PowerSploit modules that facilitate access probing with admin credentials as well as probing access to system services. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml b/detections/deprecated/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml similarity index 99% rename from detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml rename to detections/deprecated/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml index 9098776ffb..e6238d3e36 100644 --- a/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of PowerSploit modules that discover opportunities for malicious access and persistence. Some examples include access to admin accounts, weak access control policies, landing paths for dropping malicious software or data diff --git a/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml b/detections/deprecated/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml similarity index 99% rename from detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml rename to detections/deprecated/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml index 151bdea120..e49bc3b415 100644 --- a/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules that discover accounts, groups and policies that can be accessed or taken over. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml b/detections/deprecated/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml rename to detections/deprecated/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml index 14322b2d3e..96ee3261f0 100644 --- a/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml +++ b/detections/deprecated/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of Mimikatz modules for discovery of accounts and groups and access to them. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml b/detections/deprecated/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml similarity index 99% rename from detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml rename to detections/deprecated/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml index 7248a1482a..c711912309 100644 --- a/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml @@ -5,7 +5,8 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules for reconnaissance and access to elements of Active Directory infrastructure, such as domain identifiers, AD sites and forests, and trust relations. diff --git a/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml b/detections/deprecated/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml rename to detections/deprecated/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml index c22a323921..06fa9a94cf 100644 --- a/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules that discover computers, servers and domains that can be accessed or taken over. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml b/detections/deprecated/ssa___recon_and_use_computers_via_mimikatz_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml rename to detections/deprecated/ssa___recon_and_use_computers_via_mimikatz_modules.yml index 2a409ce088..4de51aecc6 100644 --- a/detections/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml +++ b/detections/deprecated/ssa___recon_and_use_computers_via_mimikatz_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of Mimikatz modules for discovery of computers and servers and access to them. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml b/detections/deprecated/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml rename to detections/deprecated/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml index a63cfbbb23..4f32e0a43a 100644 --- a/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules that discover and access operating system elements, such as processes, services, registry locations, security packages and files. diff --git a/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml b/detections/deprecated/ssa___recon_and_use_shares_via_mimikatz_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml rename to detections/deprecated/ssa___recon_and_use_shares_via_mimikatz_modules.yml index 66d177f48b..87194d38a9 100644 --- a/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml +++ b/detections/deprecated/ssa___recon_and_use_shares_via_mimikatz_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of Mimikatz modules for discovery and access to network shares. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml b/detections/deprecated/ssa___recon_and_use_shares_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml rename to detections/deprecated/ssa___recon_and_use_shares_via_powersploit_modules.yml index c98b38ae46..ef1f07cc20 100644 --- a/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___recon_and_use_shares_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules that discover and access network and distributed file system shares. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml b/detections/deprecated/ssa___recon_connectivity_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml rename to detections/deprecated/ssa___recon_connectivity_via_powersploit_modules.yml index 8fe5b4980a..1a656d9570 100644 --- a/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___recon_connectivity_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies access to PowerSploit modules for reconnaissance of connectivity. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml b/detections/deprecated/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml rename to detections/deprecated/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml index 84eef9576b..a6fdc66b33 100644 --- a/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml +++ b/detections/deprecated/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-03' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies reconnaissance of credential stores and use of CryptoAPI services by Mimikatz modules. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml b/detections/deprecated/ssa___recon_defensive_tools_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml rename to detections/deprecated/ssa___recon_defensive_tools_via_powersploit_modules.yml index 511a1cb7c0..94908b1186 100644 --- a/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___recon_defensive_tools_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of PowerSploit modules for assessment of presence of defensive tools. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml b/detections/deprecated/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml rename to detections/deprecated/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml index 1e8f9fded4..4c2ae2cd99 100644 --- a/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of PowerSploit modules for assessment of privilege escalation opportunities. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml b/detections/deprecated/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml rename to detections/deprecated/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml index d2598550e5..86f058a343 100644 --- a/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml +++ b/detections/deprecated/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of Mimikatz modules for discovery of process or service hijacking opportunities via Microsoft Detours compatibility. Microsoft Detours is an open source library for intercepting, monitoring and instrumenting diff --git a/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml b/detections/deprecated/ssa___recon_processes_and_services_via_mimikatz_modules.yml similarity index 98% rename from detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml rename to detections/deprecated/ssa___recon_processes_and_services_via_mimikatz_modules.yml index 0a785c034c..6f4d2c9603 100644 --- a/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml +++ b/detections/deprecated/ssa___recon_processes_and_services_via_mimikatz_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies use of Mimikatz modules for discovery and access to services and processes. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml b/detections/deprecated/ssa___setting_credentials_via_dsinternals_modules.yml similarity index 98% rename from detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml rename to detections/deprecated/ssa___setting_credentials_via_dsinternals_modules.yml index f53e3f8990..e8c8223525 100644 --- a/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml +++ b/detections/deprecated/ssa___setting_credentials_via_dsinternals_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-03' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies illegal setting of credentials via DSInternals modules. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml b/detections/deprecated/ssa___setting_credentials_via_mimikatz_modules.yml similarity index 98% rename from detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml rename to detections/deprecated/ssa___setting_credentials_via_mimikatz_modules.yml index 2b1e4255b0..1499f30134 100644 --- a/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml +++ b/detections/deprecated/ssa___setting_credentials_via_mimikatz_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-03' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies illegal setting of credentials via Mimikatz modules. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml b/detections/deprecated/ssa___setting_credentials_via_powersploit_modules.yml similarity index 98% rename from detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml rename to detections/deprecated/ssa___setting_credentials_via_powersploit_modules.yml index 5475eddbd4..caaf182457 100644 --- a/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml +++ b/detections/deprecated/ssa___setting_credentials_via_powersploit_modules.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-03' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Endpoint_Processes description: This detection identifies illegal setting of credentials via PowerSploit modules. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index cf08e122ac..0cadcc83db 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -69,6 +69,6 @@ tags: - Registry.registry_value_name risk_score: 64 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml index 698637479a..031d18581b 100644 --- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml +++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml @@ -14,8 +14,8 @@ description: this search is to detect a suspicious registry modification to impl premise. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows - NT\\CurrentVersion\\Winlogon*" AND Registry.registry_key_name= DefaultPassword OR - Registry.registry_key_name= DefaultUserName by Registry.registry_path Registry.registry_key_name + NT\\CurrentVersion\\Winlogon*" AND Registry.registry_value_name= DefaultPassword + OR Registry.registry_value_name= DefaultUserName by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `add_defaultuser_and_password_in_registry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information @@ -60,6 +60,6 @@ tags: - Registry.dest risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/add_or_set_windows_defender_exclusion.yml b/detections/endpoint/add_or_set_windows_defender_exclusion.yml new file mode 100644 index 0000000000..8fe360863f --- /dev/null +++ b/detections/endpoint/add_or_set_windows_defender_exclusion.yml @@ -0,0 +1,75 @@ +name: Add or Set Windows Defender Exclusion +id: 773b66fe-4dd9-11ec-8289-acde48001122 +version: 1 +date: '2021-11-25' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic will detect a suspicious process commandline related to + windows defender exclusion feature. This command is abused by adversaries, malware + author and red teams to bypassed Windows Defender Anti-Virus product by excluding folder + path, file path, process, extensions and etc. from its real time or schedule scan + to execute their malicious code. This is a good indicator for defense evasion and + to look further for events after this behavior. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.process = "*Add-MpPreference + *" OR Processes.process = "*Set-MpPreference *") AND Processes.process="*-exclusion*" + by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name + Processes.process_name Processes.original_file_name Processes.process Processes.process_id + Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `add_or_set_windows_defender_exclusion_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: admin or user may choose to use this windows features. +references: +- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html +- https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/ +tags: + analytic_story: + - Remcos + - Windows Defense Evasion Tactics + automated_detection_testing: passed + confidence: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/defender_exclusion_sysmon/sysmon.log + impact: 80 + kill_chain_phases: + - Exploitation + message: exclusion command $process$ executed on $dest$ + mitre_attack_id: + - T1562.001 + - T1562 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 64 + security_domain: endpoint diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index d871783719..dc6d46a0f5 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -65,6 +65,6 @@ tags: - Registry.user risk_score: 3 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/allow_operation_with_consent_admin.yml b/detections/endpoint/allow_operation_with_consent_admin.yml index 8b6006e29b..f44cfc4dd2 100644 --- a/detections/endpoint/allow_operation_with_consent_admin.yml +++ b/detections/endpoint/allow_operation_with_consent_admin.yml @@ -13,8 +13,8 @@ description: This analytic identifies a potential privilege escalation attempt t machine. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*" - Registry.registry_key_name = ConsentPromptBehaviorAdmin Registry.registry_value_name - = "DWORD (0x00000000)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name + Registry.registry_value_name = ConsentPromptBehaviorAdmin Registry.registry_value_data + = "0x00000000" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `allow_operation_with_consent_admin_filter`' how_to_implement: To successfully implement this search, you must be ingesting data @@ -65,6 +65,6 @@ tags: - Registry.dest risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index f4a55cfc12..1f9f5f1c42 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -82,6 +82,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml index c033e1f993..640444b0cf 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/endpoint/any_powershell_downloadfile.yml @@ -33,11 +33,14 @@ tags: analytic_story: - Malicious PowerShell - Ingress Tool Transfer + - Log4Shell CVE-2021-44228 automated_detection_testing: passed confidence: 70 context: - Source:Endpoint - Stage:Exploitation + cve: + - CVE-2021-44228 dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log impact: 80 diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 195090090c..8eae53f6f0 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -86,7 +86,7 @@ tags: - Processes.parent_process risk_score: 64 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index 63d027ddea..977f5b7446 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -84,6 +84,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/auto_admin_logon_registry_entry.yml b/detections/endpoint/auto_admin_logon_registry_entry.yml index a856efd514..566bf334c1 100644 --- a/detections/endpoint/auto_admin_logon_registry_entry.yml +++ b/detections/endpoint/auto_admin_logon_registry_entry.yml @@ -60,6 +60,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index 6c658858f5..ec9a4f196f 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -83,7 +83,7 @@ tags: - Processes.dest risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml index fcad216378..bd4cd72547 100644 --- a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml +++ b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml @@ -65,6 +65,6 @@ tags: - Processes.user risk_score: 35 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/bcdedit_failure_recovery_modification.yml b/detections/endpoint/bcdedit_failure_recovery_modification.yml index f9e5592b67..4590eb2e90 100644 --- a/detections/endpoint/bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/bcdedit_failure_recovery_modification.yml @@ -75,7 +75,7 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/change_default_file_association.yml b/detections/endpoint/change_default_file_association.yml index 28852856ab..39b2a1a629 100644 --- a/detections/endpoint/change_default_file_association.yml +++ b/detections/endpoint/change_default_file_association.yml @@ -66,6 +66,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/change_to_safe_mode_with_network_config.yml b/detections/endpoint/change_to_safe_mode_with_network_config.yml index 98783372ba..335f555d66 100644 --- a/detections/endpoint/change_to_safe_mode_with_network_config.yml +++ b/detections/endpoint/change_to_safe_mode_with_network_config.yml @@ -64,6 +64,6 @@ tags: - Processes.user risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/check_elevated_cmd_using_whoami.yml b/detections/endpoint/check_elevated_cmd_using_whoami.yml index e7d6338b01..42f46c1742 100644 --- a/detections/endpoint/check_elevated_cmd_using_whoami.yml +++ b/detections/endpoint/check_elevated_cmd_using_whoami.yml @@ -65,6 +65,6 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/cmd_carry_out_string_command_parameter.yml b/detections/endpoint/cmd_carry_out_string_command_parameter.yml index 04dee0f6bd..0550aed76a 100644 --- a/detections/endpoint/cmd_carry_out_string_command_parameter.yml +++ b/detections/endpoint/cmd_carry_out_string_command_parameter.yml @@ -1,43 +1,50 @@ name: CMD Carry Out String Command Parameter id: 54a6ed00-3256-11ec-b031-acde48001122 -version: 1 -date: '2021-10-21' -author: Teoderick Contreras, Splunk, Bhavin Patel, Splunk +version: 2 +date: '2021-12-13' +author: Teoderick Contreras, Bhavin Patel, Splunk type: Hunting datamodel: - Endpoint -description: This search looks for command-line arguments where `cmd.exe /c` is used - to execute a program. This technique is commonly seen in adversaries and malware - to execute batch command using different shell like powershell or different process - other than cmd.exe. This is a good hunting query for suspicious commandline made - by a script or relative process execute it. +description: The following analytic identifies command-line arguments where `cmd.exe + /c` is used to execute a program. `cmd /c` is used to run commands in MS-DOS and + terminate after command or process completion. This technique is commonly seen in + adversaries and malware to execute batch command using different shell like PowerShell + or different process other than `cmd.exe`. This is a good hunting query for suspicious + command-line made by a script or relative process execute it. search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` AND Processes.process="* /c *" by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `cmd_carry_out_string_command_parameter_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -known_false_positives: unknown +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives may be high based on legitimate scripted code + in any environment. Filter as needed. references: - https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/ tags: analytic_story: - IcedID + - Log4Shell CVE-2021-44228 automated_detection_testing: passed confidence: 50 context: - Source:Endpoint - Stage:Execution + cve: + - CVE-2021-44228 dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/cmd_carry_str_param/sysmon.log impact: 60 kill_chain_phases: - Exploitation - message: $process_name$ with commandline $process$ in $dest$ + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$ attempting spawn a new process. mitre_attack_id: - T1059.003 - T1059 diff --git a/detections/endpoint/csc_net_on_the_fly_compilation.yml b/detections/endpoint/csc_net_on_the_fly_compilation.yml index ae91b068f7..416939c42f 100644 --- a/detections/endpoint/csc_net_on_the_fly_compilation.yml +++ b/detections/endpoint/csc_net_on_the_fly_compilation.yml @@ -35,13 +35,25 @@ references: tags: analytic_story: - Windows Defense Evasion Tactics + automated_detection_testing: passed + confidence: 50 + context: + - Source:Endpoint + - Stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log + impact: 50 kill_chain_phases: - Exploitation + message: csc.exe with commandline $process$ to compile .net code on $dest$ by $user$ mitre_attack_id: - T1027.004 - T1027 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -56,17 +68,5 @@ tags: - Processes.process - Processes.process_id - Processes.parent_process_id - security_domain: endpoint - impact: 50 - confidence: 50 risk_score: 25 - context: - - Source:Endpoint - - Stage:Defense Evasion - message: csc.exe with commandline $process$ to compile .net code on $dest$ by $user$ - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/curl_download_and_bash_execution.yml b/detections/endpoint/curl_download_and_bash_execution.yml new file mode 100644 index 0000000000..8c748b1dda --- /dev/null +++ b/detections/endpoint/curl_download_and_bash_execution.yml @@ -0,0 +1,82 @@ +name: Curl Download and Bash Execution +id: 900bc324-59f3-11ec-9fb4-acde48001122 +version: 1 +date: '2021-12-10' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies the use of curl on Linux or MacOS attempting + to download a file from a remote source and pipe it to bash. This is typically found + with coinminers and most recently with CVE-2021-44228, a vulnerability in Log4j. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name=curl + (Processes.process="*-s *") OR (Processes.process="*|*" AND Processes.process="*bash*") + by Processes.dest Processes.user Processes.parent_process_name Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `curl_download_and_bash_execution_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon for Linux, you will need to ensure mapping is + occurring correctly. If the EDR is not parsing the pipe bash in the command-line, + modifying the analytic will be required. Add parent process name (Processes.parent_process_name) + as needed to filter. +known_false_positives: False positives should be limited, however filtering may be + required. +references: +- https://www.huntress.com/blog/rapid-response-critical-rce-vulnerability-is-affecting-java +- https://www.lunasec.io/docs/blog/log4j-zero-day/ +- https://gist.github.com/nathanqthai/01808c569903f41a52e7e7b575caa890 +tags: + analytic_story: + - Ingress Tool Transfer + - Log4Shell CVE-2021-44228 + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + cve: + - CVE-2021-44228 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/linux-sysmon_curlwget.log + impact: 80 + kill_chain_phases: + - Exploitation + message: An instance of $process_name$ was identified on endpoint $dest$ attempting + to download a remote file and run it with bash. + mitre_attack_id: + - T1105 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 80 + security_domain: endpoint + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml index 7b38c7b154..d4993baf2c 100644 --- a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml @@ -19,7 +19,7 @@ known_false_positives: Legitimate logon activity by authorized NTLM systems may references: [] tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement asset_type: Endpoint automated_detection_testing: passed cis20: diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml index 62661201c4..0c485c472d 100644 --- a/detections/endpoint/detect_exchange_web_shell.yml +++ b/detections/endpoint/detect_exchange_web_shell.yml @@ -93,7 +93,7 @@ tags: - Filesystem.user risk_score: 81 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/detect_html_help_renamed.yml b/detections/endpoint/detect_html_help_renamed.yml index 22dce62ed2..12d0f3ca29 100644 --- a/detections/endpoint/detect_html_help_renamed.yml +++ b/detections/endpoint/detect_html_help_renamed.yml @@ -20,9 +20,8 @@ description: The following analytic identifies a renamed instance of hh.exe (HTM search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_hh` by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name - Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name - | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `detect_html_help_renamed_filter`' + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_html_help_renamed_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index 6b8b7a8286..a8f9c6fc3c 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -36,7 +36,7 @@ tags: - DHS Report TA18-074A - HAFNIUM Group - DarkSide Ransomware - - Lateral Movement + - Active Directory Lateral Movement asset_type: Endpoint automated_detection_testing: passed cis20: diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml index a79b3cdc22..0417b7d8c3 100644 --- a/detections/endpoint/detect_rclone_command_line_usage.yml +++ b/detections/endpoint/detect_rclone_command_line_usage.yml @@ -1,7 +1,7 @@ name: Detect RClone Command-Line Usage id: 32e0baea-b3f1-11eb-a2ce-acde48001122 -version: 1 -date: '2021-05-13' +version: 2 +date: '2021-11-29' author: Michael Haag, Splunk type: TTP datamodel: @@ -14,21 +14,24 @@ description: This analytic identifies commonly used command-line arguments used event, exfiltration is about to occur or has already. Isolate the endpoint and continue investigating by review file modifications and parallel processes. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*copy*", - "*mega*", "*pcloud*", "*ftp*", "*--config*", "*--progress*", "*--no-check-certificate*", + as lastTime from datamodel=Endpoint.Processes where `process_rclone` Processes.process + IN ("*copy*", "*mega*", "*pcloud*", "*ftp*", "*--config*", "*--progress*", "*--no-check-certificate*", "*--ignore-existing*", "*--auto-confirm*", "*--transfers*", "*--multi-thread-streams*") by - Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id - Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | `detect_rclone_command_line_usage_filter`' + Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_rclone_command_line_usage_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -known_false_positives: There is potential for false positives as these arguments may - be used by other applications. Filter or tune the analytic as needed. + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives should be limited as this is restricted to + the Rclone process name. Filter or tune the analytic as needed. references: - https://redcanary.com/blog/rclone-mega-extortion/ - https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html - https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ +- https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ tags: analytic_story: - DarkSide Ransomware @@ -78,8 +81,6 @@ tags: - Processes.process - Processes.process_id - Processes.parent_process_id + - Processes.original_file_name risk_score: 35 security_domain: endpoint - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml index 1d746a0217..919417998b 100644 --- a/detections/endpoint/detect_regasm_spawning_a_process.yml +++ b/detections/endpoint/detect_regasm_spawning_a_process.yml @@ -87,6 +87,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_regsvcs_spawning_a_process.yml b/detections/endpoint/detect_regsvcs_spawning_a_process.yml index 579a25f2c2..c81cfc81a6 100644 --- a/detections/endpoint/detect_regsvcs_spawning_a_process.yml +++ b/detections/endpoint/detect_regsvcs_spawning_a_process.yml @@ -86,6 +86,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_renamed_psexec.yml b/detections/endpoint/detect_renamed_psexec.yml index f3bed31e95..aae0bea823 100644 --- a/detections/endpoint/detect_renamed_psexec.yml +++ b/detections/endpoint/detect_renamed_psexec.yml @@ -33,7 +33,7 @@ tags: - DHS Report TA18-074A - HAFNIUM Group - DarkSide Ransomware - - Lateral Movement + - Active Directory Lateral Movement automated_detection_testing: passed confidence: 90 context: diff --git a/detections/endpoint/detect_sharphound_command_line_arguments.yml b/detections/endpoint/detect_sharphound_command_line_arguments.yml index d2e9777751..9e0b7d70e7 100644 --- a/detections/endpoint/detect_sharphound_command_line_arguments.yml +++ b/detections/endpoint/detect_sharphound_command_line_arguments.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_id risk_score: 24 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index 9174e9c7ef..703f0ee4ea 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -67,6 +67,6 @@ tags: - Processes.dest risk_score: 35 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_amsi_through_registry.yml b/detections/endpoint/disable_amsi_through_registry.yml index 47c411b349..302620ef30 100644 --- a/detections/endpoint/disable_amsi_through_registry.yml +++ b/detections/endpoint/disable_amsi_through_registry.yml @@ -12,10 +12,9 @@ description: this search is to identify modification in registry to disable AMSI payload with minimal alert as much as possible. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows - Script\\Settings\\AmsiEnable" Registry.registry_value_name = "DWORD (0x00000000)" - by Registry.registry_path Registry.registry_key_name Registry.registry_value_name - Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` - |`security_content_ctime(lastTime)` | `disable_amsi_through_registry_filter`' + Script\\Settings\\AmsiEnable" Registry.registry_value_data = "0x00000000" by Registry.registry_path + Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` + | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disable_amsi_through_registry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure @@ -48,6 +47,6 @@ tags: - Registry.dest - Registry.registry_value_name security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_etw_through_registry.yml b/detections/endpoint/disable_etw_through_registry.yml index 7122094fe2..6fcd28fa2d 100644 --- a/detections/endpoint/disable_etw_through_registry.yml +++ b/detections/endpoint/disable_etw_through_registry.yml @@ -12,8 +12,8 @@ description: this search is to identify modification in registry to disable ETW payload with minimal alert as much as possible. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled" - Registry.registry_value_name = "DWORD (0x00000000)" by Registry.registry_path Registry.registry_key_name - Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` + Registry.registry_value_data = "0x00000000" by Registry.registry_path Registry.registry_key_name + Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disable_etw_through_registry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from @@ -46,6 +46,6 @@ tags: - Registry.dest - Registry.registry_value_name security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_logs_using_wevtutil.yml b/detections/endpoint/disable_logs_using_wevtutil.yml index 9a157c43c9..34f0b28e17 100644 --- a/detections/endpoint/disable_logs_using_wevtutil.yml +++ b/detections/endpoint/disable_logs_using_wevtutil.yml @@ -61,6 +61,6 @@ tags: - Processes.process_guid risk_score: 24 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_registry_tool.yml b/detections/endpoint/disable_registry_tool.yml index d46b2d5663..93c3c28487 100644 --- a/detections/endpoint/disable_registry_tool.yml +++ b/detections/endpoint/disable_registry_tool.yml @@ -13,8 +13,8 @@ description: This search identifies modification of registry to disable the rege and defense evasion. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools" - Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name - Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` + Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name + Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disable_registry_tool_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from @@ -60,6 +60,6 @@ tags: - Registry.registry_value_name risk_score: 40 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_schedule_task.yml b/detections/endpoint/disable_schedule_task.yml index 6848545090..bfd54fd4f3 100644 --- a/detections/endpoint/disable_schedule_task.yml +++ b/detections/endpoint/disable_schedule_task.yml @@ -60,7 +60,7 @@ tags: - Processes.dest risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/disable_show_hidden_files.yml b/detections/endpoint/disable_show_hidden_files.yml index 7fc1e7e9ce..e9c7dfccb6 100644 --- a/detections/endpoint/disable_show_hidden_files.yml +++ b/detections/endpoint/disable_show_hidden_files.yml @@ -13,10 +13,9 @@ description: The following analytic is to identify a modification in the Windows search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt" - Registry.registry_value_name = "DWORD (0x00000001)") OR (Registry.registry_path= - "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden" - Registry.registry_value_name = "DWORD (0x00000000)") by Registry.registry_path Registry.registry_key_name - Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` + Registry.registry_value_data = "0x00000001") OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden" + Registry.registry_value_data = "0x00000000") by Registry.registry_path Registry.registry_key_name + Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disable_show_hidden_files_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from diff --git a/detections/endpoint/disable_windows_app_hotkeys.yml b/detections/endpoint/disable_windows_app_hotkeys.yml index 8c99a673a6..12750778fc 100644 --- a/detections/endpoint/disable_windows_app_hotkeys.yml +++ b/detections/endpoint/disable_windows_app_hotkeys.yml @@ -61,6 +61,6 @@ tags: - Registry.dest Registry.user risk_score: 40 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index 710a2e021a..b463e4baeb 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -18,10 +18,10 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Defender\\Real-Time Protection\\DisableRealtimeMonitoring" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIntrusionPreventionSystem" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIOAVProtection" OR Registry.registry_path= "*\\Real-Time - Protection\\DisableScriptScanning" Registry.registry_value_name = "DWORD (0x00000001)" - by Registry.registry_path Registry.registry_key_name Registry.registry_value_name - Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` - |`security_content_ctime(lastTime)` | `disable_windows_behavior_monitoring_filter`' + Protection\\DisableScriptScanning" Registry.registry_value_data = "0x00000001" by + Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest + | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` + | `disable_windows_behavior_monitoring_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure @@ -68,6 +68,6 @@ tags: - Registry.registry_value_name risk_score: 40 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_cmd_application.yml b/detections/endpoint/disabling_cmd_application.yml index 7ec6ab33a6..36a8aba4f0 100644 --- a/detections/endpoint/disabling_cmd_application.yml +++ b/detections/endpoint/disabling_cmd_application.yml @@ -12,8 +12,8 @@ description: this search is to identify modification in registry to disable cmd to traverse on directory and files. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD" - Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name - Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` + Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name + Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disabling_cmd_application_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from @@ -63,6 +63,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_controlpanel.yml b/detections/endpoint/disabling_controlpanel.yml index 28cc8b8c37..6136144cd8 100644 --- a/detections/endpoint/disabling_controlpanel.yml +++ b/detections/endpoint/disabling_controlpanel.yml @@ -11,8 +11,8 @@ description: this search is to identify registry modification to disable control persistence removed on the infected machine. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel" - Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name - Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` + Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name + Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_controlpanel_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from @@ -62,6 +62,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_folderoptions_windows_feature.yml b/detections/endpoint/disabling_folderoptions_windows_feature.yml index 120f68a170..8e10371085 100644 --- a/detections/endpoint/disabling_folderoptions_windows_feature.yml +++ b/detections/endpoint/disabling_folderoptions_windows_feature.yml @@ -13,8 +13,8 @@ description: This search is to identify registry modification to disable folder fake file extensions. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions" - Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name - Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` + Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name + Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_folderoptions_windows_feature_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from @@ -64,6 +64,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_norun_windows_app.yml b/detections/endpoint/disabling_norun_windows_app.yml index 3e74739458..99a8091abe 100644 --- a/detections/endpoint/disabling_norun_windows_app.yml +++ b/detections/endpoint/disabling_norun_windows_app.yml @@ -13,8 +13,8 @@ description: This search is to identify modification of registry to disable run known application run easily through run shortcut. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun" - Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name - Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` + Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name + Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_norun_windows_app_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from @@ -66,6 +66,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_remote_user_account_control.yml b/detections/endpoint/disabling_remote_user_account_control.yml index 18d6e60eed..d0ea85b197 100644 --- a/detections/endpoint/disabling_remote_user_account_control.yml +++ b/detections/endpoint/disabling_remote_user_account_control.yml @@ -9,8 +9,8 @@ description: The search looks for modifications to registry keys that control th enforcement of Windows User Account Control (UAC). search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path=*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA* - Registry.registry_value_name="DWORD (0x00000000)" by Registry.dest, Registry.registry_key_name - Registry.user Registry.registry_path Registry.registry_value_name Registry.action + Registry.registry_value_data="0x00000000" by Registry.dest, Registry.registry_key_name + Registry.user Registry.registry_path Registry.registry_value_data Registry.action | `drop_dm_object_name(Registry)` | `disabling_remote_user_account_control_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model diff --git a/detections/endpoint/disabling_systemrestore_in_registry.yml b/detections/endpoint/disabling_systemrestore_in_registry.yml index e1078baec0..50fd4dd24f 100644 --- a/detections/endpoint/disabling_systemrestore_in_registry.yml +++ b/detections/endpoint/disabling_systemrestore_in_registry.yml @@ -13,8 +13,8 @@ description: The following search identifies the modification of registry relate search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows - NT\\CurrentVersion\\SystemRestore\\DisableConfig" Registry.registry_value_name = - "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name + NT\\CurrentVersion\\SystemRestore\\DisableConfig" Registry.registry_value_data = + "0x00000001" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `disabling_systemrestore_in_registry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information @@ -66,6 +66,6 @@ tags: - Registry.registry_value_name risk_score: 49 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_task_manager.yml b/detections/endpoint/disabling_task_manager.yml index 145bb67c16..80f5d43f38 100644 --- a/detections/endpoint/disabling_task_manager.yml +++ b/detections/endpoint/disabling_task_manager.yml @@ -12,8 +12,8 @@ description: This search is to identifies modification of registry to disable th their process. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" - Registry.registry_value_name = "DWORD (0x00000001)" by Registry.registry_path Registry.registry_key_name - Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` + Registry.registry_value_data = "0x00000001" by Registry.registry_path Registry.registry_key_name + Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_task_manager_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from @@ -64,6 +64,6 @@ tags: - Registry.registry_value_name risk_score: 42 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/domain_account_discovery_with_net_app.yml b/detections/endpoint/domain_account_discovery_with_net_app.yml index 7ebff9754f..de64911d86 100644 --- a/detections/endpoint/domain_account_discovery_with_net_app.yml +++ b/detections/endpoint/domain_account_discovery_with_net_app.yml @@ -70,6 +70,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index 00c446e74b..bbf37808f7 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/dsquery_domain_discovery.yml b/detections/endpoint/dsquery_domain_discovery.yml index a4501bd74e..af145534f6 100644 --- a/detections/endpoint/dsquery_domain_discovery.yml +++ b/detections/endpoint/dsquery_domain_discovery.yml @@ -93,7 +93,7 @@ tags: - Processes.parent_process_id risk_score: 72 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/dump_lsass_via_procdump.yml b/detections/endpoint/dump_lsass_via_procdump.yml index b5a487bac6..64fd57e696 100644 --- a/detections/endpoint/dump_lsass_via_procdump.yml +++ b/detections/endpoint/dump_lsass_via_procdump.yml @@ -89,7 +89,7 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/enable_rdp_in_other_port_number.yml b/detections/endpoint/enable_rdp_in_other_port_number.yml index f052b8a46f..5793ae1027 100644 --- a/detections/endpoint/enable_rdp_in_other_port_number.yml +++ b/detections/endpoint/enable_rdp_in_other_port_number.yml @@ -13,7 +13,7 @@ description: This search is to detect a modification to registry to enable rdp t search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal - Server\\WinStations\\RDP-Tcp*" Registry.registry_key_name = "PortNumber" by Registry.dest + Server\\WinStations\\RDP-Tcp*" Registry.registry_value_name = "PortNumber" by Registry.dest Registry.user Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `enable_rdp_in_other_port_number_filter`' how_to_implement: To successfully implement this search, you need to be ingesting @@ -60,6 +60,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/eventvwr_uac_bypass.yml b/detections/endpoint/eventvwr_uac_bypass.yml index 7b5152224c..9a4726888b 100644 --- a/detections/endpoint/eventvwr_uac_bypass.yml +++ b/detections/endpoint/eventvwr_uac_bypass.yml @@ -68,6 +68,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/excessive_attempt_to_disable_services.yml b/detections/endpoint/excessive_attempt_to_disable_services.yml index 55c5cbf810..58f9ca8413 100644 --- a/detections/endpoint/excessive_attempt_to_disable_services.yml +++ b/detections/endpoint/excessive_attempt_to_disable_services.yml @@ -64,7 +64,7 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml b/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml index 9035ec59de..19c9759a67 100644 --- a/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml +++ b/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml @@ -58,7 +58,7 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml index 9b0632b21e..f197a4fa92 100644 --- a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml +++ b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml @@ -73,6 +73,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/excessive_number_of_taskhost_processes.yml b/detections/endpoint/excessive_number_of_taskhost_processes.yml index ee6836d2d4..cc24ef4511 100644 --- a/detections/endpoint/excessive_number_of_taskhost_processes.yml +++ b/detections/endpoint/excessive_number_of_taskhost_processes.yml @@ -67,7 +67,7 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/excessive_usage_of_cacls_app.yml b/detections/endpoint/excessive_usage_of_cacls_app.yml index 3ad750937d..5b6ba5c553 100644 --- a/detections/endpoint/excessive_usage_of_cacls_app.yml +++ b/detections/endpoint/excessive_usage_of_cacls_app.yml @@ -64,7 +64,7 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/excessive_usage_of_taskkill.yml b/detections/endpoint/excessive_usage_of_taskkill.yml index ce6646f241..7bda8bf2b0 100644 --- a/detections/endpoint/excessive_usage_of_taskkill.yml +++ b/detections/endpoint/excessive_usage_of_taskkill.yml @@ -68,7 +68,7 @@ tags: - Processes.process_id risk_score: 28 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml index cea14e9c2d..d4cdc813b6 100644 --- a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml +++ b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml @@ -8,7 +8,7 @@ datamodel: - Endpoint description: The following analytic identifies executable files (.exe or .dll) being written to Windows administrative SMB shares (Admin$, IPC$, C$). This represents - suspicious behavior as its commonly user by tools like like PsExec/PaExec and others + suspicious behavior as its commonly used by tools like like PsExec/PaExec and others to stage service binaries before creating and starting a Windows service on remote endpoints. Red Teams and adversaries alike may abuse administrative shares for lateral movement and remote code execution. The Trickbot malware family also implements @@ -31,7 +31,7 @@ references: - https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement - Trickbot automated_detection_testing: passed confidence: 100 diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index 5c21d00cdb..4500a5bb6c 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -76,7 +76,7 @@ tags: - Filesystem.user risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml index 035aa05ecb..56a7ab51ab 100644 --- a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml +++ b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml @@ -74,6 +74,6 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index cf895798c4..b20a051979 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -74,7 +74,7 @@ tags: - Processes.parent_process risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml index 530082af39..e07ae71118 100644 --- a/detections/endpoint/file_with_samsam_extension.yml +++ b/detections/endpoint/file_with_samsam_extension.yml @@ -69,7 +69,7 @@ tags: - Filesystem.file_name risk_score: 90 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/firewall_allowed_program_enable.yml b/detections/endpoint/firewall_allowed_program_enable.yml index 907cd62dc3..58760edba9 100644 --- a/detections/endpoint/firewall_allowed_program_enable.yml +++ b/detections/endpoint/firewall_allowed_program_enable.yml @@ -31,13 +31,26 @@ references: tags: analytic_story: - Windows Defense Evasion Tactics + automated_detection_testing: passed + confidence: 50 + context: + - Source:Endpoint + - Stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log + impact: 50 kill_chain_phases: - Reconnaissance + message: firewall allowed program commandline $process$ of $process_name$ on $dest$ + by $user$ mitre_attack_id: - T1562.004 - T1562 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -52,21 +65,8 @@ tags: - Processes.process - Processes.process_id - Processes.parent_process_id - security_domain: endpoint - impact: 50 - confidence: 50 risk_score: 25 - context: - - Source:Endpoint - - Stage:Defense Evasion - message: firewall allowed program commandline $process$ of $process_name$ on $dest$ - by $user$ - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed - CIM_version: 4.20.2 + security_domain: endpoint + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/fodhelper_uac_bypass.yml b/detections/endpoint/fodhelper_uac_bypass.yml index 83fa82db93..7b4e5303bf 100644 --- a/detections/endpoint/fodhelper_uac_bypass.yml +++ b/detections/endpoint/fodhelper_uac_bypass.yml @@ -86,6 +86,6 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/fsutil_zeroing_file.yml b/detections/endpoint/fsutil_zeroing_file.yml index 286a681650..a1870be40e 100644 --- a/detections/endpoint/fsutil_zeroing_file.yml +++ b/detections/endpoint/fsutil_zeroing_file.yml @@ -57,6 +57,6 @@ tags: - Processes.parent_process risk_score: 54 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml index e820d5fd23..fe0a8167ce 100644 --- a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml +++ b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/get_domainpolicy_with_powershell.yml b/detections/endpoint/get_domainpolicy_with_powershell.yml index 82927d2691..38d3d42baa 100644 --- a/detections/endpoint/get_domainpolicy_with_powershell.yml +++ b/detections/endpoint/get_domainpolicy_with_powershell.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_name risk_score: 30 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml index 0c30eebf20..55214d9ee5 100644 --- a/detections/endpoint/get_domainuser_with_powershell.yml +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml index 4f23fcd739..bb07d66e57 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -73,6 +73,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/hide_user_account_from_sign_in_screen.yml b/detections/endpoint/hide_user_account_from_sign_in_screen.yml index d697eb4b7c..f23e24a339 100644 --- a/detections/endpoint/hide_user_account_from_sign_in_screen.yml +++ b/detections/endpoint/hide_user_account_from_sign_in_screen.yml @@ -14,10 +14,9 @@ description: This analytic identifies a suspicious registry modification to hide search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows - NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" AND Registry.registry_value_name - = "DWORD (0x00000000)" by Registry.dest Registry.user Registry.registry_value_name - | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` - | `hide_user_account_from_sign_in_screen_filter`' + NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" AND Registry.registry_value_data + = "0x00000000" by Registry.dest Registry.user Registry.registry_value_data | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `hide_user_account_from_sign_in_screen_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response @@ -71,6 +70,6 @@ tags: - Registry.dest Registry.user risk_score: 72 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index 4858103347..6adfa9e437 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -74,7 +74,7 @@ tags: - Processes.dest risk_score: 72 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows diff --git a/detections/endpoint/high_frequency_copy_of_files_in_network_share.yml b/detections/endpoint/high_frequency_copy_of_files_in_network_share.yml index 34b767180b..6b7b613d2b 100644 --- a/detections/endpoint/high_frequency_copy_of_files_in_network_share.yml +++ b/detections/endpoint/high_frequency_copy_of_files_in_network_share.yml @@ -32,12 +32,25 @@ references: tags: analytic_story: - Information Sabotage + automated_detection_testing: passed + confidence: 30 + context: + - Source:Endpoint + - Stage:Exfiltration dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1537/high_copy_files_in_net_share/security.log + impact: 30 kill_chain_phases: - Exfiltration + message: high frequency copy of document in network share $Share_Name$ from $Source_Address$ + by $user$ mitre_attack_id: - T1537 + observable: + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -52,18 +65,5 @@ tags: - user - src_port - Source_Address - security_domain: endpoint - impact: 30 - confidence: 30 risk_score: 9 - context: - - Source:Endpoint - - Stage:Exfiltration - message: high frequency copy of document in network share $Share_Name$ from $Source_Address$ - by $user$ - observable: - - name: user - type: User - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/hunting_for_log4shell.yml b/detections/endpoint/hunting_for_log4shell.yml new file mode 100644 index 0000000000..1804251922 --- /dev/null +++ b/detections/endpoint/hunting_for_log4shell.yml @@ -0,0 +1,118 @@ +name: Hunting for Log4Shell +id: 158b68fa-5d1a-11ec-aac8-acde48001122 +version: 1 +date: '2021-12-14' +author: Michael Haag, Splunk +type: Hunting +datamodel: +- Web +description: 'The following hunting query assists with quickly assessing CVE-2021-44228, + or Log4Shell, activity mapped to the Web Datamodel. This is a combination query + attempting to identify, score and dashboard. Because the Log4Shell vulnerability + requires the string to be in the logs, this will work to identify the activity anywhere + in the HTTP headers using _raw. Modify the first line to use the same pattern matching + against other log sources. Scoring is based on a simple rubric of 0-5. 5 being the + best match, and less than 5 meant to identify additional patterns that will equate + to a higher total score. \ + + The first jndi match identifies the standard pattern of `{jndi:` \ + + jndi_fastmatch is meant to identify any jndi in the logs. The score is set low and + is meant to be the "base" score used later. \ + + jndi_proto is a protocol match that identifies `jndi` and one of `ldap, ldaps, rmi, + dns, nis, iiop, corba, nds, http, https.` \ + + all_match is a very well written regex by https://gist.github.com/Schvenn that identifies + nearly all patterns of this attack behavior. \ + + env works to identify environment variables in the header, meant to capture `AWS_ACCESS_KEY_ID`, + `AWS_SECRET_ACCESS_KEY` and `env`. \ + + uri_detect is string match looking for the common uri paths currently being scanned/abused + in the wild. \ + + keywords matches on enumerated values that, like `$ctx:loginId`, that may be found + in the header used by the adversary. \ + + lookup matching is meant to catch some basic obfuscation that has been identified + using upper, lower and date. \ + + Scoring will then occur based on any findings. The base score is meant to be 2 , + created by jndi_fastmatch. Everything else is meant to increase that score. \ + + Finally, a simple table is created to show the scoring and the _raw field. Sort + based on score or columns of interest.' +search: '| from datamodel Web.Web | eval jndi=if(match(_raw, "(\{|%7B)[jJnNdDiI]{4}:"),4,0) + | eval jndi_fastmatch=if(match(_raw, "[jJnNdDiI]{4}"),2,0) | eval jndi_proto=if(match(_raw,"(?i)jndi:(ldap[s]?|rmi|dns|nis|iiop|corba|nds|http|https):"),5,0) + | eval all_match = if(match(_raw, "(?i)(%(25){0,}20|\s)*(%(25){0,}24|\$)(%(25){0,}20|\s)*(%(25){0,}7B|{)(%(25){0,}20|\s)*(%(25){0,}(6A|4A)|J)(%(25){0,}(6E|4E)|N)(%(25){0,}(64|44)|D)(%(25){0,}(69|49)|I)(%(25){0,}20|\s)*(%(25){0,}3A|:)[\w\%]+(%(25){1,}3A|:)(%(25){1,}2F|\/)[^\n]+"),5,0) + | eval env_var = if(match(_raw, "env:") OR match(_raw, "env:AWS_ACCESS_KEY_ID") + OR match(_raw, "env:AWS_SECRET_ACCESS_KEY"),5,0) | eval uridetect = if(match(_raw, + "(?i)Basic\/Command\/Base64|Basic\/ReverseShell|Basic\/TomcatMemshell|Basic\/JBossMemshell|Basic\/WebsphereMemshell|Basic\/SpringMemshell|Basic\/Command|Deserialization\/CommonsCollectionsK|Deserialization\/CommonsBeanutils|Deserialization\/Jre8u20\/TomcatMemshell|Deserialization\/CVE_2020_2555\/WeblogicMemshell|TomcatBypass|GroovyBypass|WebsphereBypass"),4,0) + | eval keywords = if(match(_raw,"(?i)\$\{ctx\:loginId\}|\$\{map\:type\}|\$\{filename\}|\$\{date\:MM-dd-yyyy\}|\$\{docker\:containerId\}|\$\{docker\:containerName\}|\$\{docker\:imageName\}|\$\{env\:USER\}|\$\{event\:Marker\}|\$\{mdc\:UserId\}|\$\{java\:runtime\}|\$\{java\:vm\}|\$\{java\:os\}|\$\{jndi\:logging/context-name\}|\$\{hostName\}|\$\{docker\:containerId\}|\$\{k8s\:accountName\}|\$\{k8s\:clusterName\}|\$\{k8s\:containerId\}|\$\{k8s\:containerName\}|\$\{k8s\:host\}|\$\{k8s\:labels.app\}|\$\{k8s\:labels.podTemplateHash\}|\$\{k8s\:masterUrl\}|\$\{k8s\:namespaceId\}|\$\{k8s\:namespaceName\}|\$\{k8s\:podId\}|\$\{k8s\:podIp\}|\$\{k8s\:podName\}|\$\{k8s\:imageId\}|\$\{k8s\:imageName\}|\$\{log4j\:configLocation\}|\$\{log4j\:configParentLocation\}|\$\{spring\:spring.application.name\}|\$\{main\:myString\}|\$\{main\:0\}|\$\{main\:1\}|\$\{main\:2\}|\$\{main\:3\}|\$\{main\:4\}|\$\{main\:bar\}|\$\{name\}|\$\{marker\}|\$\{marker\:name\}|\$\{spring\:profiles.active[0]|\$\{sys\:logPath\}|\$\{web\:rootDir\}|\$\{sys\:user.name\}"),4,0) + | eval obf = if(match(_raw, "(\$|%24)[^ /]*({|%7b)[^ /]*(j|%6a)[^ /]*(n|%6e)[^ /]*(d|%64)[^ + /]*(i|%69)[^ /]*(:|%3a)[^ /]*(:|%3a)[^ /]*(/|%2f)"),5,0) | eval lookups = if(match(_raw, + "date:") OR match(_raw, "upper:") OR match(_raw, "lower:"),4,0) | addtotals fieldname=Score, + jndi, jndi_proto, env_var, uridetect, all_match, jndi_fastmatch, keywords, obf, + lookups | where Score > 2 | stats values(Score) by jndi, jndi_proto, env_var, uridetect, + all_match, jndi_fastmatch, keywords, lookups, obf, _raw | `hunting_for_log4shell_filter`' +how_to_implement: Out of the box, the Web datamodel is required to be pre-filled. + However, tested was performed against raw httpd access logs. Change the first line + to any dataset to pass the regex's against. +known_false_positives: It is highly possible you will find false positives, however, + the base score is set to 2 for _any_ jndi found in raw logs. tune and change as + needed, include any filtering. +references: +- https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72 +- https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b#gistcomment-3994449 +- https://regex101.com/r/OSrm0q/1/ +- https://github.com/Neo23x0/signature-base/blob/master/yara/expl_log4j_cve_2021_44228.yar +- https://news.sophos.com/en-us/2021/12/12/log4shell-hell-anatomy-of-an-exploit-outbreak/ +- https://gist.github.com/MHaggis/1899b8554f38c8692a9fb0ceba60b44c +- https://twitter.com/sasi2103/status/1469764719850442760?s=20 +tags: + analytic_story: + - Log4Shell CVE-2021-44228 + asset_type: Web Server + automated_detection_testing: passed + confidence: 50 + context: + - Source:network + cve: + - CVE-2021-44228 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/java/log4shell-nginx.log + impact: 80 + kill_chain_phases: + - Exploitation + message: Hunting for Log4Shell exploitation has occurred. + mitre_attack_id: + - T1190 + observable: + - name: dest + type: Hostname + role: + - Victim + - name: http_method + type: Other + role: + - other + - name: src + type: Other + role: + - other + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Web.http_method + - Web.url + - Web.url_length + - Web.src + - Web.dest + - Web.http_user_agent + - _raw + risk_score: 40 + security_domain: network diff --git a/detections/endpoint/icacls_deny_command.yml b/detections/endpoint/icacls_deny_command.yml index e93ceb4a9c..b3455a9b2a 100644 --- a/detections/endpoint/icacls_deny_command.yml +++ b/detections/endpoint/icacls_deny_command.yml @@ -65,7 +65,7 @@ tags: - Processes.process risk_score: 72 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/icacls_grant_command.yml b/detections/endpoint/icacls_grant_command.yml index c7c7162b89..9b8c725594 100644 --- a/detections/endpoint/icacls_grant_command.yml +++ b/detections/endpoint/icacls_grant_command.yml @@ -65,7 +65,7 @@ tags: - Processes.process risk_score: 49 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml new file mode 100644 index 0000000000..d2c6c8d24a --- /dev/null +++ b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml @@ -0,0 +1,81 @@ +name: Impacket Lateral Movement Commandline Parameters +id: 8ce07472-496f-11ec-ab3b-3e22fbd008af +version: 1 +date: '2021-11-19' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic looks for the presence of suspicious commandline parameters + typically present when using Impacket tools. Impacket is a collection of python + classes meant to be used with Microsoft network protocols. There are multiple scripts + that leverage impacket libraries like `wmiexec.py`, `smbexec.py`, `dcomexec.py` + and `atexec.py` used to execute commands on remote endpoints. By default, these + scripts leverage administrative shares and hardcoded parameters that can be used + as a signature to detect its use. Red Teams and adversaries alike may leverage Impackets + tools for lateral movement and remote code execution. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.process = "*/c* \\\\127.0.0.1\\*" + OR Processes.process= "*/c* 2>&1") by Processes.dest Processes.user Processes.parent_process_name + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` + | `impacket_lateral_movement_commandline_parameters_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. +known_false_positives: Although uncommon, Administrators may leverage Impackets tools + to start a process on remote systems for system administration or automation use + cases. +references: +- https://attack.mitre.org/techniques/T1021/002/ +- https://attack.mitre.org/techniques/T1021/003/ +- https://attack.mitre.org/techniques/T1047/ +- https://attack.mitre.org/techniques/T1053/ +- https://attack.mitre.org/techniques/T1053/005 +- https://github.com/SecureAuthCorp/impacket +- https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/ +tags: + analytic_story: + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 70 + context: + - Source:Endpoint + - Stage:Lateral Movement + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/impacket/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Lateral Movement + message: Suspicious command line parameters on $dest may represent a lateral movement + attack with Impackets tools + mitre_attack_id: + - T1021 + - T1021.002 + - T1021.003 + - T1047 + - T1543.003 + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 63 + security_domain: endpoint diff --git a/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml b/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml index 58d8c2ef3c..3f8090e1e6 100644 --- a/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml +++ b/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml @@ -7,30 +7,43 @@ type: TTP datamodel: - Endpoint description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - to identify the usage of the `Enter-PSSession`. This commandlet can be used to open - an interactive session on a remote endpoint leveraging the WinRM protocol. - Red Teams and adversaries alike may abuse WinRM and `Enter-PSSession` for lateral movement and remote code execution. -search: 'powershell` EventCode=4104 (Message="*Enter-PSSession*" AND Message="*-ComputerName*") + to identify the usage of the `Enter-PSSession`. This commandlet can be used to open + an interactive session on a remote endpoint leveraging the WinRM protocol. Red Teams + and adversaries alike may abuse WinRM and `Enter-PSSession` for lateral movement + and remote code execution. +search: powershell` EventCode=4104 (Message="*Enter-PSSession*" AND Message="*-ComputerName*") | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message - ComputerName User | `security_content_ctime(firstTime)` | `interactive_session_on_remote_endpoint_with_powershell_filter`' + ComputerName User | `security_content_ctime(firstTime)` | `interactive_session_on_remote_endpoint_with_powershell_filter` how_to_implement: To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup instructions can be found https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. -known_false_positives: Administrators may leverage WinRM and `Enter-PSSession` for administrative and troubleshooting tasks. - This activity is usually limited to a small set of hosts or users. In certain environments, tuning may not be possible. +known_false_positives: Administrators may leverage WinRM and `Enter-PSSession` for + administrative and troubleshooting tasks. This activity is usually limited to a + small set of hosts or users. In certain environments, tuning may not be possible. references: - https://attack.mitre.org/techniques/T1021/006/ - https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/enter-pssession?view=powershell-7.2 tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + confidence: 50 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_pssession/windows-powershell.log + impact: 90 kill_chain_phases: - Lateral Movement + message: An interactive session was opened on a remote endpoint from $ComputerName mitre_attack_id: - T1021 - T1021.006 + observable: + - name: ComputerName + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -41,16 +54,5 @@ tags: - Message - ComputerName - User - security_domain: endpoint - impact: 90 - confidence: 50 risk_score: 45 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: An interactive session was opened on a remote endpoint from $ComputerName - observable: - - name: ComputerName - type: Endpoint - role: - - Victim \ No newline at end of file + security_domain: endpoint diff --git a/detections/endpoint/investigate_successful_remote_desktop_authentications.yml b/detections/endpoint/investigate_successful_remote_desktop_authentications.yml index adb4eb9517..0ef0b02006 100644 --- a/detections/endpoint/investigate_successful_remote_desktop_authentications.yml +++ b/detections/endpoint/investigate_successful_remote_desktop_authentications.yml @@ -23,7 +23,7 @@ references: [] tags: analytic_story: - Hidden Cobra Malware - - Lateral Movement + - Active Directory Lateral Movement - SamSam Ransomware product: - Splunk Phantom diff --git a/detections/endpoint/java_class_file_download_by_java_user_agent.yml b/detections/endpoint/java_class_file_download_by_java_user_agent.yml new file mode 100644 index 0000000000..3af444ccda --- /dev/null +++ b/detections/endpoint/java_class_file_download_by_java_user_agent.yml @@ -0,0 +1,79 @@ +name: Java Class File download by Java User Agent +id: 8281ce42-5c50-11ec-82d2-acde48001122 +version: 1 +date: '2021-12-13' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Web +description: The following analytic identifies a Java user agent performing a GET + request for a .class file from the remote site. This is potentially indicative of + exploitation of the Java application and may be related to current event CVE-2021-44228 + (Log4Shell). +search: '| tstats count from datamodel=Web where Web.http_user_agent="*Java*" Web.http_method="GET" + Web.url="*.class*" by Web.http_user_agent Web.http_method, Web.url,Web.url_length + Web.src, Web.dest | `drop_dm_object_name("Web")` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `java_class_file_download_by_java_user_agent_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + web or proxy logs, or ensure it is being filled by a proxy like device, into the + Web Datamodel. For additional filtering, allow list private IP space or restrict + by known good. +known_false_positives: Filtering may be required in some instances, filter as needed. +references: +- https://arstechnica.com/information-technology/2021/12/as-log4shell-wreaks-havoc-payroll-service-reports-ransomware-attack/ +tags: + analytic_story: + - Log4Shell CVE-2021-44228 + asset_type: Web Server + automated_detection_testing: passed + confidence: 50 + context: + - Source:network + cve: + - CVE-2021-44228 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/java/java.log + impact: 80 + kill_chain_phases: + - Exploitation + message: A Java user agent $http_user_agent$ was performing a $http_method$ to retrieve + a remote class file. + mitre_attack_id: + - T1190 + observable: + - name: dest + type: Hostname + role: + - Victim + - name: http_user_agent + type: Other + role: + - other + - name: http_method + type: Other + role: + - Other + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Web.http_method + - Web.url + - Web.url_length + - Web.src + - Web.dest + - Web.http_user_agent + risk_score: 40 + security_domain: network + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nginx + - Splunk_TA_microsoft-iis + - Splunk_TA_websense-cg + - Splunk_TA_squid + - Splunk_TA_haproxy + - Splunk_TA_mcafee-wg + - Splunk_TA_cisco-wsa diff --git a/detections/endpoint/jscript_execution_using_cscript_app.yml b/detections/endpoint/jscript_execution_using_cscript_app.yml index 8b5e7a416f..dc3b4a6983 100644 --- a/detections/endpoint/jscript_execution_using_cscript_app.yml +++ b/detections/endpoint/jscript_execution_using_cscript_app.yml @@ -29,6 +29,7 @@ references: tags: analytic_story: - FIN7 + - Remcos automated_detection_testing: passed confidence: 70 context: @@ -68,6 +69,6 @@ tags: - Processes.user risk_score: 49 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/loading_of_dynwrapx_module.yml b/detections/endpoint/loading_of_dynwrapx_module.yml index 0424a4d064..5bcc54809b 100644 --- a/detections/endpoint/loading_of_dynwrapx_module.yml +++ b/detections/endpoint/loading_of_dynwrapx_module.yml @@ -36,13 +36,25 @@ references: tags: analytic_story: - Remcos + automated_detection_testing: passed + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_dynwrapx/sysmon_dynwraper.log + impact: 80 kill_chain_phases: - Exploitation + message: dynwrapx.dll loaded by process $process_name$ on $Computer$ mitre_attack_id: - T1055 - T1055.001 + observable: + - name: Computer + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -58,17 +70,5 @@ tags: - EventCode - Signed - ProcessId - security_domain: endpoint - impact: 80 - confidence: 100 risk_score: 80 - context: - - Source:Endpoint - - Stage:Defense Evasion - message: dynwrapx.dll loaded by process $process_name$ on $Computer$ - observable: - - name: Computer - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/logon_script_event_trigger_execution.yml b/detections/endpoint/logon_script_event_trigger_execution.yml index cf278ff252..06a4dcd38e 100644 --- a/detections/endpoint/logon_script_event_trigger_execution.yml +++ b/detections/endpoint/logon_script_event_trigger_execution.yml @@ -64,6 +64,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml b/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml index 85b83513f3..a820995c29 100644 --- a/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml +++ b/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml @@ -33,11 +33,13 @@ references: - https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1059.001_PowerShell/OutPowerShellCommandLineParameter.ps1 - https://ss64.com/ps/powershell.html - https://twitter.com/M_haggis/status/1440758396534214658?s=20 +- https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/ tags: analytic_story: - Malicious PowerShell - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns - HAFNIUM Group + - Log4Shell CVE-2021-44228 asset_type: Endpoint automated_detection_testing: passed cis20: @@ -49,6 +51,8 @@ tags: - Source:Endpoint - Stage:Execution - Stage:Command And Control + cve: + - CVE-2021-44228 dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/hidden_powershell/windows-sysmon.log impact: 90 diff --git a/detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml new file mode 100644 index 0000000000..b49f8879df --- /dev/null +++ b/detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml @@ -0,0 +1,81 @@ +name: Mmc LOLBAS Execution Process Spawn +id: f6601940-4c74-11ec-b9b7-3e22fbd008af +version: 1 +date: '2021-11-23' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies `mmc.exe` spawning a LOLBAS execution + process. When adversaries execute code on remote endpoints abusing the DCOM protocol + and the MMC20 COM object, the executed command is spawned as a child processs of + `mmc.exe`. The LOLBAS project documents Windows native binaries that can be abused + by threat actors to perform tasks like executing malicious code. Looking for child + processes of mmc.exe that are part of the LOLBAS project can help defenders identify + lateral movement activity. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=mmc.exe) + (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", + "Rasautou.exe", "Schtasks.exe", "Xwizard.exe", "Dllhost.exe", "Pnputil.exe", "Atbroker.exe", + "Pcwrun.exe", "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe", "Certoc.exe", "Ieexec.exe", + "Microsoft.Workflow.Compiler.exe", "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe", + "Register-cimprovider.exe", "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe", + "SettingSyncHost.exe", "Cmstp.exe", "Mmc.exe", "Stordiag.exe", "Scriptrunner.exe", + "Odbcconf.exe", "Extexport.exe", "Msdt.exe", "WorkFolders.exe", "Diskshadow.exe", + "Mavinject.exe", "Regasm.exe", "Gpscript.exe", "Rundll32.exe", "Regsvr32.exe", "Msiexec.exe", + "Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", "Runonce.exe", "Syncappvpublishingserver.exe", + "Verclsid.exe", "Infdefaultinstall.exe", "Explorer.exe", "Installutil.exe", "Netsh.exe", + "Wab.exe", "Dnscmd.exe", "At.exe", "Pcalua.exe", "Msconfig.exe")) by Processes.dest + Processes.user Processes.parent_process Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `mmc_lolbas_execution_process_spawn_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. +known_false_positives: Legitimate applications may trigger this behavior, filter as + needed. +references: +- https://attack.mitre.org/techniques/T1021/003/ +- https://www.cybereason.com/blog/dcom-lateral-movement-techniques +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/lateral_movement_lolbas/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Privilege Escalation + message: Mmc.exe spawned a LOLBAS process on $dest + mitre_attack_id: + - T1021 + - T1021.003 + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 54 + security_domain: endpoint diff --git a/detections/endpoint/modify_acl_permission_to_files_or_folder.yml b/detections/endpoint/modify_acl_permission_to_files_or_folder.yml index f64bd1247a..e137540de9 100644 --- a/detections/endpoint/modify_acl_permission_to_files_or_folder.yml +++ b/detections/endpoint/modify_acl_permission_to_files_or_folder.yml @@ -62,7 +62,7 @@ tags: - Processes.process_id risk_score: 32 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/msmpeng_application_dll_side_loading.yml b/detections/endpoint/msmpeng_application_dll_side_loading.yml index 08485a7c0b..e8f0cffc91 100644 --- a/detections/endpoint/msmpeng_application_dll_side_loading.yml +++ b/detections/endpoint/msmpeng_application_dll_side_loading.yml @@ -47,7 +47,7 @@ tags: - Filesystem.user - Filesystem.file_path security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/net_localgroup_discovery.yml b/detections/endpoint/net_localgroup_discovery.yml index be87f8b84f..ea47f2e0e7 100644 --- a/detections/endpoint/net_localgroup_discovery.yml +++ b/detections/endpoint/net_localgroup_discovery.yml @@ -28,6 +28,7 @@ references: tags: analytic_story: - Active Directory Discovery + - Windows Discovery Techniques automated_detection_testing: passed confidence: 50 context: diff --git a/detections/endpoint/net_profiler_uac_bypass.yml b/detections/endpoint/net_profiler_uac_bypass.yml index 2f135b26cc..e8ff97bed0 100644 --- a/detections/endpoint/net_profiler_uac_bypass.yml +++ b/detections/endpoint/net_profiler_uac_bypass.yml @@ -62,6 +62,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/network_discovery_using_route_windows_app.yml b/detections/endpoint/network_discovery_using_route_windows_app.yml index 94a9e73975..444db4a4f3 100644 --- a/detections/endpoint/network_discovery_using_route_windows_app.yml +++ b/detections/endpoint/network_discovery_using_route_windows_app.yml @@ -28,13 +28,26 @@ references: tags: analytic_story: - Active Directory Discovery + automated_detection_testing: passed + confidence: 30 + context: + - Source:Endpoint + - Stage:Discovery + - Stage:Recon dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log + impact: 30 kill_chain_phases: - Reconnaissance + message: Network Connection discovery on $dest$ by $user$ mitre_attack_id: - T1016 - T1016.001 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -49,18 +62,5 @@ tags: - Processes.process - Processes.process_id - Processes.parent_process_id - security_domain: endpoint - impact: 30 - confidence: 30 risk_score: 9 - context: - - Source:Endpoint - - Stage:Discovery - - Stage:Recon - message: Network Connection discovery on $dest$ by $user$ - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/nltest_domain_trust_discovery.yml b/detections/endpoint/nltest_domain_trust_discovery.yml index 6c8759a4c8..97e810bb0f 100644 --- a/detections/endpoint/nltest_domain_trust_discovery.yml +++ b/detections/endpoint/nltest_domain_trust_discovery.yml @@ -75,6 +75,6 @@ tags: - Processes.parent_process_id risk_score: 15 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml index a6855f1329..3306d0a93d 100644 --- a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml +++ b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml @@ -28,6 +28,7 @@ references: [] tags: analytic_story: - FIN7 + - Remcos automated_detection_testing: passed confidence: 70 context: diff --git a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml index 2b169b61ad..a0ab4f8f17 100644 --- a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml +++ b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml @@ -28,6 +28,7 @@ references: [] tags: analytic_story: - FIN7 + - Remcos automated_detection_testing: passed confidence: 70 context: diff --git a/detections/endpoint/ntdsutil_export_ntds.yml b/detections/endpoint/ntdsutil_export_ntds.yml index 17b11c6400..c60ffba0e9 100644 --- a/detections/endpoint/ntdsutil_export_ntds.yml +++ b/detections/endpoint/ntdsutil_export_ntds.yml @@ -78,6 +78,6 @@ tags: - Processes.parent_process_id risk_score: 50 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/office_application_spawn_rundll32_process.yml b/detections/endpoint/office_application_spawn_rundll32_process.yml index 68ca92df2d..c2d07499f1 100644 --- a/detections/endpoint/office_application_spawn_rundll32_process.yml +++ b/detections/endpoint/office_application_spawn_rundll32_process.yml @@ -10,12 +10,12 @@ description: this detection was designed to identifies suspicious spawned proces of known MS office application due to macro or malicious code. this technique can be seen in so many malware like trickbot that used MS office as its weapon or attack vector to initially infect the machines. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where (Processes.parent_process_name = "winword.exe" OR Processes.parent_process_name = "excel.exe" OR Processes.parent_process_name = "powerpnt.exe") AND `process_rundll32` - by Processes.parent_process Processes.process_name Processes.process_id Processes.process_guid Processes.process Processes.user Processes.dest - | `drop_dm_object_name("Processes")` - | `security_content_ctime(firstTime)` - |`security_content_ctime(lastTime)` +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name + = "winword.exe" OR Processes.parent_process_name = "excel.exe" OR Processes.parent_process_name + = "powerpnt.exe") AND `process_rundll32` by Processes.parent_process Processes.process_name + Processes.process_id Processes.process_guid Processes.process Processes.user Processes.dest + | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `office_application_spawn_rundll32_process_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from diff --git a/detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml b/detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml new file mode 100644 index 0000000000..422529e4f5 --- /dev/null +++ b/detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml @@ -0,0 +1,64 @@ +name: Outbound Network Connection from Java Using Default Ports +id: d2c14d28-5c47-11ec-9892-acde48001122 +version: 1 +date: '2021-12-13' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: A required step while exploiting the CVE-2021-44228-Log4j vulnerability + is that the victim server will perform outbound connections to attacker-controlled + infrastructure. This is required as part of the JNDI lookup as well as for retrieving + the second stage .class payload. The following analytic identifies the Java process + reaching out to default ports used by the LDAP and RMI protocols. This behavior + could represent successfull exploitation. Note that adversaries can easily decide + to use arbitrary ports for these protocols and potentially bypass this detection. +search: ' `sysmon` EventCode=3 (process_name=java OR process_name=java.exe) (DestinationPort=389 + OR DestinationPort=1389 OR DestinationPort = 1099 ) | rename Computer as dest | stats + count min(_time) as firstTime max(_time) as lastTime by dest, process_name, DestinationPort + | `security_content_ctime(firstTime)` | `outbound_network_connection_from_java_using_default_ports_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: Legitimate Java applications may use perform outbound connections + to these ports. Filter as needed +references: +- https://www.lunasec.io/docs/blog/log4j-zero-day/ +- https://www.govcert.admin.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/ +tags: + analytic_story: + - Log4Shell CVE-2021-44228 + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Execution + cve: + - CVE-2021-44228 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_java/linux-sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: Java performed outbound connections to default ports of LDAP or RMI on + $dest$ + mitre_attack_id: + - T1190 + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - process_name + - EventID + - CommandLine + - Computer + - DestinationPort + - DestinationIp + risk_score: 54 + security_domain: endpoint diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index e495daff75..ac58c00a8f 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -69,7 +69,7 @@ tags: - Filesystem.dest risk_score: 72 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_ossec diff --git a/detections/endpoint/permission_modification_using_takeown_app.yml b/detections/endpoint/permission_modification_using_takeown_app.yml index 603c2571b7..fe3cfd7855 100644 --- a/detections/endpoint/permission_modification_using_takeown_app.yml +++ b/detections/endpoint/permission_modification_using_takeown_app.yml @@ -65,6 +65,6 @@ tags: - Processes.process_guid risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/possible_browser_pass_view_parameter.yml b/detections/endpoint/possible_browser_pass_view_parameter.yml new file mode 100644 index 0000000000..64116e3eaf --- /dev/null +++ b/detections/endpoint/possible_browser_pass_view_parameter.yml @@ -0,0 +1,80 @@ +name: Possible Browser Pass View Parameter +id: 8ba484e8-4b97-11ec-b19a-acde48001122 +version: 1 +date: '2021-11-22' +author: Teoderick Contreras, Splunk +type: Hunting +datamodel: +- Endpoint +description: This analytic will detect a suspicious process contains a commandline + parameter related to web browser credential dumper. This technique was used by Remcos + RAT malware where it use the techique of Nirsoft webbrowserpassview.exe application + to dump web browser credentials. Remcos use the "/stext" commandline to dump the + credential in text format. This Hunting query is good indicator to look further + for possible remcos infection within the network or possible compromised host. Since + the detections is only base on the parameter command and the possible path where + it will drop the text credential information, It may catch normal tools that having + same command and behavior. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*/stext + *", "*/shtml *", "*/LoadPasswordsIE*", "*/LoadPasswordsFirefox*", "*/LoadPasswordsChrome*", + "*/LoadPasswordsOpera*", "*/LoadPasswordsSafari*" , "*/UseOperaPasswordFile*", "*/OperaPasswordFile*","*/stab*", + "*/scomma*", "*/stabular*", "*/shtml*", "*/sverhtml*", "*/sxml*", "*/skeepass*" + ) AND Processes.process IN ("*\\temp\\*", "*\\users\\public\\*", "*\\programdata\\*") + by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `possible_browser_pass_view_parameter_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: False positive is quite limited. Filter is needed +references: +- https://www.nirsoft.net/utils/web_browser_password.html +- https://app.any.run/tasks/df0baf9f-8baf-4c32-a452-16562ecb19be/ +tags: + analytic_story: + - Remcos + automated_detection_testing: passed + confidence: 40 + context: + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/web_browser_pass_view/sysmon.log + impact: 40 + kill_chain_phases: + - Exploitation + message: suspicious process $process_name$ contains commandline $process$ on $dest$ + mitre_attack_id: + - T1555.003 + - T1555 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 16 + security_domain: endpoint diff --git a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml new file mode 100644 index 0000000000..0d2c0a5cfe --- /dev/null +++ b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml @@ -0,0 +1,86 @@ +name: Possible Lateral Movement PowerShell Spawn +id: cb909b3e-512b-11ec-aa31-3e22fbd008af +version: 1 +date: '2021-11-29' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic assists with identifying a PowerShell process + spawned as a child or grand child process of commonly abused processes during lateral + movement techniques including `services.exe`, `wmiprsve.exe`, `svchost.exe`, `wsmprovhost.exe` + and `mmc.exe`. Legitimate Windows features such as the Service Control Manager, + Windows Management Instrumentation, Task Scheduler, Windows Remote Management and + the DCOM protocol can be abused to start a process on a remote endpoint. Looking + for PowerShell spawned out of this processes may reveal a lateral movement attack. + Red Teams and adversaries alike may abuse these services during a breach for lateral + movement and remote code execution. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=wmiprvse.exe + OR Processes.parent_process_name=services.exe OR Processes.parent_process_name=svchost.exe + OR Processes.parent_process_name=wsmprovhost.exe OR Processes.parent_process_name=mmc.exe) + (Processes.process_name=powershell.exe OR (Processes.process_name=cmd.exe AND Processes.process=*powershell.exe*) + OR Processes.process_name=pwsh.exe OR (Processes.process_name=cmd.exe AND Processes.process=*pwsh.exe*)) + by Processes.dest Processes.user Processes.parent_process Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `possible_lateral_movement_powershell_spawn_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. +known_false_positives: Legitimate applications may spawn PowerShell as a child process + of the the identified processes. Filter as needed. +references: +- https://attack.mitre.org/techniques/T1021/003 +- https://attack.mitre.org/techniques/T1021/006/ +- https://attack.mitre.org/techniques/T1047/ +- https://attack.mitre.org/techniques/T1053.005/ +- https://attack.mitre.org/techniques/T1543/003/ +tags: + analytic_story: + - Active Directory Lateral Movement + - Malicious PowerShell + automated_detection_testing: passed + confidence: 50 + context: + - Source:Endpoint + - Stage:Lateral Movement + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_powershell/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Lateral Movement + - Malicious PowerShell + message: A PowerShell process was spawned as a child process of typically abused + processes on $dest$ + mitre_attack_id: + - T1021 + - T1021.003 + - T1021.006 + - T1047 + - T1053.005 + - T1543.003 + - T1059.001 + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 45 + security_domain: endpoint diff --git a/detections/endpoint/powershell_execute_com_object.yml b/detections/endpoint/powershell_execute_com_object.yml index b0f0eb78c4..21b359f9ae 100644 --- a/detections/endpoint/powershell_execute_com_object.yml +++ b/detections/endpoint/powershell_execute_com_object.yml @@ -58,7 +58,7 @@ tags: - _time risk_score: 5 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_cisco-ucs - Splunk_TA_citrix-netscaler diff --git a/detections/endpoint/powershell_windows_defender_exclusion_commands.yml b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml new file mode 100644 index 0000000000..77326342b3 --- /dev/null +++ b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml @@ -0,0 +1,65 @@ +name: Powershell Windows Defender Exclusion Commands +id: 907ac95c-4dd9-11ec-ba2c-acde48001122 +version: 1 +date: '2021-11-25' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic will detect a suspicious process commandline related to + windows defender exclusion feature. This command is abused by adversaries, malware + author and red teams to bypassed Windows Defender Anti-Virus product by excluding folder + path, file path, process, extensions and etc. from its real time or schedule scan + to execute their malicious code. This is a good indicator for defense evasion and + to look further for events after this behavior. +search: '`powershell` EventCode=4104 (Message = "*Add-MpPreference *" OR Message = + "*Set-MpPreference *") AND Message = "*-exclusion*" | stats count min(_time) as + firstTime max(_time) as lastTime by EventCode Message ComputerName User | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `powershell_windows_defender_exclusion_commands_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: admin or user may choose to use this windows features. +references: +- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html +- https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/ +tags: + analytic_story: + - Remcos + - Windows Defense Evasion Tactics + automated_detection_testing: passed + confidence: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/defender_exclusion_powershell/powershell.log + impact: 80 + kill_chain_phases: + - Exploitation + message: exclusion command $Message$ executed on $ComputerName$ + mitre_attack_id: + - T1562.001 + - T1562 + observable: + - name: User + type: User + role: + - Victim + - name: ComputerName + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - Message + - ComputerName + - User + risk_score: 64 + security_domain: endpoint diff --git a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml index a1af36ee5e..bd5b6ba08c 100644 --- a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml +++ b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml @@ -66,6 +66,6 @@ tags: - Processes.process_guid risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml index 3ba02a6da5..4f3e9afb9f 100644 --- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml +++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml @@ -80,7 +80,7 @@ tags: - Filesystem.user risk_score: 63 security_domain: network - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/process_execution_via_wmi.yml b/detections/endpoint/process_execution_via_wmi.yml index fe64565740..1cfcf8e22f 100644 --- a/detections/endpoint/process_execution_via_wmi.yml +++ b/detections/endpoint/process_execution_via_wmi.yml @@ -71,7 +71,7 @@ tags: - Processes.process_name risk_score: 49 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index f04102be6d..079e1f5f90 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -76,6 +76,6 @@ tags: - Processes.dest risk_score: 42 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml index 4c3d4e8d5a..b6ba6acd3d 100644 --- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml +++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml @@ -79,7 +79,7 @@ tags: - Processes.dest risk_score: 45 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 5cd4452822..37418d8290 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -89,6 +89,6 @@ tags: - Registry.user risk_score: 76 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml index 111952d065..22362f7da6 100644 --- a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml +++ b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml @@ -11,9 +11,9 @@ description: This search looks for modifications to registry keys that can be us to benign system binaries. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*Microsoft\\Windows - NT\\CurrentVersion\\Image File Execution Options*") AND (Registry.registry_key_name=GlobalFlag - OR Registry.registry_key_name=Debugger) by Registry.dest Registry.user Registry.registry_path - Registry.registry_key_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` + NT\\CurrentVersion\\Image File Execution Options*") AND (Registry.registry_value_name=GlobalFlag + OR Registry.registry_value_name=Debugger) by Registry.dest Registry.user Registry.registry_path + Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `registry_keys_used_for_privilege_escalation_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model diff --git a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml index ed4ad3ca11..deda9cfcc4 100644 --- a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml +++ b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml @@ -31,6 +31,7 @@ references: tags: analytic_story: - Suspicious Regsvr32 Activity + - Remcos automated_detection_testing: passed confidence: 60 context: diff --git a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml index 0c1cf5bcca..8b71b94ee8 100644 --- a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml +++ b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml @@ -18,7 +18,8 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` by Processes.user Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name Processes.dest Processes.process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | where match(process,"(?i)[\-|\/][Ss]{1}") | `regsvr32_with_known_silent_switch_cmdline_filter`' + | `security_content_ctime(lastTime)` | where match(process,"(?i)[\-|\/][Ss]{1}") + | `regsvr32_with_known_silent_switch_cmdline_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, @@ -33,6 +34,7 @@ tags: analytic_story: - IcedID - Suspicious Regsvr32 Activity + - Remcos automated_detection_testing: passed confidence: 80 context: diff --git a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml index e2661b19df..4732042e6b 100644 --- a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml @@ -27,14 +27,27 @@ references: - https://www.cybereason.com/blog/dcom-lateral-movement-techniques tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 70 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/lateral_movement/windows-sysmon.log + impact: 90 kill_chain_phases: - Lateral Movement + message: A process was started on a remote endpoint from $dest by abusing DCOM using + PowerShell.exe mitre_attack_id: - T1021 - T1021.003 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -52,18 +65,5 @@ tags: - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id - security_domain: endpoint - impact: 90 - confidence: 70 risk_score: 63 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: A process was started on a remote endpoint from $dest by abusing DCOM using - PowerShell.exe - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml index 488ddda2f7..15389b529a 100644 --- a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml +++ b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml @@ -25,14 +25,27 @@ references: - https://www.cybereason.com/blog/dcom-lateral-movement-techniques tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 70 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.003/lateral_movement/windows-powershell.log + impact: 90 kill_chain_phases: - Lateral Movement + message: A process was started on a remote endpoint from $ComputerName by abusing + WMI using PowerShell.exe mitre_attack_id: - T1021 - T1021.003 + observable: + - name: ComputerName + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -43,18 +56,5 @@ tags: - Message - ComputerName - User - security_domain: endpoint - impact: 90 - confidence: 70 risk_score: 63 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: A process was started on a remote endpoint from $ComputerName by abusing - WMI using PowerShell.exe - observable: - - name: ComputerName - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml index 9aeb221ca4..b26ed0eae8 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml @@ -28,14 +28,27 @@ references: - https://pentestlab.blog/2018/05/15/lateral-movement-winrm/ tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 50 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_psh/windows-sysmon.log + impact: 90 kill_chain_phases: - Lateral Movement + message: A process was started on a remote endpoint from $dest by abusing WinRM + using PowerShell.exe mitre_attack_id: - T1021 - T1021.006 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -53,18 +66,5 @@ tags: - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id - security_domain: endpoint - impact: 90 - confidence: 50 risk_score: 45 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: A process was started on a remote endpoint from $dest by abusing WinRM - using PowerShell.exe - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml index 56aa9292c0..3482d16ebd 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml @@ -18,21 +18,35 @@ how_to_implement: To successfully implement this analytic, you will need to enab PowerShell Script Block Logging on some or all endpoints. Additional setup instructions can be found https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. known_false_positives: Administrators may leverage WinRM and `Invoke-Command` to start - a process on remote systems for system administration or automation use cases. This activity - is usually limited to a small set of hosts or users. In certain environments, tuning may not be possible. + a process on remote systems for system administration or automation use cases. This + activity is usually limited to a small set of hosts or users. In certain environments, + tuning may not be possible. references: - https://attack.mitre.org/techniques/T1021/006/ - https://pentestlab.blog/2018/05/15/lateral-movement-winrm/ tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 50 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_psh/windows-powershell.log + impact: 90 kill_chain_phases: - Lateral Movement + message: A process was started on a remote endpoint from $ComputerName by abusing + WinRM using PowerShell.exe mitre_attack_id: - T1021 - T1021.006 + observable: + - name: ComputerName + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -43,18 +57,5 @@ tags: - Message - ComputerName - User - security_domain: endpoint - impact: 90 - confidence: 50 risk_score: 45 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: A process was started on a remote endpoint from $ComputerName by abusing - WinRM using PowerShell.exe - observable: - - name: ComputerName - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml index 9f9c31b4f9..0cf0e762c5 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml @@ -27,14 +27,26 @@ references: - https://attack.mitre.org/techniques/T1021/006/ tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement/windows-sysmon.log + impact: 90 kill_chain_phases: - Lateral Movement + message: A process was started on a remote endpoint from $dest mitre_attack_id: - T1021 - T1021.006 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -52,17 +64,5 @@ tags: - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id - security_domain: endpoint - impact: 90 - confidence: 60 risk_score: 54 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: A process was started on a remote endpoint from $dest - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/remote_process_instantiation_via_wmi.yml b/detections/endpoint/remote_process_instantiation_via_wmi.yml index 4a29b6ae73..ea0ab2981e 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi.yml @@ -30,7 +30,7 @@ tags: analytic_story: - Ransomware - Suspicious WMI Use - - Lateral Movement + - Active Directory Lateral Movement asset_type: Endpoint automated_detection_testing: passed cis20: diff --git a/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml index 5afc5c14fd..aa04af220f 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml @@ -27,13 +27,26 @@ references: - https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/invoke-wmimethod?view=powershell-5.1 tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 70 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/lateral_movement/windows-sysmon.log + impact: 90 kill_chain_phases: - Lateral Movement + message: A process was started on a remote endpoint from $dest by abusing WMI using + PowerShell.exe mitre_attack_id: - T1047 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -51,18 +64,5 @@ tags: - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id - security_domain: endpoint - impact: 90 - confidence: 70 risk_score: 63 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: A process was started on a remote endpoint from $dest by abusing WMI using - PowerShell.exe - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block.yml index 7307c4ff74..abd9d37eec 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block.yml @@ -25,13 +25,26 @@ references: - https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/invoke-wmimethod?view=powershell-5.1 tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 70 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/lateral_movement/windows-powershell.log + impact: 90 kill_chain_phases: - Lateral Movement + message: A process was started on a remote endpoint from $ComputerName by abusing + WMI using PowerShell.exe mitre_attack_id: - T1047 + observable: + - name: ComputerName + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -42,18 +55,5 @@ tags: - Message - ComputerName - User - security_domain: endpoint - impact: 90 - confidence: 70 risk_score: 63 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: A process was started on a remote endpoint from $ComputerName by abusing - WMI using PowerShell.exe - observable: - - name: ComputerName - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/remote_wmi_command_attempt.yml b/detections/endpoint/remote_wmi_command_attempt.yml index d15eacc6b9..4bf052f1f3 100644 --- a/detections/endpoint/remote_wmi_command_attempt.yml +++ b/detections/endpoint/remote_wmi_command_attempt.yml @@ -76,6 +76,6 @@ tags: - Processes.process_id risk_score: 36 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/resize_shadowstorage_volume.yml b/detections/endpoint/resize_shadowstorage_volume.yml index b03dfd2fb3..77ecb74652 100644 --- a/detections/endpoint/resize_shadowstorage_volume.yml +++ b/detections/endpoint/resize_shadowstorage_volume.yml @@ -70,7 +70,7 @@ tags: - Processes.user risk_score: 72 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/revil_common_exec_parameter.yml b/detections/endpoint/revil_common_exec_parameter.yml index df8f8a92f4..c31284b8e2 100644 --- a/detections/endpoint/revil_common_exec_parameter.yml +++ b/detections/endpoint/revil_common_exec_parameter.yml @@ -67,6 +67,6 @@ tags: - Processes.process_guid risk_score: 54 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/revil_registry_entry.yml b/detections/endpoint/revil_registry_entry.yml index 9194596c10..632f0a5cc7 100644 --- a/detections/endpoint/revil_registry_entry.yml +++ b/detections/endpoint/revil_registry_entry.yml @@ -65,6 +65,6 @@ tags: - Registry.registry_key_name risk_score: 60 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/runas_execution_in_commandline.yml b/detections/endpoint/runas_execution_in_commandline.yml index 5fdc2249db..d7fefc7c3e 100644 --- a/detections/endpoint/runas_execution_in_commandline.yml +++ b/detections/endpoint/runas_execution_in_commandline.yml @@ -31,13 +31,25 @@ references: tags: analytic_story: - Windows Privilege Escalation + automated_detection_testing: passed + confidence: 50 + context: + - Source:Endpoint + - stage:Privilege Escalation dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/vilsel/sysmon.log + impact: 50 kill_chain_phases: - Privilege Escalation + message: elevated process using runas on $dest$ by $user$ mitre_attack_id: - T1134 - T1134.001 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -52,17 +64,5 @@ tags: - Processes.process - Processes.process_id - Processes.parent_process_id - security_domain: endpoint - impact: 50 - confidence: 50 risk_score: 25 - context: - - Source:Endpoint - - stage:Privilege Escalation - message: elevated process using runas on $dest$ by $user$ - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/ryuk_wake_on_lan_command.yml b/detections/endpoint/ryuk_wake_on_lan_command.yml index bc6f63b705..178ddca5d3 100644 --- a/detections/endpoint/ryuk_wake_on_lan_command.yml +++ b/detections/endpoint/ryuk_wake_on_lan_command.yml @@ -73,6 +73,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/samsam_test_file_write.yml b/detections/endpoint/samsam_test_file_write.yml index 38c0eda594..0864c56b63 100644 --- a/detections/endpoint/samsam_test_file_write.yml +++ b/detections/endpoint/samsam_test_file_write.yml @@ -62,7 +62,7 @@ tags: - Filesystem.file_path risk_score: 12 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index 5e592ab93f..e42a5a3200 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -78,7 +78,7 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml index 886e19be11..dc1b4e2e5c 100644 --- a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml +++ b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml @@ -29,14 +29,26 @@ references: - https://docs.microsoft.com/en-us/windows/win32/cimwin32prov/win32-scheduledjob?redirectedfrom=MSDN tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.002/lateral_movement/windows-sysmon.log + impact: 90 kill_chain_phases: - Lateral Movement + message: A Windows Scheduled Task was created on a remote endpoint from $dest mitre_attack_id: - T1053 - T1053.002 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -54,17 +66,5 @@ tags: - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id - security_domain: endpoint - impact: 90 - confidence: 60 risk_score: 54 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: A Windows Scheduled Task was created on a remote endpoint from $dest - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index dd19378fd8..7f3437a7c2 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -71,6 +71,6 @@ tags: - Processes.dest risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml index 74a2245062..534990ea49 100644 --- a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml +++ b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml @@ -26,14 +26,26 @@ references: - https://attack.mitre.org/techniques/T1053/005/ tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/lateral_movement/windows-sysmon.log + impact: 90 kill_chain_phases: - Lateral Movement + message: A Windows Scheduled Task was ran on a remote endpoint from $dest mitre_attack_id: - T1053 - T1053.005 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -51,17 +63,5 @@ tags: - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id - security_domain: endpoint - impact: 90 - confidence: 60 risk_score: 54 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: A Windows Scheduled Task was ran on a remote endpoint from $dest - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/schtasks_run_task_on_demand.yml b/detections/endpoint/schtasks_run_task_on_demand.yml index a0afe191f3..17c489729b 100644 --- a/detections/endpoint/schtasks_run_task_on_demand.yml +++ b/detections/endpoint/schtasks_run_task_on_demand.yml @@ -66,7 +66,7 @@ tags: - Processes.user risk_score: 48 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index b8b13aa3c3..cd8779b806 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -27,7 +27,7 @@ known_false_positives: Administrators may create scheduled tasks on remote syste references: [] tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement - NOBELIUM Group asset_type: Endpoint automated_detection_testing: passed @@ -73,7 +73,7 @@ tags: - Processes.user risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index 4e9caf787c..64971ebcfd 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -70,7 +70,7 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml index e60baa369f..098bb5af5f 100644 --- a/detections/endpoint/screensaver_event_trigger_execution.yml +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -67,6 +67,6 @@ tags: - Registry.registry_value_name risk_score: 72 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/script_execution_via_wmi.yml b/detections/endpoint/script_execution_via_wmi.yml index b416c6d5d0..7b0f972204 100644 --- a/detections/endpoint/script_execution_via_wmi.yml +++ b/detections/endpoint/script_execution_via_wmi.yml @@ -65,7 +65,7 @@ tags: - Processes.dest risk_score: 36 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/sdclt_uac_bypass.yml b/detections/endpoint/sdclt_uac_bypass.yml index f0a888a33e..2909953f4f 100644 --- a/detections/endpoint/sdclt_uac_bypass.yml +++ b/detections/endpoint/sdclt_uac_bypass.yml @@ -13,7 +13,7 @@ description: This search is to detect a suspicious sdclt.exe registry modificati search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\Windows\\CurrentVersion\\App Paths\\control.exe*" OR Registry.registry_path= "*\\exefile\\shell\\runas\\command\\*") - (Registry.registry_key_name = "(Default)" OR Registry.registry_key_name = "IsolatedCommand") + (Registry.registry_value_name = "(Default)" OR Registry.registry_value_name = "IsolatedCommand") by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `sdclt_uac_bypass_filter`' @@ -62,6 +62,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index 784c131d63..24cd6152f1 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -68,6 +68,6 @@ tags: - Processes.process_guid risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/services_escalate_exe.yml b/detections/endpoint/services_escalate_exe.yml index 321c001e97..9b5d49aaa8 100644 --- a/detections/endpoint/services_escalate_exe.yml +++ b/detections/endpoint/services_escalate_exe.yml @@ -75,6 +75,6 @@ tags: - Processes.parent_process_id risk_score: 76 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml new file mode 100644 index 0000000000..3761b132b9 --- /dev/null +++ b/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml @@ -0,0 +1,81 @@ +name: Services LOLBAS Execution Process Spawn +id: ba9e1954-4c04-11ec-8b74-3e22fbd008af +version: 1 +date: '2021-11-22' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies `services.exe` spawning a LOLBAS execution + process. When adversaries execute code on remote endpoints abusing the Service Control + Manager and creating a remote malicious service, the executed command is spawned + as a child process of `services.exe`. The LOLBAS project documents Windows native + binaries that can be abused by threat actors to perform tasks like executing malicious + code. Looking for child processes of services.exe that are part of the LOLBAS project + can help defenders identify lateral movement activity. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=services.exe) + (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", + "Rasautou.exe", "Schtasks.exe", "Xwizard.exe", "Dllhost.exe", "Pnputil.exe", "Atbroker.exe", + "Pcwrun.exe", "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe", "Certoc.exe", "Ieexec.exe", + "Microsoft.Workflow.Compiler.exe", "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe", + "Register-cimprovider.exe", "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe", + "SettingSyncHost.exe", "Cmstp.exe", "Mmc.exe", "Stordiag.exe", "Scriptrunner.exe", + "Odbcconf.exe", "Extexport.exe", "Msdt.exe", "WorkFolders.exe", "Diskshadow.exe", + "Mavinject.exe", "Regasm.exe", "Gpscript.exe", "Rundll32.exe", "Regsvr32.exe", "Msiexec.exe", + "Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", "Runonce.exe", "Syncappvpublishingserver.exe", + "Verclsid.exe", "Infdefaultinstall.exe", "Explorer.exe", "Installutil.exe", "Netsh.exe", + "Wab.exe", "Dnscmd.exe", "At.exe", "Pcalua.exe", "Msconfig.exe")) by Processes.dest + Processes.user Processes.parent_process Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `services_lolbas_execution_process_spawn_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. +known_false_positives: Legitimate applications may trigger this behavior, filter as + needed. +references: +- https://attack.mitre.org/techniques/T1543/003/ +- https://pentestlab.blog/2020/07/21/lateral-movement-services/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_lolbas/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Lateral Movement + message: Services.exe spawned a LOLBAS process on $dest + mitre_attack_id: + - T1543 + - T1543.003 + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 54 + security_domain: endpoint diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index 5ed48ac68f..5647bf7d47 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -71,6 +71,6 @@ tags: - Registry.dest risk_score: 48 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index 01a3b5597f..04d2595b95 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -68,7 +68,7 @@ tags: - Processes.user risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/short_lived_scheduled_task.yml b/detections/endpoint/short_lived_scheduled_task.yml new file mode 100644 index 0000000000..260ed20cce --- /dev/null +++ b/detections/endpoint/short_lived_scheduled_task.yml @@ -0,0 +1,67 @@ +name: Short Lived Scheduled Task +id: 6fa31414-546e-11ec-adfa-acde48001122 +version: 1 +date: '2021-12-03' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: The following analytic leverages Windows Security EventCode 4698, `A + scheduled task was created` and Windows Security EventCode 4699, `A scheduled task + was deleted` to identify scheduled tasks created and deleted in less than 30 seconds. + This behavior may represent a lateral movement attack abusing the Task Scheduler + to obtain code execution. Red Teams and adversaries alike may abuse the Task Scheduler + for lateral movement and remote code execution. +search: ' `wineventlog_security` EventCode=4698 OR EventCode=4699 | xmlkv Message + | transaction Task_Name startswith=(EventCode=4698) endswith=(EventCode=4699) | + eval short_lived=case((duration<30),"TRUE") | search short_lived = TRUE | table + _time, ComputerName, Account_Name, Command, Task_Name, short_lived | `short_lived_scheduled_task_filter` ' +how_to_implement: To successfully implement this search, you need to be ingesting + Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also + required. +known_false_positives: Although uncommon, legitimate applications may create and delete + a Scheduled Task within 30 seconds. Filter as needed. +references: +- https://attack.mitre.org/techniques/T1053/005/ +- https://docs.microsoft.com/en-us/windows/win32/taskschd/about-the-task-scheduler +tags: + analytic_story: + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 90 + context: + - Source:Endpoint + - Stage:Execution + - Stage:Persistence + - Stage:Privilege Escalation + - Stage:Lateral Movement + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/lateral_movement/windows-security.log + impact: 90 + kill_chain_phases: + - Lateral Movement + message: A windows scheduled task was created and deleted in 30 seconds on $ComputerName$ + mitre_attack_id: + - T1053.005 + observable: + - name: dest + type: Endpoint + role: + - Victim + - name: Command + type: Command + role: + - Target + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - dest + - ComputerName + - Account_Name + - Task_Name + - Description + - Command + risk_score: 81 + security_domain: endpoint diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index 6422c9604a..c23ae2d576 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -63,7 +63,7 @@ tags: - All_Changes.dest risk_score: 63 security_domain: access - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose diff --git a/detections/endpoint/silentcleanup_uac_bypass.yml b/detections/endpoint/silentcleanup_uac_bypass.yml index 4f3f15f425..f4d7ee0fda 100644 --- a/detections/endpoint/silentcleanup_uac_bypass.yml +++ b/detections/endpoint/silentcleanup_uac_bypass.yml @@ -60,6 +60,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index ce7437f33e..3a1badfb11 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -66,7 +66,7 @@ tags: - Processes.process_name risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/slui_runas_elevated.yml b/detections/endpoint/slui_runas_elevated.yml index 5924a2739c..4f19e1fde7 100644 --- a/detections/endpoint/slui_runas_elevated.yml +++ b/detections/endpoint/slui_runas_elevated.yml @@ -72,6 +72,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/slui_spawning_a_process.yml b/detections/endpoint/slui_spawning_a_process.yml index 359cfdab49..d3cda3ac54 100644 --- a/detections/endpoint/slui_spawning_a_process.yml +++ b/detections/endpoint/slui_spawning_a_process.yml @@ -70,6 +70,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml index eb762b451b..64f313ed08 100644 --- a/detections/endpoint/spoolsv_writing_a_dll.yml +++ b/detections/endpoint/spoolsv_writing_a_dll.yml @@ -81,7 +81,7 @@ tags: - Processes.dest risk_score: 72 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml b/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml new file mode 100644 index 0000000000..4fe9ee9bad --- /dev/null +++ b/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml @@ -0,0 +1,79 @@ +name: Anomalous usage of Archive Tools +id: 63614a58-10e2-4c6c-ae81-ea1113681439 +version: 1 +date: '2021-11-22' +author: Patrick Bareiss, Splunk +type: Anomaly +datamodel: +- Endpoint_Processes +description: The following detection identifies the usage of archive tools from the + command line. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), + "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), + parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), parent_process=ucast(map_get(input_event, "parent_process"), "string", null), + event_id=ucast(map_get(input_event, "event_id"), "string", null) | where process_name + IS NOT NULL AND parent_process_name IS NOT NULL | where like(process_name, "7z%") + OR process_name="WinRAR.exe" OR like(process_name, "winzip%") | where like(parent_process_name, + "%cmd.exe") OR like(parent_process_name, "%powershell.exe") | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "process_name", process_name, "parent_process_name", + parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: False positives can be ligitmate usage of archive tools from + the command line. +references: +- https://attack.mitre.org/techniques/T1560/001/ +tags: + analytic_story: + - Cobalt Strike + - NOBELIUM Group + confidence: 60 + context: + - Source:Endpoint + - Stage:Collection + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_tools/windows-security.log + impact: 70 + kill_chain_phases: + - Actions on Objective + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading + of 7zip. + mitre_attack_id: + - T1560.001 + - T1560 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - Processes.process_name + - Processes.process + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + risk_score: 42 + security_domain: endpoint diff --git a/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml b/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml deleted file mode 100644 index 83940d73f0..0000000000 --- a/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml +++ /dev/null @@ -1,85 +0,0 @@ -name: Applying Stolen Credentials via Mimikatz modules -id: 759a653f-cb92-40f9-94c9-ec4e47b0f709 -version: 1 -date: '2020-11-03' -author: Stanislav Miskovic, Splunk -type: TTP -datamodel: [] -description: This detection indicates use of Mimikatz modules that facilitate Pass-the-Token - attack, Golden or Silver kerberos ticket attack, and Skeleton key attack. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line != null AND ( match_regex(cmd_line, /(?i)kerberos::ptt/)=true OR match_regex(cmd_line, - /(?i)kerberos::golden/)=true OR match_regex(cmd_line, /(?i)kerberos::silver/)=true - OR match_regex(cmd_line, /(?i)misc::skeleton/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz -- https://adsecurity.org/?p=1275 -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is violating authentication processes by injecting golden - or silver Kerberos tickets or passing stolen authentication tokens. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1055 - - T1068 - - T1078 - - T1098 - - T1134 - - T1543 - - T1547 - - T1548 - - T1554 - - T1556 - - T1558 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - type: User - role: - - Actor - - name: dest_device_id - type: Hostname - role: - - Victim - - name: cmd_line - type: processname - role: - - Others - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint diff --git a/detections/endpoint/ssa___attempt_to_delete_services.yml b/detections/endpoint/ssa___attempt_to_delete_services.yml index 2321bedfa3..6453a543b4 100644 --- a/detections/endpoint/ssa___attempt_to_delete_services.yml +++ b/detections/endpoint/ssa___attempt_to_delete_services.yml @@ -1,15 +1,16 @@ -name: Attempt To delete Services +name: Attempt To Delete Services id: a0c8c292-d01a-11eb-aa18-acde48001122 -version: 2 -date: '2021-06-18' +version: 3 +date: '2021-11-24' author: Teoderick Contreras, splunk type: TTP datamodel: -- Endpoint -description: This analytic identifies suspicious series of attempt to kill multiple - services on a system using either `net.exe` or `sc.exe`. This technique is use by - adversaries to terminate security services or other related services to continue - there objective and evade detections. +- Endpoint_Processes +description: The following analytic identifies Windows Service Control, `sc.exe`, + attempting to delete a service. This is typically identified in parallel with other + instances of service enumeration of attempts to stop a service and then delete it. + Adversaries utilize this technique to terminate security services or other related + services to continue there objective and evade detections. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), @@ -25,10 +26,12 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed sc.exe may be used. -known_false_positives: unknown + Sysmon TA. +known_false_positives: It is possible administrative scripts may start/stop/delete + services. Filter as needed. references: - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md tags: analytic_story: - XMRig @@ -36,15 +39,42 @@ tags: cis20: - CIS 8 - CIS 13 + confidence: 60 + context: + - Source:Endpoint + - Stage:Privilege Escalation + - Stage:Persistence dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log + impact: 60 kill_chain_phases: - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. mitre_attack_id: - T1489 + - T1543 + - T1543.003 nist: - PR.DS - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process product: - Splunk Behavioral Analytics required_fields: @@ -55,5 +85,7 @@ tags: - process_path - dest_user_id - process + - cmd_line + risk_score: 36 risk_severity: high security_domain: endpoint diff --git a/detections/endpoint/ssa___attempt_to_disable_services.yml b/detections/endpoint/ssa___attempt_to_disable_services.yml index 2afe31f0da..88ddd15bcb 100644 --- a/detections/endpoint/ssa___attempt_to_disable_services.yml +++ b/detections/endpoint/ssa___attempt_to_disable_services.yml @@ -1,15 +1,16 @@ name: Attempt To Disable Services id: afb31de4-d023-11eb-98d5-acde48001122 -version: 2 -date: '2021-06-18' +version: 3 +date: '2021-11-24' author: Teoderick Contreras, Splunk type: TTP datamodel: -- Endpoint -description: This analytic will identify suspicious series of command-line to disable - several services. This technique is seen where the adversary attempts to disable - security app services or other malware services to complete the objective on the - compromised system. +- Endpoint_Processes +description: The following analytic identifies Windows Service Control, `sc.exe`, + attempting to disable a service. This is typically identified in parallel with other + instances of service enumeration of attempts to stop a service and then disable + it. Adversaries utilize this technique to terminate security services or other related + services to continue there objective and evade detections. search: '| from read_ssa_enriched_events() | eval _datamodels=ucast(map_get(input_event, "_datamodels"), "collection", []), body={} | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), @@ -26,11 +27,13 @@ search: '| from read_ssa_enriched_events() | eval _datamodels=ucast(map_get(inpu how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed sc.exe may be used. -known_false_positives: unknown + Sysmon TA. +known_false_positives: It is possible administrative scripts may start/stop/delete + services. Filter as needed. references: - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service tags: analytic_story: - XMRig @@ -38,15 +41,40 @@ tags: cis20: - CIS 9 - CIS 8 + confidence: 60 + context: + - Source:Endpoint + - Stage:Privilege Escalation + - Stage:Persistence dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log + impact: 60 kill_chain_phases: - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. mitre_attack_id: - T1489 nist: - PR.DS - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process product: - Splunk Behavioral Analytics required_fields: @@ -57,5 +85,6 @@ tags: - process_path - dest_user_id - process + risk_score: 36 risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml index 66609e68dd..531fd0e392 100644 --- a/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml @@ -1,12 +1,14 @@ name: Attempted Credential Dump From Registry via Reg exe id: 14038953-e5f2-4daf-acff-5452062baf03 -version: 1 -date: 2020-6-04 +version: 2 +date: '2021-11-29' author: Jose Hernandez, Splunk type: TTP -datamodel: [] -description: Monitor for execution of reg.exe with parameters specifying an export - of keys that contain hashed credentials that attackers may try to crack offline. +datamodel: +- Endpoint_Processes +description: The following analytic identifies the use of `reg.exe` attempting to + export Windows registry keys that contain hashed credentials. Adversaries will utilize + this technique to capture and perform offline password cracking. search: ' | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) | eval process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), @@ -21,11 +23,14 @@ search: ' | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(ma = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events(); ' -how_to_implement: You must be ingesting windows endpoint data that tracks process - activity, including parent-child relationships from your endpoints. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. known_false_positives: None identified. references: - https://github.com/splunk/security_content/blob/55a17c65f9f56c2220000b62701765422b46125d/detections/attempted_credential_dump_from_registry_via_reg_exe.yml +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets tags: analytic_story: - Credential Dumping @@ -42,11 +47,11 @@ tags: impact: 70 kill_chain_phases: - Actions on Objectives - message: Malicious actor is dumping stored credentials from the registry sections - SAM, Security, or System. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ + message: An attempt to save registry keys storing credentials has been performed + on $dest_device_id$ by $dest_user_id$ via process $process_name$. mitre_attack_id: - T1003 + - T1003.002 nist: - DE.CM observable: @@ -58,10 +63,10 @@ tags: type: Hostname role: - Victim - - name: cmd_line - type: processname + - name: process_name + type: process role: - - Others + - Child Process product: - Splunk Behavioral Analytics required_fields: @@ -70,6 +75,7 @@ tags: - dest_device_id - dest_user_id - process + - cmd_line risk_score: 63 risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml b/detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml new file mode 100644 index 0000000000..d2c3c44e8f --- /dev/null +++ b/detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml @@ -0,0 +1,83 @@ +name: BCDEdit Failure Recovery Modification +id: 76d79d6e-25bb-40f6-b3b2-e0a6b7e5ea13 +version: 1 +date: '2021-12-07' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This search looks for flags passed to bcdedit.exe modifications to the + built-in Windows error recovery boot configurations. This is typically used by ransomware + to prevent recovery. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="bcdedit.exe" + AND (like (cmd_line, "%recoveryenabled%") AND like (cmd_line, "%no%")) | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, + "parent_process_name", parent_process_name, "process_path", process_path]) | into + write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +known_false_positives: Administrators may modify the boot configuration. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair +tags: + analytic_story: + - Ryuk Ransomware + - Ransomware + cis20: + - CIS 8 + confidence: 80 + context: + - Source:Endpoint + - Stage:Impact + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability + to recover the endpoint. + mitre_attack_id: + - T1490 + nist: + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 80 + risk_severity: high + security_domain: endpoint diff --git a/detections/endpoint/ssa___delete_a_net_user.yml b/detections/endpoint/ssa___delete_a_net_user.yml index 5024295db6..daae967aa8 100644 --- a/detections/endpoint/ssa___delete_a_net_user.yml +++ b/detections/endpoint/ssa___delete_a_net_user.yml @@ -1,11 +1,11 @@ name: Delete A Net User id: 8776d79c-d26e-11eb-9a56-acde48001122 -version: 2 -date: '2021-06-21' +version: 3 +date: '2021-11-30' author: Teoderick Contreras, Splunk type: Anomaly datamodel: -- Endpoint +- Endpoint_Processes description: This analytic will detect a suspicious net.exe/net1.exe command-line to delete a user on a system. This technique may be use by an administrator for legitimate purposes, however this behavior has been used in the wild to impair some @@ -24,10 +24,10 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' -how_to_implement: o successfully implement this search, you need to be ingesting logs - with the process name, parent process, and command-line executions from your endpoints. - If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. - Tune and filter known instances where renamed net.exe may be used. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed net.exe may be used. known_false_positives: System administrators or scripts may delete user accounts via this technique. Filter as needed. references: @@ -39,15 +39,41 @@ tags: cis20: - CIS 4 - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/atomic_red_team/security.log + impact: 70 kill_chain_phases: - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user + account. mitre_attack_id: - - T1489 + - T1531 nist: - PR.AC - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process product: - Splunk Behavioral Analytics required_fields: @@ -58,5 +84,7 @@ tags: - process_path - dest_user_id - process + - cmd_line + risk_score: 49 risk_severity: high security_domain: endpoint diff --git a/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml b/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml index 676ad9ffaf..6a3ade760d 100644 --- a/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml +++ b/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml @@ -1,15 +1,15 @@ name: Deny Permission using Cacls Utility id: b76eae28-cd25-11eb-9c92-acde48001122 -version: 2 -date: '2021-06-14' +version: 3 +date: '2021-11-29' author: Teoderick Contreras, Splunk type: TTP datamodel: -- Endpoint -description: This analytic identifies a potential adversary that changes the security - permission of a specific file or directory. This technique is commonly seen in APT - tradecraft, ransomware or coinminer scripts. This behavior is meant to evade detection - and prevent access to their component files. +- Endpoint_Processes +description: The following analytic identifies the use of `cacls.exe`, `icacls.exe` + or `xcacls.exe` placing the deny permission on a file or directory. Adversaries + perform this behavior to prevent responders from reviewing or gaining access to + adversary files on disk. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), @@ -26,8 +26,8 @@ how_to_implement: To successfully implement this search, you need to be ingestin logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. -known_false_positives: network administrator may use this windows utility but this - is not a common practice. +known_false_positives: System administrators may use cacls utilities but this is not + a common practice. Filter as needed. references: - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ tags: @@ -71,6 +71,7 @@ tags: - process_path - dest_user_id - process + - cmd_line risk_score: 35 risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml index 9d797b74ee..187ab0a6e6 100644 --- a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml +++ b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml @@ -1,12 +1,14 @@ name: Detect Dump LSASS Memory using comsvcs id: 76bb9e35-f314-4c3d-a385-83c72a13ce4e -version: 1 -date: '2020-09-15' +version: 2 +date: '2021-11-29' author: Jose Hernandez, Splunk type: TTP -datamodel: [] -description: This search detects the memory of lsass.exe being dumped for offline - credential theft attack. +datamodel: +- Endpoint_Processes +description: The following analytic identifies credential dumping using comsvcs.dll + with `regsvr32.exe`. This technique is common with adversaries who would like to + dump the memory of lsass.exe and perform offline password cracking. search: '| from read_ssa_enriched_events() | eval tenant=ucast(map_get(input_event, "_tenant"), "string", null), machine=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), @@ -20,9 +22,10 @@ how_to_implement: You must be ingesting endpoint data that tracks process activi including Windows command line logging. You can see how we test this with [Event Code 4688](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4688a) on the [attack_range](https://github.com/splunk/attack_range/blob/develop/ansible/roles/windows_common/tasks/windows-enable-4688-cmd-line-audit.yml). -known_false_positives: None identified. +known_false_positives: False positives should be limited, filter as needed. references: - https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-3---dump-lsassexe-memory-using-comsvcsdll tags: analytic_story: - Credential Dumping @@ -40,9 +43,8 @@ tags: impact: 70 kill_chain_phases: - Actions on Objectives - message: Malicious actor is dumping encoded credentials via Microsoft's native comsvc - DLL. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ + message: A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ + by user $dest_device_user$. mitre_attack_id: - T1003.003 - T1003 @@ -57,10 +59,6 @@ tags: type: Hostname role: - Victim - - name: cmd_line - type: processname - role: - - Others product: - Splunk Behavioral Analytics required_fields: diff --git a/detections/endpoint/ssa___detect_kerberoasting.yml b/detections/endpoint/ssa___detect_kerberoasting.yml index 79d5759281..404a1733d4 100644 --- a/detections/endpoint/ssa___detect_kerberoasting.yml +++ b/detections/endpoint/ssa___detect_kerberoasting.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-10-21' author: Xiao Lin, Splunk type: TTP -datamodel: [] +datamodel: +- Certificates description: This search detects a potential kerberoasting attack via service principal name requests search: ' | from read_ssa_enriched_events() | eval _time=map_get(input_event, "_time"), @@ -17,11 +18,11 @@ search: ' | from read_ssa_enriched_events() | eval _time=map_get(input_event, "_ AND TicketOptions="0x40810000" AND TicketEncryptionType="0x17" | first_time_event input_columns=["EventCode","TicketOptions","TicketEncryptionType","ServiceName","ServiceID"] | where first_time_EventCode_TicketOptions_TicketEncryptionType_ServiceName_ServiceID - | eval start_time=_time, end_time=_time, body=create_map(["event_id", event_id, + | eval start_time=_time, end_time=_time | eval body=create_map(["event_id", event_id, "EventCode", EventCode, "ServiceName", ServiceName, "TicketOptions", TicketOptions, - "TicketEncryptionType", TicketEncryptionType]), entities = mvappend( ucast(map_get(input_event, + "TicketEncryptionType", TicketEncryptionType]), entities = mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null))| select start_time, end_time, entities, body | into write_ssa_detected_events();' + "string", null)) | select start_time, end_time, entities, body | into write_ssa_detected_events();' how_to_implement: The test data is converted from Windows Security Event logs generated from Attach Range simulation and used in SPL search and extended to SPL2 known_false_positives: Older systems that support kerberos RC4 by default NetApp may diff --git a/detections/endpoint/ssa___detect_rclone_command_line_usage.yml b/detections/endpoint/ssa___detect_rclone_command_line_usage.yml new file mode 100644 index 0000000000..b071149c60 --- /dev/null +++ b/detections/endpoint/ssa___detect_rclone_command_line_usage.yml @@ -0,0 +1,91 @@ +name: Detect RClone Command-Line Usage +id: e8b74268-5454-11ec-a799-acde48001122 +version: 1 +date: '2021-12-03' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This analytic identifies commonly used command-line arguments used by + `rclone.exe` to initiate a file transfer. Some arguments were negated as they are + specific to the configuration used by adversaries. In particular, an adversary may + list the files or directories of the remote file share using `ls` or `lsd`, which + is not indicative of malicious behavior. During triage, at this stage of a ransomware + event, exfiltration is about to occur or has already. Isolate the endpoint and continue + investigating by review file modifications and parallel processes. +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="rclone.exe" + AND (like (cmd_line, "%copy%") OR like (cmd_line, "%mega%")OR like (cmd_line, "%pcloud%") + OR like (cmd_line, "%ftp%") OR like (cmd_line, "%--config%") OR like (cmd_line, + "%--progress%") OR like (cmd_line, "%--no-check-certificate%") OR like (cmd_line, + "%--ignore-existing%") OR like (cmd_line, "%--auto-confirm%") OR like (cmd_line, + "%--transfers%") OR like (cmd_line, "%--multi-thread-streams%")) | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) + | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +known_false_positives: False positives should be limited as this is restricted to + the Rclone process name. Filter or tune the analytic as needed. +references: +- https://redcanary.com/blog/rclone-mega-extortion/ +- https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html +- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ +- https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ +tags: + analytic_story: + - DarkSide Ransomware + - Ransomware + automated_detection_testing: passed + confidence: 70 + context: + - Source:Endpoint + - Stage:Exfiltration + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-security.log + impact: 50 + kill_chain_phases: + - Exfiltration + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a + remote cloud service to move files or folders. + mitre_attack_id: + - T1020 + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 35 + security_domain: endpoint diff --git a/detections/endpoint/ssa___disable_net_user_account.yml b/detections/endpoint/ssa___disable_net_user_account.yml index b3772d342d..f83a0091bf 100644 --- a/detections/endpoint/ssa___disable_net_user_account.yml +++ b/detections/endpoint/ssa___disable_net_user_account.yml @@ -1,34 +1,35 @@ name: Disable Net User Account id: ba858b08-d26c-11eb-af9b-acde48001122 -version: 2 -date: '2021-06-21' +version: 3 +date: '2021-11-30' author: Teoderick Contreras, Splunk type: TTP datamodel: -- Endpoint +- Endpoint_Processes description: This analytic will identify a suspicious command-line that disables a - user account using the `net.exe` utility native to Windows. This technique may used - by the adversaries to interrupt availability of such users to do their malicious - act. + user account using the native `net.exe` or `net1.exe` utility to Windows. This technique + may used by the adversaries to interrupt availability of accounts and continue the + impact against the organization. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%/active:no%") AND (process_name="net1.exe" - OR process_name="net.exe") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' + cmd_line IS NOT NULL AND like(cmd_line, "%/active:no%") AND like(cmd_line, "%user%") + AND (process_name="net1.exe" OR process_name="net.exe") | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, + "parent_process_name", parent_process_name, "process_path", process_path]) | into + write_ssa_detected_events();' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed net.exe/net1.exe may be used. -known_false_positives: network operator may use this approach to quickly disable an - account but not a common practice. +known_false_positives: System administrators or automated scripts may disable an account + but not a common practice. Filter as needed. references: - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ tags: @@ -38,15 +39,40 @@ tags: cis20: - CIS 4 - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log + impact: 70 kill_chain_phases: - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. mitre_attack_id: - T1489 + - T1078 nist: - PR.AC - PR.IP + observable: + - name: user + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process product: - Splunk Behavioral Analytics required_fields: @@ -57,5 +83,7 @@ tags: - process_path - dest_user_id - process + - cmd_line + risk_score: 49 risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml b/detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml new file mode 100644 index 0000000000..28b9bfa6ff --- /dev/null +++ b/detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml @@ -0,0 +1,88 @@ +name: DNS Exfiltration Using Nslookup App +id: 2452e632-9e0d-11eb-34ba-acde48001122 +version: 1 +date: '2021-12-07' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This search is to detect potential DNS exfiltration using nslookup application. + This technique are seen in couple of malware and APT group to exfiltrated collected + data in a infected machine or infected network. This detection is looking for unique + use of nslookup where it tries to use specific record type, TXT, A, AAAA, that are + commonly used by attacker and also the retry parameter which is designed to query + C2 DNS multiple tries. +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="nslookup.exe" + AND (like (cmd_line, "%-querytype=%") OR like (cmd_line, "%-qt=%") OR like (cmd_line, + "%-q=%") OR like (cmd_line, "%-type=%") OR like (cmd_line, "%-retry=%")) | eval + start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, + "process_name", process_name, "parent_process_name", parent_process_name, "process_path", + process_path]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +known_false_positives: It is possible for some legitimate administrative utilities + to use similar cmd_line parameters. Filter as needed. +references: +- https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html +- https://www.varonis.com/blog/dns-tunneling/ +- https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/ +tags: + analytic_story: + - Suspicious DNS Traffic + - Dynamic DNS + - Command and Control + - Data Exfiltration + automated_detection_testing: passed + confidence: 80 + context: + - Source:Endpoint + - Stage:Exfiltration + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related + to DNS exfiltration. + mitre_attack_id: + - T1048 + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 72 + security_domain: endpoint diff --git a/detections/endpoint/ssa___excessive_number_of_office_files_copied.yml b/detections/endpoint/ssa___excessive_number_of_office_files_copied.yml new file mode 100644 index 0000000000..52edec9e37 --- /dev/null +++ b/detections/endpoint/ssa___excessive_number_of_office_files_copied.yml @@ -0,0 +1,49 @@ +name: Excessive Number of Office Files Copied +id: 3c6594a9-8df6-45a1-9357-d73b62083c63 +version: 1 +date: '2021-12-07' +author: Patrick Bareiss, Splunk +type: Anomaly +datamodel: +- Endpoint_Filesystem +description: This detection detects a high amount of office file copied. This can + be an indicator for a malicious insider. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval action=ucast(map_get(input_event, "action"), "string", + null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, + "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), + "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", + null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) + | where "Endpoint_Filesystem" IN(_datamodels) | where action="created" | where like(file_name, + "%.doc%") OR like(file_name, "%.xls%") OR like(file_name, "%.ppt%") | stats count(file_name) + AS count BY dest_user_id, dest_device_id, span(timestamp, 10m) | where count > 20 + | eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, + dest_device_id), body=create_map(["count", count]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Filesytem` node. +known_false_positives: user may copy a lot of office fies from one folder to another +references: [] +tags: + analytic_story: [] + confidence: 80 + context: + - Source:Endpoint + - Stage:Exfitration + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/mass_file_creation/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: High number of files copied + mitre_attack_id: + - T1048.003 + product: + - Splunk Behavioral Analytics + required_fields: + - action + - process + - file_name + - file_path + risk_score: 72 + security_domain: endpoint diff --git a/detections/endpoint/ssa___first_time_seen_cmd_line.yml b/detections/endpoint/ssa___first_time_seen_cmd_line.yml index 61fe4af67e..4c5509119e 100644 --- a/detections/endpoint/ssa___first_time_seen_cmd_line.yml +++ b/detections/endpoint/ssa___first_time_seen_cmd_line.yml @@ -1,13 +1,19 @@ name: First time seen command line argument id: fc0edc95-ff2b-48b0-9f6f-63da3789fd23 -version: 3 -date: 2021-2-1 +version: 4 +date: '2021-11-30' author: Ignacio Bermudez Corrales, Splunk type: Anomaly -datamodel: [] +datamodel: +- Endpoint_Processes description: This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. This is an implementation - on SPL2 of the rule `First time seen command line argument` by @bpatel. + on SPL2 of the rule `First time seen command line argument` by @bpatel. 'The following + analytic identifies first time seen command-line arguments on a single endpoint. + The analytic looks for arguments instantiated by `cmd.exe /c` and the associated + command-line. Adversaries automate or spawn multiple processes using this method, + this analytic may assist with identifying the first time it's been found on this + endpoint.' search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) | eval dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", @@ -25,12 +31,13 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map | eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events();' -how_to_implement: You must be populating the endpoint data model for SSA and specifically - the process_name and the process fields -known_false_positives: Legitimate programs can also use command-line arguments to - execute. Please verify the command-line arguments to check what command/program - is being executed. We recommend customizing the `first_time_seen_cmd_line_filter` - macro to exclude legitimate parent_process_name +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: Legitimate programs use command-line arguments to execute. + Verify the command-line arguments to check what command/program is being executed. + Filtering will be needed. references: [] tags: analytic_story: @@ -46,11 +53,10 @@ tags: kill_chain_phases: - Command and Control - Actions on Objectives - message: A cmd process $process_name$ with commandline $cmd_line$ try to execute - command has not previously seen in host $dest_device_id$ + message: A process $process_name$ ha been identified in the environment with a command-line + $cmd_line$ not previously seen before on host $dest_device_id$ mitre_attack_id: - T1059 - - T1117 - T1202 nist: - PR.PT @@ -73,6 +79,7 @@ tags: - dest_device_id - dest_user_id - process + - cmd_line risk_score: 30 risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___fsutil_zeroing_file.yml b/detections/endpoint/ssa___fsutil_zeroing_file.yml new file mode 100644 index 0000000000..5b0d131f45 --- /dev/null +++ b/detections/endpoint/ssa___fsutil_zeroing_file.yml @@ -0,0 +1,82 @@ +name: Fsutil Zeroing File +id: f792cdc9-43ee-4429-a3c0-ffce4fed1a85 +version: 1 +date: '2021-12-07' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This search is to detect a suspicious fsutil process to zeroing a target + file. This technique was seen in lockbit ransomware where it tries to zero out its + malware path as part of its defense evasion after encrypting the compromised host. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="fsutil.exe" + AND (like (cmd_line, "%setzerodata%")) | eval start_time=timestamp, end_time=timestamp, + entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, + "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", + cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, + "process_path", process_path]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed net.exe may be used. +known_false_positives: System administrators or scripts may delete user accounts via + this technique. Filter as needed. +references: +- https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/ +- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-file +tags: + analytic_story: + - Ransomware + confidence: 90 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: [] + impact: 60 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file + deletion. + mitre_attack_id: + - T1070 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 54 + risk_severity: high + security_domain: endpoint diff --git a/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml b/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml index 2fb386ce14..cd874d9edd 100644 --- a/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml +++ b/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml @@ -1,15 +1,15 @@ name: Grant Permission Using Cacls Utility id: c6da561a-cd29-11eb-ae65-acde48001122 -version: 2 -date: '2021-06-14' +version: 3 +date: '2021-11-30' author: Teoderick Contreras, Splunk type: TTP datamodel: -- Endpoint -description: This analytic identifies potential adversaries that modify the security - permission of a specific file or directory. This technique is commonly seen in APT - tradecraft, ransomware and coinminer scripts to evade detections and restrict access - to their component files. +- Endpoint_Processes +description: The following analytic identifies the use of `cacls.exe`, `icacls.exe` + or `xcacls.exe` placing the grant permission on a file or directory. Adversaries + perform this behavior to allow components of their files to run, however it allows + responders to review or gaining access to adversary files on disk. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), @@ -26,8 +26,8 @@ how_to_implement: To successfully implement this search, you need to be ingestin logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. -known_false_positives: network administrator may use this windows utility but this - is not a common practice. +known_false_positives: System administrators may use cacls utilities but this is not + a common practice. Filter as needed. references: - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ tags: @@ -71,6 +71,7 @@ tags: - process_path - dest_user_id - process + - cmd_line risk_score: 35 risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___high_file_deletion_frequency.yml b/detections/endpoint/ssa___high_file_deletion_frequency.yml new file mode 100644 index 0000000000..b377297dc0 --- /dev/null +++ b/detections/endpoint/ssa___high_file_deletion_frequency.yml @@ -0,0 +1,70 @@ +name: High File Deletion Frequency +id: b6200efd-13bd-4336-920a-057b25bbcfaf +version: 1 +date: '2021-12-07' +author: Patrick Bareiss, Splunk +type: Anomaly +datamodel: +- Endpoint_Filesystem +description: This detection detects a high amount of file deletions in a short time + for specific file types. This can be an indicator for a malicious insider. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval action=ucast(map_get(input_event, "action"), "string", + null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, + "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), + "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", + null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) + | where "Endpoint_Filesystem" IN(_datamodels) | where action="deleted" | where like(file_name, + "%.cmd") OR like(file_name, "%.ini") OR like(file_name, "%.gif") OR like(file_name, + "%.jpg") OR like(file_name, "%.jpeg") OR like(file_name, "%.db") OR like(file_name, + "%.doc%") OR like(file_name, "%.ps1") OR like(file_name, "%.xls%") OR like(file_name, + "%.ppt%") OR like(file_name, "%.bmp") OR like(file_name, "%.zip") OR like(file_name, + "%.rar") OR like(file_name, "%.7z") OR like(file_name, "%.chm") OR like(file_name, + "%.png") OR like(file_name, "%.log") OR like(file_name, "%.vbs") OR like(file_name, + "%.js") | stats count(file_name) AS count BY dest_user_id, dest_device_id, span(timestamp, + 10m) | where count > 20 | eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, + dest_device_id), body=create_map(["count", count]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Filesytem` node. +known_false_positives: user may delete bunch of pictures or files in a folder. +references: +- https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html +- https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html +tags: + analytic_story: + - Clop Ransomware + confidence: 80 + context: + - Source:Endpoint + - Stage:Execution + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_deletions/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: High frequency file deletion activity detected on host $Computer$ + mitre_attack_id: + - T1485 + observable: + - name: user + type: User + role: + - Victim + - name: Computer + type: Endpoint + role: + - Victim + - name: deleted_files + type: File Name + role: + - Target + product: + - Splunk Behavioral Analytics + required_fields: + - action + - process + - file_name + - file_path + risk_score: 72 + security_domain: endpoint diff --git a/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml b/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml index 4ca2240a8f..944c08e1bf 100644 --- a/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml +++ b/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml @@ -1,16 +1,16 @@ name: Modify ACLs Permission Of Files Or Folders id: 9ae9a48a-cdbe-11eb-875a-acde48001122 -version: 1 -date: '2021-06-15' +version: 2 +date: '2021-11-30' author: Teoderick Contreras, Splunk type: Anomaly datamodel: -- Endpoint +- Endpoint_Processes description: This analytic identifies suspicious modification of ACL permission to a files or folder to make it available to everyone or to a specific user. This technique may be used by the adversary to evade ACLs or protected files access. This changes is commonly configured by the file or directory owner with appropriate permission. - This behavior is a good indicator if this command seen on a machine utilized by + This behavior raises suspicion if this command is seen on an endpoint utilized by an account with no permission to do so. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", @@ -29,7 +29,7 @@ how_to_implement: To successfully implement this search, you need to be ingestin logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed cacls.exe may be used. -known_false_positives: network administrator may use this windows utility. filter +known_false_positives: System administrators may use this windows utility. filter is needed. references: - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ @@ -74,6 +74,7 @@ tags: - process_path - dest_user_id - process + - cmd_line risk_score: 35 risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml b/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml index 3c20b25cdb..0be577e79f 100644 --- a/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml +++ b/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml @@ -1,36 +1,41 @@ name: Detect Prohibited Applications Spawning cmd exe id: c10a18cb-fd80-4ffa-a844-25026e0a0c94 version: 2 -date: '2021-11-10' +date: '2020-11-10' author: Ignacio Bermudez Corrales, Splunk type: Anomaly -datamodel: [] -description: 'The following analytic identifies parent processes, browsers, Windows terminal applications, Office Products and Java spawning cmd.exe. By its very nature, many applications spawn cmd.exe natively or built into macros. Much of this will need to be tuned to further enhance the risk. -During triage, review parallel process execution and identify any file modifications that may have occurred. Capture any artifacts and review further.' +datamodel: +- Endpoint_Processes +description: The following analytic identifies parent processes, browsers, Windows + terminal applications, Office Products and Java spawning cmd.exe. By its very nature, + many applications spawn cmd.exe natively or built into macros. Much of this will + need to be tuned to further enhance the risk. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) | eval process_name=ucast(map_get(input_event, "process_name"), "string", null), parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", - null)), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), - dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) - - | where process_name="cmd.exe" | rex field=parent_process "(?[^\\\\]+)$" - | where field0="winword.exe" OR field0="excel.exe" OR field0="outlook.exe" OR field0="powerpnt.exe" - OR field0="visio.exe" OR field0="mspub.exe" OR field0="acrobat.exe" OR field0="acrord32.exe" - OR field0="chrome.exe" OR field0="iexplore.exe" OR field0="opera.exe" OR field0="firefox.exe" - OR field0="java.exe" OR field0="powershell.exe" - + null)), cmd_line=lower(ucast(map_get(input_event, "process"),"string", null)), dest_user_id=ucast(map_get(input_event, + "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), + "string", null), event_id=ucast(map_get(input_event,"event_id"), "string", null) + | where process_name="cmd.exe" | rex field=parent_process "(?[^\\\\]+)$" + | where ParentBaseFileName="winword.exe" OR ParentBaseFileName="excel.exe" OR ParentBaseFileName="outlook.exe" + OR ParentBaseFileName="powerpnt.exe" OR ParentBaseFileName="visio.exe" OR ParentBaseFileName="mspub.exe" + OR ParentBaseFileName="acrobat.exe" OR ParentBaseFileName="acrord32.exe" OR ParentBaseFileName="iexplore.exe" + OR ParentBaseFileName="opera.exe" OR ParentBaseFileName="firefox.exe" OR (ParentBaseFileName="java.exe" + AND (cmd_line IS NULL OR (cmd_line IS NOT NULL AND NOT like(cmd_line, "%patch1-Hotfix1a%")))) + OR ParentBaseFileName="powershell.exe" OR (ParentBaseFileName="chrome.exe" AND (cmd_line + IS NULL OR (cmd_line IS NOT NULL AND NOT like(cmd_line, "%chrome-extension%")))) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", event_id, "process_name", process_name, - "parent_process_name", parent_process]) | into write_ssa_detected_events();' -how_to_implement: In order to successfully implement this analytic, you will need endpoint process data from a EDR product or Sysmon. This search has been modified + "parent_process_name", parent_process, "cmd_line", cmd_line]) | into write_ssa_detected_events();' +how_to_implement: In order to successfully implement this analytic, you will need + endpoint process data from a EDR product or Sysmon. This search has been modified to process raw sysmon data from attack_range's nxlogs on DSP. known_false_positives: There are circumstances where an application may legitimately - execute and interact with the Windows command-line interface. + execute and interact with the Windows command-line interface. references: - - https://attack.mitre.org/techniques/T1059/ +- https://attack.mitre.org/techniques/T1059/ tags: analytic_story: - Suspicious Command-Line Executions @@ -43,7 +48,9 @@ tags: impact: 70 kill_chain_phases: - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event that warrants investigating. + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event + that warrants investigating. mitre_attack_id: - T1059 nist: @@ -74,6 +81,7 @@ tags: - _time - dest_device_id - dest_user_id + - cmd_line risk_score: 35 risk_severity: low - security_domain: endpoint \ No newline at end of file + security_domain: endpoint diff --git a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml index 9559097edf..2f0e28df62 100644 --- a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml +++ b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml @@ -1,21 +1,23 @@ name: Potential Pass the Token or Hash Observed at the Destination Device id: 82e76b80-5cdb-4899-9b43-85dbe777b36d -version: 2 -date: '2021-11-05' +version: 3 +date: '2021-11-30' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Authentication description: This detection identifies potential Pass the Token or Pass the Hash credential - exploits. We detect the main side effect of these attacks, which is a transition + stealing. We detect the main side effect of these attacks, which is a transition from the dominant Kerberos logins to rare NTLM logins for a given user, as reported by a detination device. -search: '| from read_ssa_enriched_events() | eval timestamp= parse_long(ucast(map_get(input_event, - "_time"), "string", null)), dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), - "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id= ucast(map_get(input_event, "dest_device_id"), "string", - null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", - null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), - "string", null)) +search: '| from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + dest_user=lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", + null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), + dest_device_id= ucast(map_get(input_event, "dest_device_id"), "string", null), + signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), + authentication_method= lower(ucast(map_get(input_event, "authentication_method"), + "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") AND dest_user_id != null AND dest_device_id != null @@ -32,9 +34,10 @@ search: '| from read_ssa_enriched_events() | eval timestamp= parse_long(uca (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) | eval start_time=ucast(startNTLMTime, "long", null), end_time=ucast(endNTLMTime, - "long", null), entities=mvappend(dest_user_id, dest_device_id), body=create_map(["total_kerberos", - totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", - endTime, "pth_start_time", startNTLMTime, "pth_end_time", endNTLMTime]) + "long", null), entities=mvappend(dest_user_id, dest_device_id), body=create_map(["event_id", + event_id, "total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", + startTime, "analysis_end_time", endTime, "pth_start_time", startNTLMTime, "pth_end_time", + endNTLMTime]) | into write_ssa_detected_events();' how_to_implement: You must be ingesting Windows Security logs from endpoint devices, @@ -43,9 +46,10 @@ known_false_positives: Environments in which NTLM is used extremely rarely and f benign purposes (such as a rare use of SMB shares). references: - https://attack.mitre.org/techniques/T1550/002/ +- https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/ tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement asset_type: Windows cis20: - CIS 16 diff --git a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml index e97575e56e..51f2eff5e9 100644 --- a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml +++ b/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml @@ -4,20 +4,22 @@ version: 2 date: '2021-11-05' author: Stanislav Miskovic, Splunk type: TTP -datamodel: [] +datamodel: +- Authentication description: This detection identifies potential Pass the Token or Pass the Hash credential - exploits. We detect the main side effect of these attacks, which is a transition + stealing. We detect the main side effect of these attacks, which is a transition from the dominant Kerberos logins to rare NTLM logins for a given user, as reported by an event-collecting device (i.e., a specific domain controller or an endpoint destination). -search: '| from read_ssa_enriched_events() | eval timestamp= parse_long(ucast(map_get(input_event, - "_time"), "string", null)), dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), +search: '| from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), origin_device_id= ucast(map_get(input_event, "origin_device_id"), "string", null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), - "string", null)) - + "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") AND dest_user_id != null AND origin_device_id != null @@ -33,9 +35,9 @@ search: '| from read_ssa_enriched_events() | eval timestamp= parse_long(uca (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) | eval start_time=startNTLMTime, end_time=endNTLMTime, entities=mvappend(dest_user_id, - origin_device_id), body=create_map(["total_kerberos", totalKerberos, "total_ntlm", - totalNtlm, "analysis_start_time", startTime, "analysis_end_time", endTime, "detection_start_time", - startNTLMTime, "detection_end_time", endNTLMTime]) + origin_device_id), body=create_map(["event_id", event_id, "total_kerberos", totalKerberos, + "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", + endTime, "detection_start_time", startNTLMTime, "detection_end_time", endNTLMTime]) | into write_ssa_detected_events();' how_to_implement: You must be ingesting Windows Security logs from devices of interest @@ -45,9 +47,10 @@ known_false_positives: Environments in which NTLM is used extremely rarely and f benign purposes (such as a rare use of SMB shares). references: - https://attack.mitre.org/techniques/T1550/002/ +- https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/ tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement asset_type: Windows cis20: - CIS 16 diff --git a/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml b/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml index 825ce7954e..7a55f59651 100644 --- a/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml +++ b/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml @@ -1,14 +1,15 @@ name: Rare Parent-Child Process Relationship id: cf090c78-bcc6-11eb-8529-0242ac130003 -version: 1 -date: '2021-05-20' +version: 2 +date: '2021-11-30' author: Peter Gael, Splunk; Ignacio Bermudez Corrales, Splunk type: Anomaly -datamodel: [] +datamodel: +- Endpoint_Processes description: An attacker may use LOLBAS tools spawned from vulnerable applications - not typically used by system administrators. This search leverages the Splunk Streaming - ML DSP plugin to find rare parent/child relationships. The list of application has - been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries + not typically used by system administrators. This analytic leverages the Splunk + Streaming ML DSP plugin to find rare parent/child relationships. The list of application + has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) | eval parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", null)), parent_process_name=mvindex(split(parent_process, @@ -51,12 +52,11 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map "input", input, "mean", mean, "variance", variance, "output", output, "cmd_line", cmd_line]) | into write_ssa_detected_events();' how_to_implement: Collect endpoint data such as sysmon or 4688 events. -known_false_positives: 'Some custom tools used by admins could be used rarely to launch - remotely applications. This might trigger false positives at the beginning when - it hasn''t collected yet enough data to construct the baseline. - - ' -references: [] +known_false_positives: Some custom tools used by administrators could be used rarely + to launch remotely applications. This might trigger false positives at the beginning + when it has not collected yet enough data to construct the baseline. +references: +- https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries tags: analytic_story: - Unusual Processes @@ -81,5 +81,6 @@ tags: - _time - dest_device_id - dest_user_id + - cmd_line risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___resize_shadowstorage_volume.yml b/detections/endpoint/ssa___resize_shadowstorage_volume.yml index df3b78a776..1ee19a2616 100644 --- a/detections/endpoint/ssa___resize_shadowstorage_volume.yml +++ b/detections/endpoint/ssa___resize_shadowstorage_volume.yml @@ -1,17 +1,15 @@ name: Resize Shadowstorage Volume id: dbc30554-d27e-11eb-9e5e-acde48001122 -version: 2 -date: '2021-06-21' +version: 3 +date: '2021-11-30' author: Teoderick Contreras, Splunk type: TTP datamodel: -- Endpoint -description: The following analytics identifies the resizing of shadowstorage by ransomware - malware to avoid the shadow volumes being made again. this technique is an alternative - by ransomware attacker than deleting the shadowstorage which is known alert in defensive - team. one example of ransomware that use this technique is CLOP ransomware where - it drops a .bat file that will resize the shadowstorage to minimum size as much - as possible +- Endpoint_Processes +description: The following analytic identifies the resizing of shadowstorage using + vssadmin.exe to avoid the shadow volumes being made again. This technique is typically + found used by adversaries during a ransomware event and a precursor to deleting + the shadowstorage. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), @@ -29,7 +27,8 @@ how_to_implement: To successfully implement this search, you need to be ingestin logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -known_false_positives: network admin can resize the shadowstorage for valid purposes. +known_false_positives: System administrators may resize the shadowstorage for valid + purposes. Filter as needed. references: - https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html @@ -40,15 +39,40 @@ tags: cis20: - CIS 10 - CIS 13 + confidence: 80 + context: + - Source:Endpoint + - stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log + impact: 80 kill_chain_phases: - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow + copy to perform offline password cracking. mitre_attack_id: - T1489 nist: - PR.DS - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process product: - Splunk Behavioral Analytics required_fields: @@ -59,5 +83,7 @@ tags: - process_path - dest_user_id - process + - cmd_line + risk_score: 64 risk_severity: high security_domain: endpoint diff --git a/detections/endpoint/ssa___sdelete_application_execution.yml b/detections/endpoint/ssa___sdelete_application_execution.yml index d86c3b6f60..66a706b8d0 100644 --- a/detections/endpoint/ssa___sdelete_application_execution.yml +++ b/detections/endpoint/ssa___sdelete_application_execution.yml @@ -5,30 +5,34 @@ date: '2021-11-15' author: Teoderick Contreras, Splunk type: Anomaly datamodel: -- Endpoint -description: This analytic will detect the execution of sdelete.exe attempting to delete potentially important files - that may related to adversary or insider threats to destroy evidence or information sabotage. Sdelete is a SysInternals utility - meant to securely delete files on disk. This tool is commonly used to clear tracks and artifact on the targeted host. -search: '| from read_ssa_enriched_events() - | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), "string", null)), - cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), - process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), - process_path=ucast(map_get(input_event, "process_path"), "string", null), - parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), - parent_cmd_line=ucast(map_get(input_event, "parent_process"), "string", null), - event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND like(process_name, "%sdelete%") - AND (like (cmd_line, "%-c %") OR like (cmd_line, "%-f %")OR like (cmd_line, "%-p %") OR like (cmd_line, "%-r %") OR like (cmd_line, "%-q %") - OR like (cmd_line, "%-s %") OR like (cmd_line, "%-z %") OR like (cmd_line, "%/accepteula%") - OR like (cmd_line, "%-nobanner%")OR like (cmd_line, "%.doc%")OR like (cmd_line, "%.xls%") - OR like (cmd_line, "%.ppt%")OR like (cmd_line, "%.rtf%") OR like (cmd_line, "%.pdf%") - OR like (cmd_line, "%.key%")OR like (cmd_line, "%.log%") OR like (cmd_line, "%.txt%") - OR like (cmd_line, "%.jpg%") OR like (cmd_line, "%.png%") OR like (cmd_line, "%.gif%") - OR like (cmd_line, "%.bmp%") OR like (cmd_line, "%.7z%") OR like (cmd_line, "%.zip%") - OR like (cmd_line, "%.rar%") OR like (cmd_line, "%.tar%") OR like (cmd_line, "%.gz%") OR like (cmd_line, "%.xls%")) - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "process_path", process_path, "parent_process_name", parent_process_name, "parent_cmd_line", parent_cmd_line]) - | into write_ssa_detected_events();' +- Endpoint_Processes +description: This analytic will detect the execution of sdelete.exe attempting to + delete potentially important files that may related to adversary or insider threats + to destroy evidence or information sabotage. Sdelete is a SysInternals utility meant + to securely delete files on disk. This tool is commonly used to clear tracks and + artifact on the targeted host. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), + "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), + parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), parent_cmd_line=ucast(map_get(input_event, "parent_process"), "string", null), + event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line + IS NOT NULL AND process_name IS NOT NULL AND like(process_name, "%sdelete%") AND + (like (cmd_line, "%-c %") OR like (cmd_line, "%-f %")OR like (cmd_line, "%-p %") + OR like (cmd_line, "%-r %") OR like (cmd_line, "%-q %") OR like (cmd_line, "%-s + %") OR like (cmd_line, "%-z %") OR like (cmd_line, "%/accepteula%") OR like (cmd_line, + "%-nobanner%")OR like (cmd_line, "%.doc%")OR like (cmd_line, "%.xls%") OR like (cmd_line, + "%.ppt%")OR like (cmd_line, "%.rtf%") OR like (cmd_line, "%.pdf%") OR like (cmd_line, + "%.key%")OR like (cmd_line, "%.log%") OR like (cmd_line, "%.txt%") OR like (cmd_line, + "%.jpg%") OR like (cmd_line, "%.png%") OR like (cmd_line, "%.gif%") OR like (cmd_line, + "%.bmp%") OR like (cmd_line, "%.7z%") OR like (cmd_line, "%.zip%") OR like (cmd_line, + "%.rar%") OR like (cmd_line, "%.tar%") OR like (cmd_line, "%.gz%") OR like (cmd_line, + "%.xls%")) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "process_path", process_path, "parent_process_name", parent_process_name, + "parent_cmd_line", parent_cmd_line]) | into write_ssa_detected_events();' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, @@ -36,19 +40,43 @@ how_to_implement: To successfully implement this search you need to be ingesting endpoint product. known_false_positives: False positives should be limited, filter as needed. references: - - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.md +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.md tags: analytic_story: - Information Sabotage + confidence: 70 + context: + - Source:Endpoint + - Stage:Execution dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log + impact: 60 kill_chain_phases: - Exploitation + message: Sdelete process $process_name$ executed on $dest_device_id$ attempting + to permanently delete files by $dest_user_id$. mitre_attack_id: - T1485 - T1070.004 - T1070 + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process product: - Splunk Behavioral Analytics required_fields: @@ -61,26 +89,6 @@ tags: - process - process_id - process_path - security_domain: endpoint - impact: 60 - confidence: 70 - # (impact * confidence)/100 + - cmd_line risk_score: 42 - context: - - Source:Endpoint - - Stage:Execution - message: sdelete process $process_name$ executed on $dest$ attempting to permanently delete files. - observable: - - name: dest - type: Endpoint - role: - - Victim - - name: user - type: User - role: - - Victim - - name: process_name - type: Process - role: - - Child Process - \ No newline at end of file + security_domain: endpoint diff --git a/detections/endpoint/ssa___system_process_running_unexpected_location.yml b/detections/endpoint/ssa___system_process_running_unexpected_location.yml index dc69941b24..3c49c33a0d 100644 --- a/detections/endpoint/ssa___system_process_running_unexpected_location.yml +++ b/detections/endpoint/ssa___system_process_running_unexpected_location.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-08-25' author: Ignacio Bermudez Corrales, Splunk type: Anomaly -datamodel: [] +datamodel: +- Endpoint_Processes description: An attacker tries might try to use different version of a system command without overriding original, or they might try to avoid some detection running the process from a different folder. This detection checks that a list of system processes diff --git a/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml b/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml index 63ec825a35..c27912632d 100644 --- a/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml +++ b/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-08-25' author: Ignacio Bermudez Corrales, Splunk type: Anomaly -datamodel: [] +datamodel: +- Endpoint_Processes description: Attacker activity may compromise executing several LOLBAS applications in conjunction to accomplish their objectives. We are looking for more than usual LOLBAS applications over a window of time, by building profiles per machine. diff --git a/detections/endpoint/ssa___unusually_long_command_line.yml b/detections/endpoint/ssa___unusually_long_command_line.yml index 7f48539c86..79847f633f 100644 --- a/detections/endpoint/ssa___unusually_long_command_line.yml +++ b/detections/endpoint/ssa___unusually_long_command_line.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-06' author: Ignacio Bermudez Corrales, Splunk type: Anomaly -datamodel: [] +datamodel: +- Endpoint_Processes description: Command lines that are extremely long may be indicative of malicious activity on your hosts. This search leverages the Splunk Streaming ML DSP plugin to help identify command lines with lengths that are unusual for a given user. This diff --git a/detections/endpoint/ssa___wbadmin_delete_system_backups.yml b/detections/endpoint/ssa___wbadmin_delete_system_backups.yml new file mode 100644 index 0000000000..424b7dc49a --- /dev/null +++ b/detections/endpoint/ssa___wbadmin_delete_system_backups.yml @@ -0,0 +1,86 @@ +name: WBAdmin Delete System Backups +id: 71efbf52-4dbb-4c00-a520-306aa546cbb7 +version: 1 +date: '2021-12-07' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This search looks for flags passed to wbadmin.exe (Windows Backup Administrator + Tool) that delete backup files. This is typically used by ransomware to prevent + recovery. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="wbadmin.exe" + AND like (cmd_line, "%delete%") OR like (cmd_line, "%catalog%") OR like (cmd_line, + "%systemstatebackup%") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +known_false_positives: Administrators may modify the boot configuration. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md +- https://thedfirreport.com/2020/10/08/ryuks-return/ +- https://attack.mitre.org/techniques/T1490/ +- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin +tags: + analytic_story: + - Ryuk Ransomware + - Ransomware + cis20: + - CIS 8 + confidence: 50 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: [] + impact: 30 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system + backups. + mitre_attack_id: + - T1490 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 15 + risk_severity: high + security_domain: endpoint diff --git a/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml b/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml index 0ff21233b6..4f556bdf5d 100644 --- a/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml +++ b/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml @@ -5,24 +5,25 @@ date: '2021-06-15' author: Teoderick Contreras, Splunk type: TTP datamodel: -- Endpoint +- Endpoint_Processes description: The wevtutil.exe application is the windows event log utility. This searches for wevtutil.exe with parameters for clearing the application, security, setup, powershell, sysmon, or system event logs. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), process_name=ucast(map_get(input_event, "process_name"), "string", null), - process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, - "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line IS NOT NULL AND like(cmd_line, "% cl %") AND (match_regex(cmd_line, +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND like(cmd_line, "% cl %") AND (match_regex(cmd_line, /(?i)security/)=true OR match_regex(cmd_line, /(?i)system/)=true OR match_regex(cmd_line, /(?i)sysmon/)=true OR match_regex(cmd_line, /(?i)application/)=true OR match_regex(cmd_line, /(?i)setup/)=true OR match_regex(cmd_line, /(?i)powershell/)=true) AND process_name="wevtutil.exe" | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' + "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, + "process_name", process_name, "parent_process_name", parent_process_name, "process_path", + process_path]) | into write_ssa_detected_events();' how_to_implement: You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. diff --git a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml index cd77f947a9..f16d61ebc4 100644 --- a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml +++ b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml @@ -5,20 +5,21 @@ date: '2021-06-15' author: Teoderick Contreras, Splunk type: TTP datamodel: -- Endpoint +- Endpoint_Processes description: This search is to detect execution of wevtutil.exe to disable logs. This technique was seen in several ransomware to disable the event logs to evade alerts and detections in compromised host. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), process_name=ucast(map_get(input_event, "process_name"), "string", null), - process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, - "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line IS NOT NULL AND like(cmd_line, "% sl %") AND like(cmd_line, - "%/e:false%") AND process_name="wevtutil.exe" | eval start_time=timestamp, end_time=timestamp, +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND like(cmd_line, "% sl %") AND like(cmd_line, "%/e:false%") + AND process_name="wevtutil.exe" | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, - "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", - cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, + "dest_device_id"), "string", null)) | eval body=create_map(["event_id", event_id, + "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' how_to_implement: You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be diff --git a/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml b/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml new file mode 100644 index 0000000000..64d3c29009 --- /dev/null +++ b/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml @@ -0,0 +1,99 @@ +name: Windows Curl Upload to Remote Destination +id: cc8d046a-543b-11ec-b864-acde48001122 +version: 1 +date: '2021-12-03' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: 'The following analytic identifies the use of Windows Curl.exe uploading + a file to a remote destination. \ + + `-T` or `--upload-file` is used when a file is to be uploaded to a remotge destination. + \ + + `-d` or `--data` POST is the HTTP method that was invented to send data to a receiving + web application, and it is, for example, how most common HTML forms on the web work. + \ + + HTTP multipart formposts are done with `-F`, but this appears to not be compatible + with the Windows version of Curl. Will update if identified adversary tradecraft. + \ + + Adversaries may use one of the three methods based on the remote destination and + what they are attempting to upload (zip vs txt). During triage, review parallel + processes for further behavior. In addition, identify if the upload was successful + in network logs. If a file was uploaded, isolate the endpoint and review.' +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + + | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="curl.exe" + AND (like (cmd_line, "%-T %") OR like (cmd_line, "%--upload-file %")OR like (cmd_line, + "%-d %") OR like (cmd_line, "%--data %") OR like (cmd_line, "%-F %")) + + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, + "process_name", process_name, "parent_process_name", parent_process_name, "process_path", + process_path]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +known_false_positives: False positives may be limited to source control applications + and may be required to be filtered out. +references: +- https://everything.curl.dev/usingcurl/uploads +- https://techcommunity.microsoft.com/t5/containers/tar-and-curl-come-to-windows/ba-p/382409 +- https://twitter.com/d1r4c/status/1279042657508081664?s=20 +tags: + analytic_story: + - Ingress Tool Transfer + automated_detection_testing: passed + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log + impact: 80 + kill_chain_phases: + - Exfiltration + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote + destination. + mitre_attack_id: + - T1105 + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 80 + security_domain: endpoint diff --git a/detections/endpoint/start_up_during_safe_mode_boot.yml b/detections/endpoint/start_up_during_safe_mode_boot.yml index 3b9a982235..7221f234df 100644 --- a/detections/endpoint/start_up_during_safe_mode_boot.yml +++ b/detections/endpoint/start_up_during_safe_mode_boot.yml @@ -59,6 +59,6 @@ tags: - Registry.dest risk_score: 42 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index a3e71a37f0..50c468f624 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -79,6 +79,6 @@ tags: - Processes.user risk_score: 40 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml index 5531d26ba7..c068e541e1 100644 --- a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml +++ b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml @@ -29,13 +29,29 @@ references: tags: analytic_story: - Remcos + automated_detection_testing: passed + confidence: 80 + context: + - Source:Endpoint + - Stage:Execution dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_pastebin_download/sysmon.log + impact: 80 kill_chain_phases: - Exploitation + message: suspicious process $process_name$ has a dns query in $QueryName$ on $Computer$ mitre_attack_id: - T1059.005 - T1059 + observable: + - name: Computer + type: Hostname + role: + - Victim + - name: process_name + type: process name + role: + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security @@ -48,21 +64,5 @@ tags: - process_name - QueryResults - Computer - security_domain: endpoint - impact: 80 - confidence: 80 risk_score: 64 - context: - - Source:Endpoint - - Stage:Execution - message: suspicious process $process_name$ has a dns query in $QueryName$ on $Computer$ - observable: - - name: Computer - type: Hostname - role: - - Victim - - name: process_name - type: process name - role: - - Attacker - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index f6067ee1a8..726fbc4664 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -72,6 +72,6 @@ tags: - Processes.user risk_score: 35 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index 70fc81d7dd..d245184887 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -78,7 +78,7 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index 567be79aab..5c7bf0a49b 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -73,6 +73,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index 9446d60e10..2cd0a8901e 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -77,7 +77,7 @@ tags: - Processes.user risk_score: 28 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/svchost_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/svchost_exe_lolbas_execution_process_spawn.yml new file mode 100644 index 0000000000..e4ff7baa92 --- /dev/null +++ b/detections/endpoint/svchost_exe_lolbas_execution_process_spawn.yml @@ -0,0 +1,80 @@ +name: Svchost LOLBAS Execution Process Spawn +id: 09e5c72a-4c0d-11ec-aa29-3e22fbd008af +version: 1 +date: '2021-11-22' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies `svchost.exe` spawning a LOLBAS execution + process. When adversaries execute code on remote endpoints abusing the Task Scheduler + and creating a malicious remote scheduled task, the executed command is spawned + as a child process of `svchost.exe`. The LOLBAS project documents Windows native + binaries that can be abused by threat actors to perform tasks like executing malicious + code. Looking for child processes of svchost.exe that are part of the LOLBAS project + can help defenders identify lateral movement activity. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=svchost.exe) + (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", + "Rasautou.exe", "Schtasks.exe", "Xwizard.exe", "Pnputil.exe", "Atbroker.exe", "Pcwrun.exe", + "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe", "Certoc.exe", "Ieexec.exe", "Microsoft.Workflow.Compiler.exe", + "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe", "Register-cimprovider.exe", + "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe", "SettingSyncHost.exe", "Cmstp.exe", + "Stordiag.exe", "Scriptrunner.exe", "Odbcconf.exe", "Extexport.exe", "Msdt.exe", + "WorkFolders.exe", "Diskshadow.exe", "Mavinject.exe", "Regasm.exe", "Gpscript.exe", + "Regsvr32.exe", "Msiexec.exe", "Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", + "Runonce.exe", "Syncappvpublishingserver.exe", "Verclsid.exe", "Infdefaultinstall.exe", + "Installutil.exe", "Netsh.exe", "Wab.exe", "Dnscmd.exe", "At.exe", "Pcalua.exe", + "Msconfig.exe")) by Processes.dest Processes.user Processes.parent_process Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `svchost_lolbas_execution_process_spawn_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. +known_false_positives: Legitimate applications may trigger this behavior, filter as + needed. +references: +- https://attack.mitre.org/techniques/T1053/005/ +- https://www.ired.team/offensive-security/persistence/t1053-schtask +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/lateral_movement_lolbas/windows-security.log + impact: 90 + kill_chain_phases: + - Lateral Movement + message: Svchost.exe spawned a LOLBAS process on $dest + mitre_attack_id: + - T1053 + - T1053.005 + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 54 + security_domain: endpoint diff --git a/detections/endpoint/system_info_gathering_using_dxdiag_application.yml b/detections/endpoint/system_info_gathering_using_dxdiag_application.yml new file mode 100644 index 0000000000..8c2ceb7026 --- /dev/null +++ b/detections/endpoint/system_info_gathering_using_dxdiag_application.yml @@ -0,0 +1,73 @@ +name: System Info Gathering Using Dxdiag Application +id: f92d74f2-4921-11ec-b685-acde48001122 +version: 1 +date: '2021-11-19' +author: Teoderick Contreras, Splunk +type: Hunting +datamodel: +- Endpoint +description: This analytic is to detect a suspicious dxdiag.exe process commandline + can collect system info of the target host. This technique was seen in remcos, adversaries + and other malware to collect information as part of recon or collection phase of + attack. Even this behavior is rarely seen in a corporate network this commandline + can be used by network administrator to audit host machine specification. Better + to check what it did after it pipes out the result to a file for further processing. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_dxdiag` AND Processes.process + = "* /t *" by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `system_info_gathering_using_dxdiag_application_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` + node. In addition, confirm the latest CIM App 4.20 or higher is installed and the + latest TA for the endpoint product. +known_false_positives: this commandline can be used by network administrator to audit + host machine specification.filter is needed. +references: +- https://app.any.run/tasks/df0baf9f-8baf-4c32-a452-16562ecb19be/ +tags: + analytic_story: + - Remcos + automated_detection_testing: passed + confidence: 50 + context: + - source:endpoint + - stage:Reconnaissance + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1592/host_info_dxdiag/sysmon.log + impact: 50 + kill_chain_phases: + - Reconnaissance + message: dxdiag.exe process with commandline $process$ on $dest$ + mitre_attack_id: + - T1592 + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 25 + security_domain: endpoint diff --git a/detections/endpoint/system_information_discovery_detection.yml b/detections/endpoint/system_information_discovery_detection.yml index 9713ae4a3a..4448f1972b 100644 --- a/detections/endpoint/system_information_discovery_detection.yml +++ b/detections/endpoint/system_information_discovery_detection.yml @@ -66,7 +66,7 @@ tags: - Processes.dest risk_score: 15 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index e02f6ccab4..9ce0208ecf 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -82,7 +82,7 @@ tags: - Processes.process_hash risk_score: 49 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml index 00a42c0dc4..5f64813caa 100644 --- a/detections/endpoint/time_provider_persistence_registry.yml +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -67,6 +67,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/unified_messaging_service_spawning_a_process.yml b/detections/endpoint/unified_messaging_service_spawning_a_process.yml index fb7c90a9dd..1726cd5cf6 100644 --- a/detections/endpoint/unified_messaging_service_spawning_a_process.yml +++ b/detections/endpoint/unified_messaging_service_spawning_a_process.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/uninstall_app_using_msiexec.yml b/detections/endpoint/uninstall_app_using_msiexec.yml index a59f0d1633..d6f01d390a 100644 --- a/detections/endpoint/uninstall_app_using_msiexec.yml +++ b/detections/endpoint/uninstall_app_using_msiexec.yml @@ -65,6 +65,6 @@ tags: - Processes.parent_process_id risk_score: 30 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index a465998c71..1d0a956510 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -65,7 +65,7 @@ tags: - Processes.user risk_score: 45 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/usn_journal_deletion.yml b/detections/endpoint/usn_journal_deletion.yml index d125cb69e3..ca9e6d9bef 100644 --- a/detections/endpoint/usn_journal_deletion.yml +++ b/detections/endpoint/usn_journal_deletion.yml @@ -70,6 +70,6 @@ tags: - Processes.dest risk_score: 45 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/wbadmin_delete_system_backups.yml b/detections/endpoint/wbadmin_delete_system_backups.yml index 2f5add7e12..a7013ed7d7 100644 --- a/detections/endpoint/wbadmin_delete_system_backups.yml +++ b/detections/endpoint/wbadmin_delete_system_backups.yml @@ -64,7 +64,7 @@ tags: - Processes.user risk_score: 15 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/wget_download_and_bash_execution.yml b/detections/endpoint/wget_download_and_bash_execution.yml new file mode 100644 index 0000000000..19fc18ddc7 --- /dev/null +++ b/detections/endpoint/wget_download_and_bash_execution.yml @@ -0,0 +1,83 @@ +name: Wget Download and Bash Execution +id: 35682718-5a85-11ec-b8f7-acde48001122 +version: 1 +date: '2021-12-11' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies the use of wget on Linux or MacOS attempting + to download a file from a remote source and pipe it to bash. This is typically found + with coinminers and most recently with CVE-2021-44228, a vulnerability in Log4j. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wget + (Processes.process="*-q *" OR Processes.process="*--quiet*" AND Processes.process="*-O- + *") OR (Processes.process="*|*" AND Processes.process="*bash*") by Processes.dest + Processes.user Processes.parent_process_name Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `wget_download_and_bash_execution_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon for Linux, you will need to ensure mapping is + occurring correctly. If the EDR is not parsing the pipe bash in the command-line, + modifying the analytic will be required. Add parent process name (Processes.parent_process_name) + as needed to filter. +known_false_positives: False positives should be limited, however filtering may be + required. +references: +- https://www.huntress.com/blog/rapid-response-critical-rce-vulnerability-is-affecting-java +- https://www.lunasec.io/docs/blog/log4j-zero-day/ +- https://gist.github.com/nathanqthai/01808c569903f41a52e7e7b575caa890 +tags: + analytic_story: + - Ingress Tool Transfer + - Log4Shell CVE-2021-44228 + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + cve: + - CVE-2021-44228 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/linux-sysmon_curlwget.log + impact: 80 + kill_chain_phases: + - Exploitation + message: An instance of $process_name$ was identified on endpoint $dest$ attempting + to download a remote file and run it with bash. + mitre_attack_id: + - T1105 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 80 + security_domain: endpoint + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/windows_adfind_exe.yml b/detections/endpoint/windows_adfind_exe.yml index 90fa0367a7..494d1774c2 100644 --- a/detections/endpoint/windows_adfind_exe.yml +++ b/detections/endpoint/windows_adfind_exe.yml @@ -58,6 +58,6 @@ tags: - Processes.process_id - Processes.parent_process_id security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index 9b56376649..f8c22e9a38 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -36,38 +36,20 @@ tags: analytic_story: - IceID - Ingress Tool Transfer - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl.log - kill_chain_phases: - - Exploitation - mitre_attack_id: - - T1105 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.parent_process - - Processes.original_file_name - - Processes.process_name - - Processes.process - - Processes.process_id - - Processes.parent_process_path - - Processes.process_path - - Processes.parent_process_id - security_domain: endpoint - impact: 80 + automated_detection_testing: passed confidence: 100 - risk_score: 80 context: - Source:Endpoint - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl.log + impact: 80 + kill_chain_phases: + - Exploitation message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ to download a file to a suspicious directory. + mitre_attack_id: + - T1105 observable: - name: user type: User @@ -85,4 +67,22 @@ tags: type: Process role: - Child Process - automated_detection_testing: passed + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 80 + security_domain: endpoint diff --git a/detections/endpoint/windows_curl_upload_to_remote_destination.yml b/detections/endpoint/windows_curl_upload_to_remote_destination.yml index 95d092ccba..29a94ae877 100644 --- a/detections/endpoint/windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/windows_curl_upload_to_remote_destination.yml @@ -44,38 +44,20 @@ references: tags: analytic_story: - Ingress Tool Transfer - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl_upload.log - kill_chain_phases: - - Exfiltration - mitre_attack_id: - - T1105 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.parent_process - - Processes.original_file_name - - Processes.process_name - - Processes.process - - Processes.process_id - - Processes.parent_process_path - - Processes.process_path - - Processes.parent_process_id - security_domain: endpoint - impact: 80 + automated_detection_testing: passed confidence: 100 - risk_score: 80 context: - Source:Endpoint - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl_upload.log + impact: 80 + kill_chain_phases: + - Exfiltration message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ uploading a file to a remote destination. + mitre_attack_id: + - T1105 observable: - name: user type: User @@ -93,4 +75,22 @@ tags: type: Process role: - Child Process - automated_detection_testing: passed + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 80 + security_domain: endpoint diff --git a/detections/endpoint/windows_defender_exclusion_registry_entry.yml b/detections/endpoint/windows_defender_exclusion_registry_entry.yml new file mode 100644 index 0000000000..c767cc7558 --- /dev/null +++ b/detections/endpoint/windows_defender_exclusion_registry_entry.yml @@ -0,0 +1,68 @@ +name: Windows Defender Exclusion Registry Entry +id: 13395a44-4dd9-11ec-9df7-acde48001122 +version: 1 +date: '2021-11-25' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic will detect a suspicious process that modify a registry + related to windows defender exclusion feature. This registry is abused by adversaries, + malware author and red teams to bypassed Windows Defender Anti-Virus product by + excluding folder path, file path, process, extensions and etc. from its real time + or schedule scan to execute their malicious code. This is a good indicator for a + defense evasion and to look further for events after this behavior. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\SOFTWARE\\Policies\\Microsoft\\Windows + Defender\\Exclusions\\*" by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` | `windows_defender_exclusion_registry_entry_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: admin or user may choose to use this windows features. +references: +- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html +- https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/ +tags: + analytic_story: + - Remcos + - Windows Defense Evasion Tactics + automated_detection_testing: passed + confidence: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/defender_exclusion_sysmon/sysmon.log + impact: 80 + kill_chain_phases: + - Exploitation + message: exclusion registry $registry_path$ modified or added on $dest$ + mitre_attack_id: + - T1562.001 + - T1562 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.registry_key_name + - Registry.registry_path + - Registry.user + - Registry.dest + - Registry.registry_value_name + - Registry.registry_value_data + risk_score: 64 + security_domain: endpoint diff --git a/detections/endpoint/windows_disableantispyware_reg.yml b/detections/endpoint/windows_disableantispyware_reg.yml index f0fdddb081..89e638c918 100644 --- a/detections/endpoint/windows_disableantispyware_reg.yml +++ b/detections/endpoint/windows_disableantispyware_reg.yml @@ -13,10 +13,10 @@ description: The search looks for the Registry Key DisableAntiSpyware set to dis registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Registry where Registry.registry_key_name="DisableAntiSpyware" - AND Registry.registry_value_name="DWORD (0x00000001)" by Registry.dest Registry.user - Registry.registry_path Registry.registry_value_name | `drop_dm_object_name(Registry)` - | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `windows_disableantispyware_registry_filter`' + as lastTime from datamodel=Endpoint.Registry where Registry.registry_value_name="DisableAntiSpyware" + AND Registry.registry_value_data="0x00000001" by Registry.dest Registry.user Registry.registry_path + Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` | `windows_disableantispyware_registry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. @@ -68,6 +68,6 @@ tags: - Registry.registry_path risk_score: 24 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/windows_diskcryptor_usage.yml b/detections/endpoint/windows_diskcryptor_usage.yml index 1786a1c3c5..930e28b5db 100644 --- a/detections/endpoint/windows_diskcryptor_usage.yml +++ b/detections/endpoint/windows_diskcryptor_usage.yml @@ -31,38 +31,20 @@ references: tags: analytic_story: - Ransomware - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/dcrypt/windows-sysmon.log - kill_chain_phases: - - Exploitation - mitre_attack_id: - - T1486 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.parent_process - - Processes.original_file_name - - Processes.process_name - - Processes.process - - Processes.process_id - - Processes.parent_process_path - - Processes.process_path - - Processes.parent_process_id - security_domain: endpoint - impact: 70 + automated_detection_testing: passed confidence: 50 - risk_score: 35 context: - Source:Endpoint - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/dcrypt/windows-sysmon.log + impact: 70 + kill_chain_phases: + - Exploitation message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to encrypt disks. + mitre_attack_id: + - T1486 observable: - name: user type: User @@ -80,4 +62,22 @@ tags: type: Process role: - Child Process - automated_detection_testing: passed + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 35 + security_domain: endpoint diff --git a/detections/endpoint/windows_installutil_credential_theft.yml b/detections/endpoint/windows_installutil_credential_theft.yml index 0cfabc008d..11b50baa38 100644 --- a/detections/endpoint/windows_installutil_credential_theft.yml +++ b/detections/endpoint/windows_installutil_credential_theft.yml @@ -36,41 +36,23 @@ references: tags: analytic_story: - Signed Binary Proxy Execution InstallUtil - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log - kill_chain_phases: - - Exploitation - - Privilege Escalation - mitre_attack_id: - - T1218.004 - - T1218 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.parent_process - - Processes.original_file_name - - Processes.process_name - - Processes.process - - Processes.process_id - - Processes.parent_process_path - - Processes.process_path - - Processes.parent_process_id - security_domain: endpoint - impact: 80 + automated_detection_testing: passed confidence: 100 - risk_score: 80 context: - Source:Endpoint - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log + impact: 80 + kill_chain_phases: + - Exploitation + - Privilege Escalation message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ loading samlib.dll and vaultcli.dll to potentially capture credentials in memory. + mitre_attack_id: + - T1218.004 + - T1218 observable: - name: user type: User @@ -88,4 +70,22 @@ tags: type: Process role: - Child Process - automated_detection_testing: passed + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 80 + security_domain: endpoint diff --git a/detections/endpoint/windows_installutil_remote_network_connection.yml b/detections/endpoint/windows_installutil_remote_network_connection.yml index b75481568c..74868751a9 100644 --- a/detections/endpoint/windows_installutil_remote_network_connection.yml +++ b/detections/endpoint/windows_installutil_remote_network_connection.yml @@ -42,14 +42,39 @@ references: tags: analytic_story: - Signed Binary Proxy Execution InstallUtil + automated_detection_testing: passed + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log + impact: 80 kill_chain_phases: - Exploitation - Privilege Escalation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$ generating a remote download. mitre_attack_id: - T1218.004 - T1218 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process product: - Splunk Enterprise - Splunk Enterprise Security @@ -70,30 +95,5 @@ tags: - Ports.process_guid - Ports.dest - Ports.dest_port - security_domain: endpoint - impact: 80 - confidence: 100 risk_score: 80 - context: - - Source:Endpoint - - Stage:Defense Evasion - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest$ by user $user$ generating a remote download. - observable: - - name: user - type: User - role: - - Victim - - name: dest - type: Hostname - role: - - Victim - - name: parent_process_name - type: Parent Process - role: - - Parent Process - - name: process_name - type: Process - role: - - Child Process - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/windows_installutil_uninstall_option.yml b/detections/endpoint/windows_installutil_uninstall_option.yml index 9e17fac379..804cb45e00 100644 --- a/detections/endpoint/windows_installutil_uninstall_option.yml +++ b/detections/endpoint/windows_installutil_uninstall_option.yml @@ -44,40 +44,22 @@ references: tags: analytic_story: - Signed Binary Proxy Execution InstallUtil - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log - kill_chain_phases: - - Exploitation - - Privilege Escalation - mitre_attack_id: - - T1218.004 - - T1218 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.parent_process - - Processes.original_file_name - - Processes.process_name - - Processes.process - - Processes.process_id - - Processes.parent_process_path - - Processes.process_path - - Processes.parent_process_id - security_domain: endpoint - impact: 80 + automated_detection_testing: passed confidence: 100 - risk_score: 80 context: - Source:Endpoint - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log + impact: 80 + kill_chain_phases: + - Exploitation + - Privilege Escalation message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ performing an uninstall. + mitre_attack_id: + - T1218.004 + - T1218 observable: - name: user type: User @@ -95,4 +77,22 @@ tags: type: Process role: - Child Process - automated_detection_testing: passed + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 80 + security_domain: endpoint diff --git a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml b/detections/endpoint/windows_installutil_uninstall_option_with_network.yml index 3e84ff76eb..039a92f7d1 100644 --- a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml +++ b/detections/endpoint/windows_installutil_uninstall_option_with_network.yml @@ -49,14 +49,39 @@ references: tags: analytic_story: - Signed Binary Proxy Execution InstallUtil + automated_detection_testing: passed + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log + impact: 80 kill_chain_phases: - Exploitation - Privilege Escalation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$ performing an uninstall. mitre_attack_id: - T1218.004 - T1218 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process product: - Splunk Enterprise - Splunk Enterprise Security @@ -77,30 +102,5 @@ tags: - Ports.process_guid - Ports.dest - Ports.dest_port - security_domain: endpoint - impact: 80 - confidence: 100 risk_score: 80 - context: - - Source:Endpoint - - Stage:Defense Evasion - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest$ by user $user$ performing an uninstall. - observable: - - name: user - type: User - role: - - Victim - - name: dest - type: Hostname - role: - - Victim - - name: parent_process_name - type: Parent Process - role: - - Parent Process - - name: process_name - type: Process - role: - - Child Process - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/windows_installutil_url_in_command_line.yml b/detections/endpoint/windows_installutil_url_in_command_line.yml index 5a0138303f..6e9e84ed39 100644 --- a/detections/endpoint/windows_installutil_url_in_command_line.yml +++ b/detections/endpoint/windows_installutil_url_in_command_line.yml @@ -40,40 +40,22 @@ references: tags: analytic_story: - Signed Binary Proxy Execution InstallUtil - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log - kill_chain_phases: - - Exploitation - - Privilege Escalation - mitre_attack_id: - - T1218.004 - - T1218 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.parent_process - - Processes.original_file_name - - Processes.process_name - - Processes.process - - Processes.process_id - - Processes.parent_process_path - - Processes.process_path - - Processes.parent_process_id - security_domain: endpoint - impact: 80 + automated_detection_testing: passed confidence: 100 - risk_score: 80 context: - Source:Endpoint - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log + impact: 80 + kill_chain_phases: + - Exploitation + - Privilege Escalation message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ passing a URL on the command-line. + mitre_attack_id: + - T1218.004 + - T1218 observable: - name: user type: User @@ -91,4 +73,22 @@ tags: type: Process role: - Child Process - automated_detection_testing: passed + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 80 + security_domain: endpoint diff --git a/detections/endpoint/create_service_in_suspicious_file_path.yml b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml similarity index 58% rename from detections/endpoint/create_service_in_suspicious_file_path.yml rename to detections/endpoint/windows_service_created_with_suspicious_service_path.yml index fc021d10ca..c3fa2d88f7 100644 --- a/detections/endpoint/create_service_in_suspicious_file_path.yml +++ b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml @@ -1,40 +1,48 @@ -name: Create Service In Suspicious File Path +name: Windows Service Created With Suspicious Service Path id: 429141be-8311-11eb-adb6-acde48001122 -version: 1 -date: '2021-03-12' -author: Teoderick Contreras +version: 2 +date: '2021-11-22' +author: Teoderick Contreras, Mauricio Velazco, Splunk type: TTP datamodel: - Endpoint -description: This detection is to identify a creation of "user mode service" where - the service file path is located in non-common service folder in windows. +description: The following analytc uses Windows Event Id 7045, `New Service Was Installed`, + to identify the creation of a Windows Service where the service binary path path + is located in a non-common Service folder in Windows. Red Teams and adversaries + alike may create malicious Services for lateral movement or remote code execution + as well as persistence and execution. The Clop ransomware has also been seen in + the wild abusing Windows services. search: ' `wineventlog_system` EventCode=7045 Service_File_Name = "*\.exe" NOT (Service_File_Name IN ("C:\\Windows\\*", "C:\\Program File*", "C:\\Programdata\\*", "%systemroot%\\*")) - Service_Type = "user mode service" | stats count min(_time) as firstTime max(_time) - as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `create_service_in_suspicious_file_path_filter`' + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name + Service_Name Service_Start_Type Service_Type | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_service_created_with_suspicious_service_path_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. -known_false_positives: unknown +known_false_positives: Legitimate applications may install services with uncommon + services paths. references: - https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html tags: analytic_story: - Clop Ransomware + - Active Directory Lateral Movement automated_detection_testing: passed confidence: 80 context: - Source:Endpoint - Stage:Privilege Escalation + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log impact: 70 kill_chain_phases: - Privilege Escalation + - Lateral Movement message: A service $Service_File_Name$ was created from a non-standard path using - $Service_Name$, potentially leading to a privilege escalation. + $Service_Name$ mitre_attack_id: - T1569 - T1569.002 diff --git a/detections/endpoint/windows_service_created_within_public_path.yml b/detections/endpoint/windows_service_created_within_public_path.yml new file mode 100644 index 0000000000..483bbb5954 --- /dev/null +++ b/detections/endpoint/windows_service_created_within_public_path.yml @@ -0,0 +1,66 @@ +name: Windows Service Created Within Public Path +id: 3abb2eda-4bb8-11ec-9ae4-3e22fbd008af +version: 1 +date: '2021-11-22' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytc uses Windows Event Id 7045, `New Service Was Installed`, + to identify the creation of a Windows Service where the service binary path is located + in public paths. This behavior could represent the installation of a malicious service. + Red Teams and adversaries alike may create malicious Services for lateral movement + or remote code execution +search: '`wineventlog_system` EventCode=7045 Service_File_Name = "*\.exe" NOT (Service_File_Name + IN ("C:\\Windows\\*", "C:\\Program File*", "C:\\Programdata\\*", "%systemroot%\\*")) + | stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode + Service_File_Name Service_Name Service_Start_Type Service_Type | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_service_created_within_public_path_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the Service name, Service File Name Service Start type, and Service Type + from your endpoints. +known_false_positives: Legitimate applications may install services with uncommon + services paths. +references: +- https://docs.microsoft.com/en-us/windows/win32/services/service-control-manager +- https://pentestlab.blog/2020/07/21/lateral-movement-services/ +tags: + analytic_story: + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_suspicious_path/windows-system.log + impact: 90 + kill_chain_phases: + - Lateral Movement + message: A Windows Service $Service_File_Name$ with a public path was created on + $ComputerName + mitre_attack_id: + - T1543 + - T1543.003 + observable: + - name: Service_File_Name + type: Other + role: + - Other + - name: ComputerName + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - EventCode + - Service_File_Name + - Service_Type + - _time + - Service_Name + - Service_Start_Type + risk_score: 54 + security_domain: endpoint diff --git a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml index ab55d5ce1e..ee54cbec60 100644 --- a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml +++ b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml @@ -28,14 +28,26 @@ references: - https://attack.mitre.org/techniques/T1543/003/ tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement/windows-sysmon.log + impact: 90 kill_chain_phases: - Lateral Movement + message: A Windows Service was created on a remote endpoint from $dest mitre_attack_id: - T1543 - T1543.003 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -53,17 +65,5 @@ tags: - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id - security_domain: endpoint - impact: 90 - confidence: 60 risk_score: 54 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: A Windows Service was created on a remote endpoint from $dest - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml index 66394e80ff..bf0a3f099e 100644 --- a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml +++ b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml @@ -26,14 +26,26 @@ references: - https://attack.mitre.org/techniques/T1543/003/ tags: analytic_story: - - Lateral Movement + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement/windows-sysmon.log + impact: 90 kill_chain_phases: - Lateral Movement + message: A Windows Service was started on a remote endpoint from $dest mitre_attack_id: - T1543 - T1543.003 + observable: + - name: dest + type: Endpoint + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -51,17 +63,5 @@ tags: - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id - security_domain: endpoint - impact: 90 - confidence: 60 risk_score: 54 - context: - - Source:Endpoint - - Stage:Lateral Movement - message: A Windows Service was started on a remote endpoint from $dest - observable: - - name: dest - type: Endpoint - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml index 0091f8b44b..ff59f2304b 100644 --- a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml +++ b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml @@ -47,7 +47,7 @@ tags: - Ransomware - Ryuk Ransomware - IcedID - - Lateral Movement + - Active Directory Lateral Movement automated_detection_testing: passed confidence: 100 context: diff --git a/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml b/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml index 4cd69afb82..8b49efca42 100644 --- a/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml +++ b/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml @@ -31,12 +31,24 @@ tags: analytic_story: - IcedID - Windows Persistence Techniques + automated_detection_testing: passed + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/windows_taskschedule/windows-taskschedule.log + impact: 80 kill_chain_phases: - Exploitation + message: A Scheduled Task was scheduled and ran on $dest$. mitre_attack_id: - T1053.005 + observable: + - name: dest + type: Hostname + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security @@ -48,17 +60,5 @@ tags: - EventID - dest - ProcessID - security_domain: endpoint - impact: 80 - confidence: 100 risk_score: 80 - context: - - Source:Endpoint - - Stage:Defense Evasion - message: A Scheduled Task was scheduled and ran on $dest$. - observable: - - name: dest - type: Hostname - role: - - Victim - automated_detection_testing: passed + security_domain: endpoint diff --git a/detections/endpoint/wmic_xsl_execution_via_url.yml b/detections/endpoint/wmic_xsl_execution_via_url.yml index 768394b4ba..083857a0c6 100644 --- a/detections/endpoint/wmic_xsl_execution_via_url.yml +++ b/detections/endpoint/wmic_xsl_execution_via_url.yml @@ -34,38 +34,20 @@ references: tags: analytic_story: - Suspicious WMI Use - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1220/atomic_red_team/windows-sysmon.log - kill_chain_phases: - - Exploitation - mitre_attack_id: - - T1220 - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.parent_process - - Processes.original_file_name - - Processes.process_name - - Processes.process - - Processes.process_id - - Processes.parent_process_path - - Processes.process_path - - Processes.parent_process_id - security_domain: endpoint - impact: 80 + automated_detection_testing: passed confidence: 100 - risk_score: 80 context: - Source:Endpoint - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1220/atomic_red_team/windows-sysmon.log + impact: 80 + kill_chain_phases: + - Exploitation message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing wmic to download a remote XSL script. + mitre_attack_id: + - T1220 observable: - name: user type: User @@ -83,4 +65,22 @@ tags: type: Process role: - Child Process - automated_detection_testing: passed + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 80 + security_domain: endpoint diff --git a/detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml new file mode 100644 index 0000000000..e97f6960b8 --- /dev/null +++ b/detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml @@ -0,0 +1,80 @@ +name: Wmiprsve LOLBAS Execution Process Spawn +id: 95a455f0-4c04-11ec-b8ac-3e22fbd008af +version: 1 +date: '2021-11-22' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies `wmiprsve.exe` spawning a LOLBAS execution + process. When adversaries execute code on remote endpoints abusing Windows Management + Instrumentation (WMI), the executed command is spawned as a child process of `wmiprvse.exe`. + The LOLBAS project documents Windows native binaries that can be abused by threat + actors to perform tasks like executing malicious code. Looking for child processes + of wmiprvse.exe that are part of the LOLBAS project can help defenders identify + lateral movement activity. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=wmiprvse.exe) + (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", + "Rasautou.exe", "Schtasks.exe", "Xwizard.exe", "Dllhost.exe", "Pnputil.exe", "Atbroker.exe", + "Pcwrun.exe", "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe", "Certoc.exe", "Ieexec.exe", + "Microsoft.Workflow.Compiler.exe", "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe", + "Register-cimprovider.exe", "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe", + "SettingSyncHost.exe", "Cmstp.exe", "Mmc.exe", "Stordiag.exe", "Scriptrunner.exe", + "Odbcconf.exe", "Extexport.exe", "Msdt.exe", "WorkFolders.exe", "Diskshadow.exe", + "Mavinject.exe", "Regasm.exe", "Gpscript.exe", "Rundll32.exe", "Regsvr32.exe", "Msiexec.exe", + "Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", "Runonce.exe", "Syncappvpublishingserver.exe", + "Verclsid.exe", "Infdefaultinstall.exe", "Explorer.exe", "Installutil.exe", "Netsh.exe", + "Wab.exe", "Dnscmd.exe", "At.exe", "Pcalua.exe", "Msconfig.exe")) by Processes.dest + Processes.user Processes.parent_process Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `wmiprsve_lolbas_execution_process_spawn_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. +known_false_positives: Legitimate applications may trigger this behavior, filter as + needed. +references: +- https://attack.mitre.org/techniques/T1047/ +- https://www.ired.team/offensive-security/lateral-movement/t1047-wmi-for-lateral-movement +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/lateral_movement_lolbas/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Lateral Movement + message: Wmiprsve.exe spawned a LOLBAS process on $dest$. + mitre_attack_id: + - T1047 + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 54 + security_domain: endpoint diff --git a/detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml new file mode 100644 index 0000000000..f7a2261b11 --- /dev/null +++ b/detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml @@ -0,0 +1,81 @@ +name: Wsmprovhost LOLBAS Execution Process Spawn +id: 2eed004c-4c0d-11ec-93e8-3e22fbd008af +version: 1 +date: '2021-11-22' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies `Wsmprovhost.exe` spawning a LOLBAS + execution process. When adversaries execute code on remote endpoints abusing the + Windows Remote Management (WinRm) protocol, the executed command is spawned as a + child processs of `Wsmprovhost.exe`. The LOLBAS project documents Windows native + binaries that can be abused by threat actors to perform tasks like executing malicious + code. Looking for child processes of Wsmprovhost.exe that are part of the LOLBAS + project can help defenders identify lateral movement activity. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=wsmprovhost.exe) + (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", + "Rasautou.exe", "Schtasks.exe", "Xwizard.exe", "Dllhost.exe", "Pnputil.exe", "Atbroker.exe", + "Pcwrun.exe", "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe", "Certoc.exe", "Ieexec.exe", + "Microsoft.Workflow.Compiler.exe", "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe", + "Register-cimprovider.exe", "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe", + "SettingSyncHost.exe", "Cmstp.exe", "Mmc.exe", "Stordiag.exe", "Scriptrunner.exe", + "Odbcconf.exe", "Extexport.exe", "Msdt.exe", "WorkFolders.exe", "Diskshadow.exe", + "Mavinject.exe", "Regasm.exe", "Gpscript.exe", "Rundll32.exe", "Regsvr32.exe", "Msiexec.exe", + "Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", "Runonce.exe", "Syncappvpublishingserver.exe", + "Verclsid.exe", "Infdefaultinstall.exe", "Explorer.exe", "Installutil.exe", "Netsh.exe", + "Wab.exe", "Dnscmd.exe", "At.exe", "Pcalua.exe", "Msconfig.exe")) by Processes.dest + Processes.user Processes.parent_process Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `wsmprovhost_lolbas_execution_process_spawn_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. +known_false_positives: Legitimate applications may trigger this behavior, filter as + needed. +references: +- https://attack.mitre.org/techniques/T1021/006/ +- https://lolbas-project.github.io/ +- https://pentestlab.blog/2018/05/15/lateral-movement-winrm/ +tags: + analytic_story: + - Active Directory Lateral Movement + automated_detection_testing: passed + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.006/lateral_movement_lolbas/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Lateral Movement + message: Wsmprovhost.exe spawned a LOLBAS process on $dest$. + mitre_attack_id: + - T1021 + - T1021.006 + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 54 + security_domain: endpoint diff --git a/detections/endpoint/wsreset_uac_bypass.yml b/detections/endpoint/wsreset_uac_bypass.yml index aee3a9f687..5b9a81bbfb 100644 --- a/detections/endpoint/wsreset_uac_bypass.yml +++ b/detections/endpoint/wsreset_uac_bypass.yml @@ -12,7 +12,7 @@ description: This search is to detect a suspicious modification of registry rela account Control. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command*" - (Registry.registry_key_name = "(Default)" OR Registry.registry_key_name = "DelegateExecute") + (Registry.registry_value_name = "(Default)" OR Registry.registry_value_name = "DelegateExecute") by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `wsreset_uac_bypass_filter`' @@ -61,6 +61,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/xsl_script_execution_with_wmic.yml b/detections/endpoint/xsl_script_execution_with_wmic.yml index e0a0028be5..dd69f41f6e 100644 --- a/detections/endpoint/xsl_script_execution_with_wmic.yml +++ b/detections/endpoint/xsl_script_execution_with_wmic.yml @@ -77,6 +77,6 @@ tags: - Processes.user risk_score: 49 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/experimental/cloud/abnormally_high_cloud_instances_destroyed.yml b/detections/experimental/cloud/abnormally_high_cloud_instances_destroyed.yml index 79d8ffec04..5f5357037d 100644 --- a/detections/experimental/cloud/abnormally_high_cloud_instances_destroyed.yml +++ b/detections/experimental/cloud/abnormally_high_cloud_instances_destroyed.yml @@ -59,20 +59,3 @@ tags: risk_object_type: user risk_score: 10 security_domain: Cloud - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_citrix-netscaler - - Splunk_TA_nix - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_ossec - - Splunk_TA_juniper - - splunk_ta_o365 - - Splunk_TA_cyberark - - Splunk_TA_box - - Splunk_TA_CrowdStrike_FDR - - Splunk_TA_cisco-asa - - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose diff --git a/detections/experimental/cloud/abnormally_high_cloud_instances_launched.yml b/detections/experimental/cloud/abnormally_high_cloud_instances_launched.yml index 641cd30cf3..fdaff07d65 100644 --- a/detections/experimental/cloud/abnormally_high_cloud_instances_launched.yml +++ b/detections/experimental/cloud/abnormally_high_cloud_instances_launched.yml @@ -60,20 +60,3 @@ tags: risk_object_type: user risk_score: 40 security_domain: Cloud - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_citrix-netscaler - - Splunk_TA_nix - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_ossec - - Splunk_TA_juniper - - splunk_ta_o365 - - Splunk_TA_cyberark - - Splunk_TA_box - - Splunk_TA_CrowdStrike_FDR - - Splunk_TA_cisco-asa - - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose diff --git a/detections/endpoint/detect_computer_changed_with_anonymous_account.yml b/detections/experimental/endpoint/detect_computer_changed_with_anonymous_account.yml similarity index 100% rename from detections/endpoint/detect_computer_changed_with_anonymous_account.yml rename to detections/experimental/endpoint/detect_computer_changed_with_anonymous_account.yml diff --git a/detections/endpoint/first_time_seen_child_process_of_zoom.yml b/detections/experimental/endpoint/first_time_seen_child_process_of_zoom.yml similarity index 100% rename from detections/endpoint/first_time_seen_child_process_of_zoom.yml rename to detections/experimental/endpoint/first_time_seen_child_process_of_zoom.yml diff --git a/detections/experimental/endpoint/linux_java_spawning_shell.yml b/detections/experimental/endpoint/linux_java_spawning_shell.yml new file mode 100644 index 0000000000..b8df23e21e --- /dev/null +++ b/detections/experimental/endpoint/linux_java_spawning_shell.yml @@ -0,0 +1,79 @@ +name: Linux Java Spawning Shell +id: 7b09db8a-5c20-11ec-9945-acde48001122 +version: 1 +date: '2021-12-13' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies the process name of Java, Apache, or + Tomcat spawning a Linux shell. This is potentially indicative of exploitation of + the Java application and may be related to current event CVE-2021-44228 (Log4Shell). + The shells included in the macro are "sh", "ksh", "zsh", "bash", "dash", "rbash", + "fish", "csh', "tcsh', "ion", "eshell". Upon triage, review parallel processes and + command-line arguments to determine legitimacy. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=java + OR Processes.parent_process_name=apache OR Processes.parent_process_name=tomcat + `linux_shells` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_java_spawning_shell_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon for Linux, you will need to ensure mapping is + occurring correctly. Ensure EDR product is mapping OS Linux to the datamodel properly. + Add any additional java process names for your environment to the analytic as needed. +known_false_positives: Filtering may be required on internal developer build systems + or classify assets as web facing and restrict the analytic based on that. +references: +- https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/ +- https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72 +tags: + analytic_story: + - Log4Shell CVE-2021-44228 + confidence: 50 + context: + - Source:Endpoint + - Stage:Defense Evasion + cve: + - CVE-2021-44228 + dataset: [] + impact: 80 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ spawning a Linux shell, potentially indicative of exploitation. + mitre_attack_id: + - T1190 + observable: + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 40 + security_domain: endpoint diff --git a/detections/experimental/endpoint/print_processor_registry_autostart.yml b/detections/experimental/endpoint/print_processor_registry_autostart.yml index 0bf18cd094..f654e0db1e 100644 --- a/detections/experimental/endpoint/print_processor_registry_autostart.yml +++ b/detections/experimental/endpoint/print_processor_registry_autostart.yml @@ -67,6 +67,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/detections/experimental/endpoint/randomly_generated_scheduled_task_name.yml b/detections/experimental/endpoint/randomly_generated_scheduled_task_name.yml new file mode 100644 index 0000000000..197d64c2c3 --- /dev/null +++ b/detections/experimental/endpoint/randomly_generated_scheduled_task_name.yml @@ -0,0 +1,64 @@ +name: Randomly Generated Scheduled Task Name +id: 9d22a780-5165-11ec-ad4f-3e22fbd008af +version: 1 +date: '2021-11-29' +author: Mauricio Velazco, Splunk +type: Hunting +datamodel: +- Endpoint +description: The following hunting analytic leverages Event ID 4698, `A scheduled + task was created`, to identify the creation of a Scheduled Task with a suspicious, + high entropy, Task Name. To achieve this, this analytic also leverages the `ut_shannon` + function from the URL ToolBox Splunk application. Red teams and adversaries alike + may abuse the Task Scheduler to create and start a remote Scheduled Task and obtain + remote code execution. To achieve this goal, tools like Impacket or Crapmapexec, + typically create a Scheduled Task with a random task name on the victim host. This + hunting analytic may help defenders identify Scheduled Tasks created as part of + a lateral movement attack. The entropy threshold `ut_shannon > 3` should be customized + by users. The Command field can be used to determine if the task has malicious intent + or not. +search: ' `wineventlog_security` EventCode=4698 | xmlkv Message | lookup ut_shannon_lookup + word as Task_Name | where ut_shannon > 3 | table _time, dest, Task_Name, ut_shannon, + Command, Author, Enabled, Hidden | `randomly_generated_scheduled_task_name_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + Windows Security Event Logs with 4698 EventCode enabled. The Windows TA as well + as the URL ToolBox application are also required. +known_false_positives: Legitimate applications may use random Scheduled Task names. +references: +- https://attack.mitre.org/techniques/T1053/005/ +- https://splunkbase.splunk.com/app/2734/ +- https://en.wikipedia.org/wiki/Entropy_(information_theory) +tags: + analytic_story: + - Active Directory Lateral Movement + confidence: 50 + context: + - Source:Endpoint + - Stage:Persistence + - Stage:Lateral Movement + impact: 90 + kill_chain_phases: + - Privilege Escalation + - Lateral Movement + - Persistence + message: A windows scheduled task with a suspicious task name was created on $dest$ + mitre_attack_id: + - T1053 + - T1053.005 + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - dest + - Task_Name + - Description + - Command + risk_score: 45 + security_domain: endpoint diff --git a/detections/experimental/endpoint/randomly_generated_windows_service_name.yml b/detections/experimental/endpoint/randomly_generated_windows_service_name.yml new file mode 100644 index 0000000000..ea1bffb29f --- /dev/null +++ b/detections/experimental/endpoint/randomly_generated_windows_service_name.yml @@ -0,0 +1,68 @@ +name: Randomly Generated Windows Service Name +id: 2032a95a-5165-11ec-a2c3-3e22fbd008af +version: 1 +date: '2021-11-29' +author: Mauricio Velazco, Splunk +type: Hunting +datamodel: +- Endpoint +description: The following hunting analytic leverages Event ID 7045, `A new service + was installed in the system`, to identify the installation of a Windows Service + with a suspicious, high entropy, Service Name. To achieve this, this analytic also + leverages the `ut_shannon` function from the URL ToolBox Splunk application. Red + teams and adversaries alike may abuse the Service Control Manager to create and + start a remote Windows Service and obtain remote code execution. To achieve this + goal, some tools like Metasploit, Cobalt Strike and Impacket, typically create a + Windows Service with a random service name on the victim host. This hunting analytic + may help defenders identify Windows Services installed as part of a lateral movement + attack. The entropy threshold `ut_shannon > 3` should be customized by users. The + Service_File_Name field can be used to determine if the Windows Service has malicious + intent or not. +search: ' `wineventlog_system` EventCode=7045 | lookup ut_shannon_lookup word as Service_Name + | where ut_shannon > 3 | table EventCode ComputerName Service_Name ut_shannon Service_Start_Type + Service_Type Service_File_Name | `randomly_generated_windows_service_name_filter` ' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the Service name, Service File Name Service Start type, and Service Type + from your endpoints. The Windows TA as well as the URL ToolBox application are also + required. +known_false_positives: Legitimate applications may use random Windows Service names. +references: +- https://attack.mitre.org/techniques/T1543/003/ +tags: + analytic_story: + - Active Directory Lateral Movement + confidence: 50 + context: + - Source:Endpoint + - Stage:Lateral Movement + impact: 90 + kill_chain_phases: + - Privilege Escalation + - Lateral Movement + message: A Windows Service with a suspicious service name was installed on $ComputerName$ + mitre_attack_id: + - T1543 + - T1543.003 + observable: + - name: Service_File_Name + type: Other + role: + - Other + - name: ComputerName + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ComputerName + - Service_File_Name + - Service_Type + - Service_Name + - Service_Start_Type + risk_score: 45 + security_domain: endpoint diff --git a/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml b/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml index 512846226c..d9c7c0dda1 100644 --- a/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml +++ b/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml @@ -28,7 +28,7 @@ references: [] tags: analytic_story: - Hidden Cobra Malware - - Lateral Movement + - Active Directory Lateral Movement asset_type: Endpoint cis20: - CIS 3 diff --git a/detections/experimental/endpoint/unusual_number_of_computer_service_tickets_requested.yml b/detections/experimental/endpoint/unusual_number_of_computer_service_tickets_requested.yml new file mode 100644 index 0000000000..c382b71c0d --- /dev/null +++ b/detections/experimental/endpoint/unusual_number_of_computer_service_tickets_requested.yml @@ -0,0 +1,70 @@ +name: Unusual Number of Computer Service Tickets Requested +id: ac3b81c0-52f4-11ec-ac44-acde48001122 +version: 1 +date: '2021-12-01' +author: Mauricio Velazco, Splunk +type: Hunting +datamodel: +- Endpoint +description: 'The following hunting analytic leverages Event ID 4769, `A Kerberos + service ticket was requested`, to identify an unusual number of computer service + ticket requests from one source. When a domain joined endpoint connects to a remote + endpoint, it first will request a Kerberos Ticket with the computer name as the + Service Name. An endpoint requesting a large number of computer service tickets + for different endpoints could represent malicious behavior like lateral movement, + malware staging, reconnaissance, etc.\ + + The detection calculates the standard deviation for each host and leverages the + 3-sigma statistical rule to identify an unusual number of service requests. To customize + this analytic, users can try different combinations of the `bucket` span time, the + calculation of the `upperBound` field as well as the Outlier calculation. This logic + can be used for real time security monitoring as well as threat hunting exercises.\' +search: ' `wineventlog_security` EventCode=4769 Service_Name="*$" Account_Name!="*$*" + | bucket span=2m _time | stats dc(Service_Name) AS unique_targets values(Service_Name) + as host_targets by _time, Client_Address, Account_Name | eventstats avg(unique_targets) + as comp_avg , stdev(unique_targets) as comp_std by Client_Address, Account_Name + | eval upperBound=(comp_avg+comp_std*3) | eval isOutlier=if(unique_targets >10 and + unique_targets >= upperBound, 1, 0) | `unusual_number_of_computer_service_tickets_requested_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + Domain Controller and Kerberos events. The Advanced Security Audit policy setting + `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. +known_false_positives: An single endpoint requesting a large number of computer service + tickets is not common behavior. Possible false positive scenarios include but are + not limited to vulnerability scanners, administration systeams and missconfigured + systems. +references: +- https://attack.mitre.org/techniques/T1078/ +tags: + analytic_story: + - Active Directory Lateral Movement + confidence: 60 + context: + - Source:Endpoint + - Stage:Lateral Movement + impact: 70 + kill_chain_phases: + - Reconnaissance + - Exploitation + - Lateral Movement + message: null + mitre_attack_id: + - T1078 + observable: + - name: Client_Address + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - Ticket_Options + - Ticket_Encryption_Type + - dest + - service + - service_id + risk_score: 42 + security_domain: endpoint diff --git a/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml b/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml new file mode 100644 index 0000000000..47668c6ddf --- /dev/null +++ b/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml @@ -0,0 +1,69 @@ +name: Unusual Number of Remote Endpoint Authentication Events +id: acb5dc74-5324-11ec-a36d-acde48001122 +version: 1 +date: '2021-12-01' +author: Mauricio Velazco, Splunk +type: Hunting +datamodel: +- Endpoint +description: 'The following hunting analytic leverages Event ID 4624, `An account + was successfully logged on`, to identify an unusual number of remote authentication + attempts coming from one source. An endpoint authenticating to a large number of + remote endpoints could represent malicious behavior like lateral movement, malware + staging, reconnaissance, etc.\ + + The detection calculates the standard deviation for each host and leverages the + 3-sigma statistical rule to identify an unusual high number of authentication events. + To customize this analytic, users can try different combinations of the `bucket` + span time, the calculation of the `upperBound` field as well as the Outlier calculation. + This logic can be used for real time security monitoring as well as threat hunting + exercises.\' +search: ' `wineventlog_security` EventCode=4624 Logon_Type=3 Account_Name!="*$" | + eval Source_Account = mvindex(Account_Name, 1) | bucket span=2m _time | stats dc(ComputerName) + AS unique_targets values(ComputerName) as target_hosts by _time, Source_Network_Address, + Source_Account | eventstats avg(unique_targets) as comp_avg , stdev(unique_targets) + as comp_std by Source_Network_Address, Source_Account | eval upperBound=(comp_avg+comp_std*3) + | eval isOutlier=if(unique_targets >10 and unique_targets >= upperBound, 1, 0) `unusual_number_of_remote_endpoint_authentication_events_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + Windows Event Logs from domain controllers aas well as member servers and workstations. + The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs + to be enabled. +known_false_positives: An single endpoint authenticating to a large number of hosts + is not common behavior. Possible false positive scenarios include but are not limited + to vulnerability scanners, jump servers and missconfigured systems. +references: +- https://attack.mitre.org/techniques/T1078/ +tags: + analytic_story: + - Active Directory Lateral Movement + confidence: 60 + context: + - Source:Endpoint + - Stage:Reconnaissance + - Stage:Lateral Movement + impact: 70 + kill_chain_phases: + - Reconnaissance + - Lateral Movement + message: null + mitre_attack_id: + - T1078 + observable: + - name: ComputerName + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - Logon_Type + - Caller_Process_Name + - Security_ID + - Account_Name + - ComputerName + risk_score: 42 + security_domain: endpoint diff --git a/detections/experimental/endpoint/windows_java_spawning_shells.yml b/detections/experimental/endpoint/windows_java_spawning_shells.yml new file mode 100644 index 0000000000..0383efa02a --- /dev/null +++ b/detections/experimental/endpoint/windows_java_spawning_shells.yml @@ -0,0 +1,79 @@ +name: Windows Java Spawning Shells +id: 28c81306-5c47-11ec-bfea-acde48001122 +version: 1 +date: '2021-12-13' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies the process name of java.exe and w3wp.exe + spawning a Windows shell. This is potentially indicative of exploitation of the + Java application and may be related to current event CVE-2021-44228 (Log4Shell). + The shells included in the macro are "cmd.exe", "powershell.exe". Upon triage, review + parallel processes and command-line arguments to determine legitimacy. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=java.exe + OR Processes.parent_process_name=w3wp.exe `windows_shells` by Processes.dest Processes.user + Processes.parent_process_name Processes.process_name Processes.process Processes.process_id + Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_java_spawning_shells_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. Restrict the analytic to publicly facing endpoints to reduce false positives. + Add any additional identified web application process name to the query. Add any + further Windows process names to the macro (ex. LOLBins) to further expand this + query. +known_false_positives: Filtering may be required on internal developer build systems + or classify assets as web facing and restrict the analytic based on that. +references: +- https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/ +- https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72 +tags: + analytic_story: + - Log4Shell CVE-2021-44228 + confidence: 50 + context: + - Source:Endpoint + - Stage:Defense Evasion + cve: + - CVE-2021-44228 + dataset: [] + impact: 80 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ spawning a Windows shell, potentially indicative of exploitation. + mitre_attack_id: + - T1190 + observable: + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 40 + security_domain: endpoint diff --git a/detections/experimental/network/remote_desktop_network_traffic.yml b/detections/experimental/network/remote_desktop_network_traffic.yml index a3148b01dd..e08cb53592 100644 --- a/detections/experimental/network/remote_desktop_network_traffic.yml +++ b/detections/experimental/network/remote_desktop_network_traffic.yml @@ -32,7 +32,7 @@ tags: - SamSam Ransomware - Ryuk Ransomware - Hidden Cobra Malware - - Lateral Movement + - Active Directory Lateral Movement asset_type: Endpoint cis20: - CIS 3 diff --git a/detections/network/detect_outbound_ldap_traffic.yml b/detections/network/detect_outbound_ldap_traffic.yml new file mode 100644 index 0000000000..97ca0cb956 --- /dev/null +++ b/detections/network/detect_outbound_ldap_traffic.yml @@ -0,0 +1,78 @@ +name: Detect Outbound LDAP Traffic +id: c77162d3-f91c-45cc-80c8-22f6v546119f +version: 1 +date: '2021-12-13' +author: Bhavin Patel, Johan Bjerke, Splunk +type: Hunting +datamodel: +- Network_Traffic +description: Malicious actors often abuse misconfigured LDAP servers or applications + that use the LDAP servers in organizations. Outbound LDAP traffic should not be + allowed outbound through your perimeter firewall. This search will help determine + if you have any LDAP connections to IP addresses outside of private (RFC1918) address + space. +search: '| tstats earliest(_time) as earliest_time latest(_time) as latest_time values(All_Traffic.dest_ip) + as dest_ip from datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port + = 389 OR All_Traffic.dest_port = 636 AND NOT (All_Traffic.dest_ip = 10.0.0.0/8 OR + All_Traffic.dest_ip=192.168.0.0/16 OR All_Traffic.dest_ip = 172.16.0.0/12) by All_Traffic.src_ip + All_Traffic.dest_ip |`drop_dm_object_name("All_Traffic")` | where src_ip != dest_ip + | `security_content_ctime(latest_time)` | `security_content_ctime(earliest_time)` + |`detect_outbound_ldap_traffic_filter`' +how_to_implement: You must be ingesting Zeek DNS and Zeek Conn data into Splunk. Zeek + data should also be getting ingested in JSON format and should be mapped to the + Network Traffic datamodels that are in use for this search. +known_false_positives: Unknown at this moment. Outbound LDAP traffic should not be + allowed outbound through your perimeter firewall. Please check those servers to + verify if the activity is legitimate. +references: +- https://www.govcert.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/ +tags: + analytic_story: + - Log4Shell CVE-2021-44228 + asset_type: Endpoint + automated_detection_testing: passed + cis20: + - CIS 12 + - CIS 13 + confidence: 80 + context: + - Source:Endpoint + - Stage:Initial Access + cve: + - CVE-2021-44228 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_ldap/bro_conn.json + impact: 70 + kill_chain_phases: + - Command and Control + - Actions on Objectives + message: An outbound LDAP connection from $src_ip$ in your infrastructure connecting + to dest ip $dest_ip$ + mitre_attack_id: + - T1190 + - T1059 + nist: + - PR.DS + - PR.PT + - DE.AE + - DE.CM + observable: + - name: src_ip + type: IP Address + role: + - Victim + - name: dest_ip + type: IP Address + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - All_Traffic.dest_ip + - All_Traffic.dest_port + - All_Traffic.src_ip + risk_score: 56 + security_domain: network diff --git a/detections/network/dns_query_length_with_high_standard_deviation.yml b/detections/network/dns_query_length_with_high_standard_deviation.yml index 8c559cabaa..6141540fa0 100644 --- a/detections/network/dns_query_length_with_high_standard_deviation.yml +++ b/detections/network/dns_query_length_with_high_standard_deviation.yml @@ -66,7 +66,7 @@ tags: - DNS.query risk_score: 56 security_domain: network - CIM_version: 4.20.2 + cim_version: 4.20.2 supported_tas: - Splunk_TA_isc-bind - Splunk_TA_CrowdStrike_FDR diff --git a/detections/web/log4shell_jndi_payload_injection_attempt.yml b/detections/web/log4shell_jndi_payload_injection_attempt.yml new file mode 100644 index 0000000000..e7b549f675 --- /dev/null +++ b/detections/web/log4shell_jndi_payload_injection_attempt.yml @@ -0,0 +1,89 @@ +name: Log4Shell JNDI Payload Injection Attempt +id: c184f12e-5c90-11ec-bf1f-497c9a704a72 +version: 1 +date: '2021-12-13' +author: Jose Hernandez +type: Anomaly +datamodel: +- Web +description: CVE-2021-44228 Log4Shell payloads can be injected via various methods, + but on of the most common vectors injection is via Web calls. Many of the vulnerable + java web applications that are using log4j have a web component to them are specially + targets of this injection, specifically projects like Apache Struts, Flink, Druid, + and Solr. The exploit is triggered by a LDAP lookup function in the log4j package, + its invocation is similar to `${jndi:ldap://PAYLOAD_INJECTED}`, when executed against + vulnerable web applications the invocation can be seen in various part of web logs. + Specifically it has been successfully exploited via headers like X-Forwarded-For, + User-Agent, Referer, and X-Api-Version. In this detection we first limit the scope + of our search to the Web Datamodel and use the `| from datamodel` function to benefit + from schema accelerated searching capabilities, mainly because the second part of + the detection is pretty heavy, it runs a regex across all _raw events that looks + for `${jndi:ldap://` pattern across all potential web fields available to the raw + data, like http headers for example. If you see results for this detection, it means + that there was a attempt at a injection, which could be a reconnaissance activity + or a valid expliotation attempt, but this does not exactly mean that the host was + indeed successfully exploited. +search: '| from datamodel Web.Web | regex _raw="[jJnNdDiI]{4}(\:|\%3A|\/|\%2F)\w+(\:\/\/|\%3A\%2F\%2F)(\$\{.*?\}(\.)?)?" + | fillnull | stats count by action, category, dest, dest_port, http_content_type, + http_method, http_referrer, http_user_agent, site, src, url, url_domain, user | + `log4shell_jndi_payload_injection_attempt_filter`' +how_to_implement: This detection requires the Web datamodel to be populated from a + supported Technology Add-On like Splunk for Apache or Splunk for Nginx. +known_false_positives: If there is a vulnerablility scannner looking for log4shells + this will trigger, otherwise likely to have low false positives. +references: +- https://www.lunasec.io/docs/blog/log4j-zero-day/ +tags: + analytic_story: + - Log4Shell CVE-2021-44228 + automated_detection_testing: passed + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 30 + context: + - Source:Application Log + - Stage:Execution + cve: + - CVE-2021-44228 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/log4j_proxy_logs/log4j_proxy_logs.log + impact: 50 + kill_chain_phases: + - Reconnaissance + - Exploitation + message: CVE-2021-44228 Log4Shell triggered for host $dest$ + mitre_attack_id: + - T1190 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - action + - category + - dest + - dest_port + - http_content_type + - http_method + - http_referrer + - http_user_agent + - site + - src + - url + - url_domain + - user + risk_score: 15 + security_domain: threat diff --git a/detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml b/detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml new file mode 100644 index 0000000000..0e781ffc20 --- /dev/null +++ b/detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml @@ -0,0 +1,86 @@ +name: Log4Shell JNDI Payload Injection with Outbound Connection +id: 69afee44-5c91-11ec-bf1f-497c9a704a72 +version: 1 +date: '2021-12-13' +author: Jose Hernandez +type: Anomaly +datamodel: +- Network_Traffic +- Web +description: CVE-2021-44228 Log4Shell payloads can be injected via various methods, + but on of the most common vectors injection is via Web calls. Many of the vulnerable + java web applications that are using log4j have a web component to them are specially + targets of this injection, specifically projects like Apache Struts, Flink, Druid, + and Solr. The exploit is triggered by a LDAP lookup function in the log4j package, + its invocation is similar to `${jndi:ldap://PAYLOAD_INJECTED}`, when executed against + vulnerable web applications the invocation can be seen in various part of web logs. + Specifically it has been successfully exploited via headers like X-Forwarded-For, + User-Agent, Referer, and X-Api-Version. In this detection we match the invocation + function with a network connection to a malicious ip address. +search: '| from datamodel Web.Web | rex field=_raw max_match=0 "[jJnNdDiI]{4}(\:|\%3A|\/|\%2F)(?\w+)(\:\/\/|\%3A\%2F\%2F)(\$\{.*?\}(\.)?)?(?[a-zA-Z0-9\.\-\_\$]+)" + | join affected_host type=inner [| tstats `security_content_summariesonly` count + min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic.All_Traffic + by All_Traffic.dest | `drop_dm_object_name(All_Traffic)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | rename dest AS affected_host] | fillnull + | stats count by action, category, dest, dest_port, http_content_type, http_method, + http_referrer, http_user_agent, site, src, url, url_domain, user | `log4shell_jndi_payload_injection_with_outbound_connection_filter`' +how_to_implement: This detection requires the Web datamodel to be populated from a + supported Technology Add-On like Splunk for Apache or Splunk for Nginx. +known_false_positives: If there is a vulnerablility scannner looking for log4shells + this will trigger, otherwise likely to have low false positives. +references: +- https://www.lunasec.io/docs/blog/log4j-zero-day/ +tags: + analytic_story: + - Log4Shell CVE-2021-44228 + automated_detection_testing: passed + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 30 + context: + - Source:Application Log + - Stage:Execution + cve: + - CVE-2021-44228 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/log4j_proxy_logs/log4j_proxy_logs.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/log4j_network_logs/log4j_network_logs.log + impact: 50 + kill_chain_phases: + - Exploitation + message: CVE-2021-44228 Log4Shell triggered for host $dest$ + mitre_attack_id: + - T1190 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - action + - category + - dest + - dest_port + - http_content_type + - http_method + - http_referrer + - http_user_agent + - site + - src + - url + - url_domain + - user + risk_score: 15 + security_domain: threat diff --git a/security_content_automation/detection_ta_mapping.yaml b/security_content_automation/detection_ta_mapping.yml similarity index 55% rename from security_content_automation/detection_ta_mapping.yaml rename to security_content_automation/detection_ta_mapping.yml index 9491fb6ae4..e19217d0c5 100644 --- a/security_content_automation/detection_ta_mapping.yaml +++ b/security_content_automation/detection_ta_mapping.yml @@ -1,5 +1,5 @@ -Abnormally High Number Of Cloud Infrastructure API Calls Unit Test: - CIM_version: 4.20.2 +abnormally_high_number_of_cloud_infrastructure_api_calls: + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_nix @@ -16,26 +16,8 @@ Abnormally High Number Of Cloud Infrastructure API Calls Unit Test: - Splunk_TA_salesforce tas_with_data: - Splunk_TA_aws-kinesis-firehose -Abnormally High Number Of Cloud Instances Destroyed Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_citrix-netscaler - - Splunk_TA_nix - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_ossec - - Splunk_TA_juniper - - splunk_ta_o365 - - Splunk_TA_cyberark - - Splunk_TA_box - - Splunk_TA_CrowdStrike_FDR - - Splunk_TA_cisco-asa - - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose -Abnormally High Number Of Cloud Security Group API Calls Unit Test: - CIM_version: 4.20.2 +abnormally_high_number_of_cloud_security_group_api_calls: + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_nix @@ -51,87 +33,69 @@ Abnormally High Number Of Cloud Security Group API Calls Unit Test: - Splunk_TA_salesforce tas_with_data: - Splunk_TA_aws-kinesis-firehose -Abnormally High Number of Cloud Instances Launched Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_citrix-netscaler - - Splunk_TA_nix - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_ossec - - Splunk_TA_juniper - - splunk_ta_o365 - - Splunk_TA_cyberark - - Splunk_TA_box - - Splunk_TA_CrowdStrike_FDR - - Splunk_TA_cisco-asa - - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose -Active Setup Registry Autostart Unit Test: - CIM_version: 4.20.2 +active_setup_registry_autostart: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Add DefaultUser And Password In Registry Unit Test: - CIM_version: 4.20.2 +add_defaultuser_and_password_in_registr: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Allow Inbound Traffic By Firewall Rule Registry Unit Test: - CIM_version: 4.20.2 +allow_inbound_traffic_by_firewall_rule_registr: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Allow Operation with Consent Admin Unit Test: - CIM_version: 4.20.2 +allow_operation_with_consent_admin: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Anomalous usage of 7zip Unit Test: - CIM_version: 4.20.2 +anomalous_usage_of_7zip: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Attacker Tools On Endpoint Unit Test: - CIM_version: 4.20.2 +attacker_tools_on_endpoint: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows -Attempt To Add Certificate To Untrusted Store Unit Test: - CIM_version: 4.20.2 +attempt_to_add_certificate_to_untrusted_store: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Auto Admin Logon Registry Entry Unit Test: - CIM_version: 4.20.2 +auto_admin_logon_registry_entr: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -BCDEdit Failure Recovery Modification: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -Batch File Write to System32 Unit Test: - CIM_version: 4.20.2 +batch_file_write_to_system32: + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR -Bcdedit Command Back To Normal Mode Boot Unit Test: - CIM_version: 4.20.2 +bcdedit_command_back_to_normal_mode_boot: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Change Default File Association Unit Test: - CIM_version: 4.20.2 +bcdedit_failure_recovery_modification: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Change To Safe Mode With Network Config Unit Test: - CIM_version: 4.20.2 + - Splunk_TA_CrowdStrike_FDR +change_default_file_association: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Check Elevated CMD using whoami Unit Test: - CIM_version: 4.20.2 +change_to_safe_mode_with_network_config: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Cloud API Calls From Previously Unseen User Roles Unit Test: - CIM_version: 4.20.2 +check_elevated_cmd_using_whoami: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +cloud_api_calls_from_previously_unseen_user_roles: + cim_version: 4.20.2 supported_tas: - Splunk_TA_aws-kinesis-firehose - Splunk_TA_rsa_securid_cas @@ -141,32 +105,32 @@ Cloud API Calls From Previously Unseen User Roles Unit Test: - Splunk_TA_salesforce tas_with_data: - Splunk_TA_aws-kinesis-firehose -Cloud Compute Instance Created By Previously Unseen User Unit Test: - CIM_version: 4.20.2 +cloud_compute_instance_created_by_previously_unseen_user: + cim_version: 4.20.2 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: - Splunk_TA_aws-kinesis-firehose -Cloud Compute Instance Created In Previously Unused Region Unit Test: - CIM_version: 4.20.2 +cloud_compute_instance_created_in_previously_unused_region: + cim_version: 4.20.2 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: - Splunk_TA_aws-kinesis-firehose -Cloud Compute Instance Created With Previously Unseen Image Unit Test: - CIM_version: 4.20.2 +cloud_compute_instance_created_with_previously_unseen_image: + cim_version: 4.20.2 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: - Splunk_TA_aws-kinesis-firehose -Cloud Compute Instance Created With Previously Unseen Instance Type Unit Test: - CIM_version: 4.20.2 +cloud_compute_instance_created_with_previously_unseen_instance_type: + cim_version: 4.20.2 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: - Splunk_TA_aws-kinesis-firehose -Cloud Instance Modified By Previously Unseen User Unit Test: - CIM_version: 4.20.2 +cloud_instance_modified_with_previously_unseen_user: + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_nix @@ -181,8 +145,8 @@ Cloud Instance Modified By Previously Unseen User Unit Test: - Splunk_TA_salesforce tas_with_data: - Splunk_TA_aws-kinesis-firehose -Cloud Provisioning Activity From Previously Unseen City Unit Test: - CIM_version: 4.20.2 +cloud_provisioning_from_previously_unseen_cit: + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid @@ -197,8 +161,8 @@ Cloud Provisioning Activity From Previously Unseen City Unit Test: - Splunk_TA_salesforce tas_with_data: - Splunk_TA_aws-kinesis-firehose -Cloud Provisioning Activity From Previously Unseen Country Unit Test: - CIM_version: 4.20.2 +cloud_provisioning_from_previously_unseen_countr: + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid @@ -213,8 +177,8 @@ Cloud Provisioning Activity From Previously Unseen Country Unit Test: - Splunk_TA_salesforce tas_with_data: - Splunk_TA_aws-kinesis-firehose -Cloud Provisioning Activity From Previously Unseen IP Address Unit Test: - CIM_version: 4.20.2 +cloud_provisioning_from_previously_unseen_ip_address: + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid @@ -227,8 +191,8 @@ Cloud Provisioning Activity From Previously Unseen IP Address Unit Test: - Splunk_TA_salesforce tas_with_data: - Splunk_TA_aws-kinesis-firehose -Cloud Provisioning Activity From Previously Unseen Region Unit Test: - CIM_version: 4.20.2 +cloud_provisioning_from_previously_unseen_region: + cim_version: 4.20.2 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid @@ -243,133 +207,123 @@ Cloud Provisioning Activity From Previously Unseen Region Unit Test: - Splunk_TA_salesforce tas_with_data: - Splunk_TA_aws-kinesis-firehose -DNS Query Length With High Standard Deviation Unit Test: - CIM_version: 4.20.2 +curl_download_and_bash_execution: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +detect_exchange_web_she: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +detect_regasm_spawning_a_process: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +detect_regsvcs_spawning_a_process: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +detect_sharphound_command_line_arguments: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +detect_use_of_cmd_exe_to_launch_script_interpreters: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disable_amsi_through_registr: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disable_etw_through_registr: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disable_logs_using_wevtuti: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disable_registry_too: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disable_schedule_task: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +disable_windows_app_hotkeys: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disable_windows_behavior_monitoring: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disabling_cmd_application: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disabling_controlpane: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disabling_folderoptions_windows_feature: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disabling_norun_windows_app: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disabling_systemrestore_in_registr: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +disabling_task_manager: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +dns_query_length_with_high_standard_deviation: + cim_version: 4.20.2 supported_tas: - Splunk_TA_isc-bind - Splunk_TA_CrowdStrike_FDR - Splunk_TA_infoblox -DSQuery Domain Discovery Unit Test: - CIM_version: 4.20.2 +domain_account_discovery_with_net_app: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +domain_account_discovery_with_wmic: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +dsquery_domain_discover: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Detect Exchange Web Shell Unit Test: - CIM_version: 4.20.2 +dump_lsass_via_procdump: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Detect RClone Command-Line Usage Unit Test: - CIM_version: 4.20.2 +enable_rdp_in_other_port_number: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Detect Regasm Spawning a Process Unit Test: - CIM_version: 4.20.2 +eventvwr_uac_bypass: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Detect Regsvcs Regasm Spawning a Process Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Detect SharpHound Command-Line Arguments Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Detect Use of cmd exe to Launch Script Interpreters Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disable AMSI Through Registry Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disable ETW Through Registry Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disable Logs Using WevtUtil Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disable Registry Tool Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disable Schedule Task Unit Test: - CIM_version: 4.20.2 +excessive_attempt_to_disable_services: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Disable Windows App Hotkeys Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disable Windows Behavior Monitoring Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disabling CMD Application Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disabling ControlPanel Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disabling FolderOptions Windows Feature Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disabling NoRun Windows App Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disabling SystemRestore In Registry Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Disabling Task Manager Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Domain Account Discovery With Net App Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Domain Account Discovery with Wmic Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Dump LSASS via procdump Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -Enable RDP In Other Port Number Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Eventvwr UAC Bypass Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Excessive Attempt To Disable Services Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -Excessive Usage Of Cacls App Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -Excessive Usage Of Taskkill Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -Excessive number of distinct processes created in Windows Temp folder Unit Test: - CIM_version: 4.20.2 +excessive_number_of_distinct_processes_created_in_windows_temp_folder: + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack @@ -378,12 +332,12 @@ Excessive number of distinct processes created in Windows Temp folder Unit Test: - Splunk_TA_cyberark_epm tas_with_data: - Splunk_TA_windows -Excessive number of service control start as disabled Unit Test: - CIM_version: 4.20.2 +excessive_number_of_service_control_start_as_disabled: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Excessive number of taskhost processes Unit Test: - CIM_version: 4.20.2 +excessive_number_of_taskhost_processes: + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack @@ -391,22 +345,32 @@ Excessive number of taskhost processes Unit Test: - Splunk_TA_CrowdStrike_FDR tas_with_data: - Splunk_TA_windows -Executables Or Script Creation In Suspicious Path Unit Test: - CIM_version: 4.20.2 +excessive_usage_of_cacls_app: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Execute Javascript With Jscript COM CLSID Unit Test: - CIM_version: 4.20.2 +excessive_usage_of_taskki: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Execution of File with Multiple Extensions Unit Test: - CIM_version: 4.20.2 + - Splunk_TA_CrowdStrike_FDR +executables_or_script_creation_in_suspicious_path: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +execute_javascript_with_jscript_com_clsid: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +execution_of_file_with_multiple_extensions: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows -File with Samsam Extension Unit Test: - CIM_version: 4.20.2 +file_with_samsam_extension: + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack @@ -415,85 +379,91 @@ File with Samsam Extension Unit Test: - Splunk_TA_cyberark - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR -Firewall Allowed Program Enable Unit Test: - CIM_version: 4.20.2 +firewall_allowed_program_enable: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -FodHelper UAC Bypass Unit Test: - CIM_version: 4.20.2 +fodhelper_uac_bypass: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Fsutil Zeroing File Unit Test: - CIM_version: 4.20.2 +fsutil_zeroing_file: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Get ADUserResultantPasswordPolicy with Powershell Unit Test: - CIM_version: 4.20.2 +get_aduserresultantpasswordpolicy_with_powershe: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Get DomainPolicy with Powershell Unit Test: - CIM_version: 4.20.2 +get_domainpolicy_with_powershe: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Get DomainUser with PowerShell Unit Test: - CIM_version: 4.20.2 +get_domainuser_with_powershe: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -GetWmiObject DS User with PowerShell Unit Test: - CIM_version: 4.20.2 +getwmiobject_ds_user_with_powershe: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Hide User Account From Sign-In Screen Unit Test: - CIM_version: 4.20.2 +hide_user_account_from_sign_in_screen: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Hiding Files And Directories With Attrib exe Unit Test: - CIM_version: 4.20.2 +hiding_files_and_directories_with_attrib_exe: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows -ICACLS Grant Command Unit Test: - CIM_version: 4.20.2 +icacls_deny_command: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Icacls Deny Command Unit Test: - CIM_version: 4.20.2 +icacls_grant_command: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Jscript Execution Using Cscript App Unit Test: - CIM_version: 4.20.2 +java_class_file_download_by_java_user_agent: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_citrix-netscaler + - Splunk_TA_nginx + - Splunk_TA_microsoft-iis + - Splunk_TA_websense-cg + - Splunk_TA_squid + - Splunk_TA_haproxy + - Splunk_TA_mcafee-wg + - Splunk_TA_cisco-wsa +jscript_execution_using_cscript_app: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Logon Script Event Trigger Execution Unit Test: - CIM_version: 4.20.2 +net_profiler_uac_bypass: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Modify ACL permission To Files Or Folder Unit Test: - CIM_version: 4.20.2 +nltest_domain_trust_discover: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +ntdsutil_export_ntds: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +odify_acl_permission_to_files_or_folder: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Msmpeng Application DLL Side Loading Unit Test: - CIM_version: 4.20.2 +ogon_script_event_trigger_execution: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -NET Profiler UAC bypass Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -NLTest Domain Trust Discovery: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -NTdsutil export ntds dit Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Overwriting Accessibility Binaries Unit Test: - CIM_version: 4.20.2 +overwriting_accessibility_binaries: + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_ossec @@ -503,12 +473,12 @@ Overwriting Accessibility Binaries Unit Test: - Splunk_TA_cyberark - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR -Permission Modification using Takeown App Unit Test: - CIM_version: 4.20.2 +permission_modification_using_takeown_app: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Powershell Execute COM Object Unit Test: - CIM_version: 4.20.2 +powershell_execute_com_object: + cim_version: 4.20.2 supported_tas: - Splunk_TA_cisco-ucs - Splunk_TA_citrix-netscaler @@ -567,68 +537,60 @@ Powershell Execute COM Object Unit Test: - Splunk_TA_oracle tas_with_data: - Splunk_TA_windows -Prevent Automatic Repair Mode using Bcdedit Unit Test: - CIM_version: 4.20.2 +prevent_automatic_repair_mode_using_bcdedit: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Print Processor Registry Autostart Unit Test: - CIM_version: 4.20.2 +print_processor_registry_autostart: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Process Creating LNK file in Suspicious location Unit Test: - CIM_version: 4.20.2 +process_creating_lnk_file_in_suspicious_location: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Process execution via wmi Unit Test: - CIM_version: 4.20.2 +process_execution_via_wmi: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Processes created by netsh Unit Test: - CIM_version: 4.20.2 +processes_launching_netsh: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Reg exe Manipulating Windows Services Registry Keys Unit Test: - CIM_version: 4.20.2 +reg_exe_manipulating_windows_services_registry_keys: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Registry Keys Used For Persistence Unit Test: - CIM_version: 4.20.2 +registry_keys_used_for_persistence: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Remote WMI Command Attempt Unit Test: - CIM_version: 4.20.2 +remote_wmi_command_attempt: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Resize ShadowStorage volume Unit Test: - CIM_version: 4.20.2 +resize_shadowstorage_volume: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Revil Common Exec Parameter Unit Test: - CIM_version: 4.20.2 +revil_common_exec_parameter: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Revil Registry Entry Unit Test: - CIM_version: 4.20.2 +revil_registry_entr: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Ryuk Wake on LAN Command Unit Test: - CIM_version: 4.20.2 +ryuk_wake_on_lan_command: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -SLUI RunAs Elevated Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -SLUI Spawning a Process Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Samsam Test File Write Unit Test: - CIM_version: 4.20.2 +samsam_test_file_write: + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack @@ -637,166 +599,183 @@ Samsam Test File Write Unit Test: - Splunk_TA_cyberark - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR -Sc exe Manipulating Windows Services Unit Test: - CIM_version: 4.20.2 +sc_exe_manipulating_windows_services: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Scheduled Task Deleted Or Created Via CMD: - CIM_version: 4.20.2 +scheduled_task_deleted_or_created_via_cmd: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Schtasks Run Task On Demand Unit Test: - CIM_version: 4.20.2 +schtasks_run_task_on_demand: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Schtasks scheduling job on remote system Unit Test: - CIM_version: 4.20.2 +schtasks_scheduling_job_on_remote_syste: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Schtasks used for forcing a reboot Unit Test: - CIM_version: 4.20.2 +schtasks_used_for_forcing_a_reboot: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Screensaver Event Trigger Execution Unit Test: - CIM_version: 4.20.2 +screensaver_event_trigger_execution: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Script Execution via WMI Unit Test: - CIM_version: 4.20.2 +script_execution_via_wmi: + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm -Sdclt UAC Bypass Unit Test: - CIM_version: 4.20.2 +sdclt_uac_bypass: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -SecretDumps Offline NTDS Dumping Tool Unit Test: - CIM_version: 4.20.2 +secretdumps_offline_ntds_dumping_too: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Services Escalate Exe Unit Test: - CIM_version: 4.20.2 +services_escalate_exe: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Set Default PowerShell Execution Policy To Unrestricted or Bypass Unit Test: - CIM_version: 4.20.2 +set_default_powershell_execution_policy_to_unrestricted_or_bypass: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Shim Database Installation With Suspicious Parameters Unit Test: - CIM_version: 4.20.2 +shim_database_installation_with_suspicious_parameters: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Short Lived Windows Accounts Unit Test: - CIM_version: 4.20.2 +short_lived_windows_accounts: + cim_version: 4.20.2 supported_tas: - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose - Splunk_TA_cyberark -SilentCleanup UAC Bypass Unit Test: - CIM_version: 4.20.2 +silentcleanup_uac_bypass: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Single Letter Process On Endpoint Unit Test: - CIM_version: 4.20.2 +single_letter_process_on_endpoint: + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm -Spoolsv Writing a DLL Unit Test: - CIM_version: 4.20.2 +slui_runas_elevated: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +slui_spawning_a_process: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +smpeng_application_dll_side_loading: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +spoolsv_writing_a_d: + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR -Start Up During Safe Mode Boot Unit Test: - CIM_version: 4.20.2 +start_up_during_safe_mode_boot: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Suspicious File Write Unit Test: - CIM_version: 4.20.2 +suspicious_mshta_child_process: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +suspicious_process_file_path: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +suspicious_reg_exe_process: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Suspicious Process File Path Unit Test: - CIM_version: 4.20.2 +suspicious_scheduled_task_from_public_director: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Suspicious Reg exe Process Unit Test: - CIM_version: 4.20.2 +suspicious_wevtutil_usage: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Suspicious Scheduled Task from Public Directory Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Suspicious mshta child process Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -System Information Discovery Detection Unit Test: - CIM_version: 4.20.2 +system_information_discovery_detection: + cim_version: 4.20.2 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm -System Processes Run From Unexpected Locations Unit Test: - CIM_version: 4.20.2 +system_processes_run_from_unexpected_locations: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -Time Provider Persistence Registry Unit Test: - CIM_version: 4.20.2 +time_provider_persistence_registr: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -USN Journal Deletion Unit Test: - CIM_version: 4.20.2 +unified_messaging_service_spawning_a_process: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Unified Messaging Service Spawning a Process Unit Test: - CIM_version: 4.20.2 +uninstall_app_using_msiexec: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Uninstall App Using MsiExec Unit Test: - CIM_version: 4.20.2 - supported_tas: - - Splunk_TA_bit9-carbonblack -Unload Sysmon Filter Driver Unit Test: - CIM_version: 4.20.2 +unload_sysmon_filter_driver: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -WBAdmin Delete System Backups Unit Test: - CIM_version: 4.20.2 +usn_journal_deletion: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +wbadmin_delete_system_backups: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR -WSReset UAC Bypass Unit Test: - CIM_version: 4.20.2 +wget_download_and_bash_execution: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Windows AdFind Exe Unit Test: - CIM_version: 4.20.2 +windows_adfind_exe: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -Windows Disable Antispyware Reg Unit Test: - CIM_version: 4.20.2 +windows_disableantispyware_reg: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack -XSL Script Execution With WMIC Unit Test: - CIM_version: 4.20.2 +wsreset_uac_bypass: + cim_version: 4.20.2 + supported_tas: + - Splunk_TA_bit9-carbonblack +xsl_script_execution_with_wmic: + cim_version: 4.20.2 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index 9bd3569e75..d4261fa210 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -30,12 +30,14 @@ def fetch_ta_cim_mapping_report(file_name): def load_file(file_path): - with open(file_path, "r", encoding="utf-8") as stream: + try: - file = list(yaml.safe_load_all(stream))[0] + with open(file_path, "r", encoding="utf-8") as stream: + file = list(yaml.safe_load_all(stream))[0] + return file except yaml.YAMLError as exc: sys.exit("ERROR: reading {0}".format(file_path)) - return file + def map_required_fields(cim_summary, datamodel, required_fields): @@ -140,24 +142,24 @@ def main(): detection_types = ["cloud", "endpoint", "network"] # clone security content repository - security_content_repo_obj = git.Repo.clone_from( - "https://" - + github_token - + ":x-oauth-basic@github.com/" - + security_content_repo, - "security_content", - branch=security_content_branch, - ) + # security_content_repo_obj = git.Repo.clone_from( + # "https://" + # + github_token + # + ":x-oauth-basic@github.com/" + # + security_content_repo, + # "security_content", + # branch=security_content_branch, + # ) - # clone ta cim field reports repository - ta_cim_field_reports_obj = git.Repo.clone_from( - "https://" - + github_token - + ":x-oauth-basic@github.com/" - + "splunk/ta-cim-field-reports", - "ta_cim_mapping_reports", - branch="feat/cim-field-mapping", - ) + # # clone ta cim field reports repository + # ta_cim_field_reports_obj = git.Repo.clone_from( + # "https://" + # + github_token + # + ":x-oauth-basic@github.com/" + # + "splunk/ta-cim-field-reports", + # "ta_cim_mapping_reports", + # branch="feat/cim-field-mapping", + # ) # iterate for every detection types detection_ta_mapping = {} @@ -170,15 +172,26 @@ def main(): supported_ta_list = [] tas_with_data_list = [] detection_obj = load_file(filepath) - detection_name = detection_obj["name"] source_type = ( detection_obj.get("tests")[0] .get("attack_data")[0] .get("sourcetype") ) + detection_file_name = ( + detection_obj.get("tests")[0] + .get("file") + .rsplit("/", 1)[1] + .strip(".yml") + ) filepath = "security_content/detections/" + detection_obj.get("tests")[ 0 ].get("file") + try: + fo = open(filepath) + except FileNotFoundError: + continue + + if is_valid_detection_file(filepath): for ta_cim_mapping_file in os.listdir( "./ta_cim_mapping_reports/ta_cim_mapping/cim_mapping_reports/latest/" @@ -208,62 +221,62 @@ def main(): tas_with_data_list.append( ta_cim_map.get("ta_name").get("name") ) - detection_ta_mapping[detection_name] = {} + detection_ta_mapping[detection_file_name] = {} if supported_ta_list: keyname = "supported_tas" print(filepath) - enrich_detection_file(filepath, cim_version, "CIM_version") + enrich_detection_file(filepath, cim_version, "cim_version") enrich_detection_file(filepath, supported_ta_list, keyname) - detection_ta_mapping[detection_name][ - "CIM_version" + detection_ta_mapping[detection_file_name][ + "cim_version" ] = cim_version - detection_ta_mapping[detection_name][ + detection_ta_mapping[detection_file_name][ keyname ] = supported_ta_list if tas_with_data_list: keyname = "tas_with_data" enrich_detection_file(filepath, tas_with_data_list, keyname) - detection_ta_mapping[detection_name][ + detection_ta_mapping[detection_file_name][ keyname ] = tas_with_data_list - security_content_repo_obj.index.add( - [filepath.strip("security_content/")] - ) + # security_content_repo_obj.index.add( + # [filepath.strip("security_content/")] + # ) print("done") with io.open( - r"./security_content_automation/detection_ta_mapping.yaml", "w", encoding="utf8" + r"./security_content_automation/detection_ta_mapping.yml", "w", encoding="utf8" ) as outfile: yaml.safe_dump( detection_ta_mapping, outfile, default_flow_style=False, allow_unicode=True ) - security_content_repo_obj.index.commit( - "Updated detection files with supported TA list." - ) + # security_content_repo_obj.index.commit( + # "Updated detection files with supported TA list." + # ) - epoch_time = str(int(time.time())) - branch_name = "security_content_automation_" + epoch_time - security_content_repo_obj.git.checkout("-b", branch_name) + # epoch_time = str(int(time.time())) + # branch_name = "security_content_automation_" + epoch_time + # security_content_repo_obj.git.checkout("-b", branch_name) - security_content_repo_obj.git.push("--set-upstream", "origin", branch_name) - repo = g.get_repo("kirtankhatana-crest/security_content") + # security_content_repo_obj.git.push("--set-upstream", "origin", branch_name) + # repo = g.get_repo("kirtankhatana-crest/security_content") - pr = repo.create_pull( - title="Enrich Detection PR " + branch_name, - body="This is a dummy PR", - head=branch_name, - base="develop", - ) + # pr = repo.create_pull( + # title="Enrich Detection PR " + branch_name, + # body="This is a dummy PR", + # head=branch_name, + # base="develop", + # ) - try: - shutil.rmtree("./security_content") - shutil.rmtree("./ta_cim_mapping_reports") - except OSError as e: - print("Error: %s - %s." % (e.filename, e.strerror)) + # try: + # shutil.rmtree("./security_content") + # shutil.rmtree("./ta_cim_mapping_reports") + # except OSError as e: + # print("Error: %s - %s." % (e.filename, e.strerror)) if __name__ == "__main__": From 77f963cd112567fcdcb8b1d56801363e357de037 Mon Sep 17 00:00:00 2001 From: Detection Testing Service Date: Wed, 22 Dec 2021 18:30:21 +0530 Subject: [PATCH 04/25] test:updated detection-ta-mapping.yml --- .../detection_ta_mapping.yml | 270 +++++++++--------- .../enrich_detections.py | 114 ++++---- 2 files changed, 193 insertions(+), 191 deletions(-) diff --git a/security_content_automation/detection_ta_mapping.yml b/security_content_automation/detection_ta_mapping.yml index e19217d0c5..c9ba50693b 100644 --- a/security_content_automation/detection_ta_mapping.yml +++ b/security_content_automation/detection_ta_mapping.yml @@ -1,5 +1,5 @@ abnormally_high_number_of_cloud_infrastructure_api_calls: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_nix @@ -17,7 +17,7 @@ abnormally_high_number_of_cloud_infrastructure_api_calls: tas_with_data: - Splunk_TA_aws-kinesis-firehose abnormally_high_number_of_cloud_security_group_api_calls: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_nix @@ -29,73 +29,74 @@ abnormally_high_number_of_cloud_security_group_api_calls: - splunk_ta_o365 - Splunk_TA_cyberark - Splunk_TA_box + - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce tas_with_data: - Splunk_TA_aws-kinesis-firehose active_setup_registry_autostart: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack add_defaultuser_and_password_in_registr: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack allow_inbound_traffic_by_firewall_rule_registr: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack allow_operation_with_consent_admin: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack anomalous_usage_of_7zip: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack attacker_tools_on_endpoint: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows attempt_to_add_certificate_to_untrusted_store: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack auto_admin_logon_registry_entr: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack batch_file_write_to_system32: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR bcdedit_command_back_to_normal_mode_boot: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack bcdedit_failure_recovery_modification: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR change_default_file_association: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack change_to_safe_mode_with_network_config: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack check_elevated_cmd_using_whoami: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack cloud_api_calls_from_previously_unseen_user_roles: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose - Splunk_TA_rsa_securid_cas @@ -106,31 +107,31 @@ cloud_api_calls_from_previously_unseen_user_roles: tas_with_data: - Splunk_TA_aws-kinesis-firehose cloud_compute_instance_created_by_previously_unseen_user: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: - Splunk_TA_aws-kinesis-firehose cloud_compute_instance_created_in_previously_unused_region: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: - Splunk_TA_aws-kinesis-firehose cloud_compute_instance_created_with_previously_unseen_image: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: - Splunk_TA_aws-kinesis-firehose cloud_compute_instance_created_with_previously_unseen_instance_type: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose tas_with_data: - Splunk_TA_aws-kinesis-firehose cloud_instance_modified_with_previously_unseen_user: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_nix @@ -146,7 +147,7 @@ cloud_instance_modified_with_previously_unseen_user: tas_with_data: - Splunk_TA_aws-kinesis-firehose cloud_provisioning_from_previously_unseen_cit: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid @@ -162,7 +163,7 @@ cloud_provisioning_from_previously_unseen_cit: tas_with_data: - Splunk_TA_aws-kinesis-firehose cloud_provisioning_from_previously_unseen_countr: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid @@ -178,7 +179,7 @@ cloud_provisioning_from_previously_unseen_countr: tas_with_data: - Splunk_TA_aws-kinesis-firehose cloud_provisioning_from_previously_unseen_ip_address: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid @@ -192,7 +193,7 @@ cloud_provisioning_from_previously_unseen_ip_address: tas_with_data: - Splunk_TA_aws-kinesis-firehose cloud_provisioning_from_previously_unseen_region: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid @@ -208,122 +209,122 @@ cloud_provisioning_from_previously_unseen_region: tas_with_data: - Splunk_TA_aws-kinesis-firehose curl_download_and_bash_execution: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack detect_exchange_web_she: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR detect_regasm_spawning_a_process: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack detect_regsvcs_spawning_a_process: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack detect_sharphound_command_line_arguments: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack detect_use_of_cmd_exe_to_launch_script_interpreters: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disable_amsi_through_registr: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disable_etw_through_registr: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disable_logs_using_wevtuti: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disable_registry_too: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disable_schedule_task: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR disable_windows_app_hotkeys: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disable_windows_behavior_monitoring: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disabling_cmd_application: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disabling_controlpane: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disabling_folderoptions_windows_feature: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disabling_norun_windows_app: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disabling_systemrestore_in_registr: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack disabling_task_manager: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack dns_query_length_with_high_standard_deviation: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_isc-bind - Splunk_TA_CrowdStrike_FDR - Splunk_TA_infoblox domain_account_discovery_with_net_app: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack domain_account_discovery_with_wmic: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack dsquery_domain_discover: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR dump_lsass_via_procdump: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR enable_rdp_in_other_port_number: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack eventvwr_uac_bypass: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack excessive_attempt_to_disable_services: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR excessive_number_of_distinct_processes_created_in_windows_temp_folder: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack @@ -333,11 +334,11 @@ excessive_number_of_distinct_processes_created_in_windows_temp_folder: tas_with_data: - Splunk_TA_windows excessive_number_of_service_control_start_as_disabled: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack excessive_number_of_taskhost_processes: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack @@ -346,31 +347,31 @@ excessive_number_of_taskhost_processes: tas_with_data: - Splunk_TA_windows excessive_usage_of_cacls_app: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR excessive_usage_of_taskki: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR executables_or_script_creation_in_suspicious_path: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR execute_javascript_with_jscript_com_clsid: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack execution_of_file_with_multiple_extensions: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows file_with_samsam_extension: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack @@ -380,54 +381,54 @@ file_with_samsam_extension: - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR firewall_allowed_program_enable: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack fodhelper_uac_bypass: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack fsutil_zeroing_file: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack get_aduserresultantpasswordpolicy_with_powershe: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack get_domainpolicy_with_powershe: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack get_domainuser_with_powershe: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack getwmiobject_ds_user_with_powershe: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack hide_user_account_from_sign_in_screen: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack hiding_files_and_directories_with_attrib_exe: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows icacls_deny_command: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR icacls_grant_command: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR java_class_file_download_by_java_user_agent: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_citrix-netscaler - Splunk_TA_nginx @@ -438,32 +439,32 @@ java_class_file_download_by_java_user_agent: - Splunk_TA_mcafee-wg - Splunk_TA_cisco-wsa jscript_execution_using_cscript_app: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack net_profiler_uac_bypass: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack nltest_domain_trust_discover: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack ntdsutil_export_ntds: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack odify_acl_permission_to_files_or_folder: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR ogon_script_event_trigger_execution: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack overwriting_accessibility_binaries: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_nix - Splunk_TA_ossec @@ -474,11 +475,11 @@ overwriting_accessibility_binaries: - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR permission_modification_using_takeown_app: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack powershell_execute_com_object: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_cisco-ucs - Splunk_TA_citrix-netscaler @@ -520,6 +521,7 @@ powershell_execute_com_object: - Splunk_TA_ibm-was - Splunk_TA_microsoft-hyperv - Splunk_TA_windows + - Splunk_TA_stream_wire_data - Splunk_TA_mcafee-wg - Splunk_TA_isc-dhcp - Splunk_TA_websense-dlp @@ -538,59 +540,59 @@ powershell_execute_com_object: tas_with_data: - Splunk_TA_windows prevent_automatic_repair_mode_using_bcdedit: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack print_processor_registry_autostart: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack process_creating_lnk_file_in_suspicious_location: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR process_execution_via_wmi: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR processes_launching_netsh: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack reg_exe_manipulating_windows_services_registry_keys: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR registry_keys_used_for_persistence: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack remote_wmi_command_attempt: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack resize_shadowstorage_volume: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR revil_common_exec_parameter: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack revil_registry_entr: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack ryuk_wake_on_lan_command: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack samsam_test_file_write: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack @@ -600,35 +602,35 @@ samsam_test_file_write: - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR sc_exe_manipulating_windows_services: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR scheduled_task_deleted_or_created_via_cmd: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack schtasks_run_task_on_demand: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR schtasks_scheduling_job_on_remote_syste: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR schtasks_used_for_forcing_a_reboot: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR screensaver_event_trigger_execution: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack script_execution_via_wmi: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack @@ -636,38 +638,38 @@ script_execution_via_wmi: - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm sdclt_uac_bypass: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack secretdumps_offline_ntds_dumping_too: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack services_escalate_exe: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack set_default_powershell_execution_policy_to_unrestricted_or_bypass: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack shim_database_installation_with_suspicious_parameters: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR short_lived_windows_accounts: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose - Splunk_TA_cyberark silentcleanup_uac_bypass: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack single_letter_process_on_endpoint: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack @@ -675,53 +677,53 @@ single_letter_process_on_endpoint: - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm slui_runas_elevated: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack slui_spawning_a_process: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack smpeng_application_dll_side_loading: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR spoolsv_writing_a_d: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR start_up_during_safe_mode_boot: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack suspicious_mshta_child_process: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack suspicious_process_file_path: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack suspicious_reg_exe_process: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR suspicious_scheduled_task_from_public_director: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack suspicious_wevtutil_usage: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR system_information_discovery_detection: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack @@ -729,53 +731,53 @@ system_information_discovery_detection: - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm system_processes_run_from_unexpected_locations: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR time_provider_persistence_registr: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack unified_messaging_service_spawning_a_process: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack uninstall_app_using_msiexec: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack unload_sysmon_filter_driver: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR usn_journal_deletion: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack wbadmin_delete_system_backups: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR wget_download_and_bash_execution: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack windows_adfind_exe: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack windows_disableantispyware_reg: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack wsreset_uac_bypass: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack xsl_script_execution_with_wmic: - cim_version: 4.20.2 + cim_version: 5.0.0 supported_tas: - Splunk_TA_bit9-carbonblack diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index d4261fa210..8d96cf197b 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -30,14 +30,13 @@ def fetch_ta_cim_mapping_report(file_name): def load_file(file_path): - - try: - with open(file_path, "r", encoding="utf-8") as stream: - file = list(yaml.safe_load_all(stream))[0] - return file - except yaml.YAMLError as exc: - sys.exit("ERROR: reading {0}".format(file_path)) - + + try: + with open(file_path, "r", encoding="utf-8") as stream: + file = list(yaml.safe_load_all(stream))[0] + return file + except yaml.YAMLError as exc: + sys.exit("ERROR: reading {0}".format(file_path)) def map_required_fields(cim_summary, datamodel, required_fields): @@ -142,24 +141,24 @@ def main(): detection_types = ["cloud", "endpoint", "network"] # clone security content repository - # security_content_repo_obj = git.Repo.clone_from( - # "https://" - # + github_token - # + ":x-oauth-basic@github.com/" - # + security_content_repo, - # "security_content", - # branch=security_content_branch, - # ) + security_content_repo_obj = git.Repo.clone_from( + "https://" + + github_token + + ":x-oauth-basic@github.com/" + + security_content_repo, + "security_content", + branch=security_content_branch, + ) - # # clone ta cim field reports repository - # ta_cim_field_reports_obj = git.Repo.clone_from( - # "https://" - # + github_token - # + ":x-oauth-basic@github.com/" - # + "splunk/ta-cim-field-reports", - # "ta_cim_mapping_reports", - # branch="feat/cim-field-mapping", - # ) + # clone ta cim field reports repository + ta_cim_field_reports_obj = git.Repo.clone_from( + "https://" + + github_token + + ":x-oauth-basic@github.com/" + + "splunk/ta-cim-field-reports", + "ta_cim_mapping_reports", + branch="main", + ) # iterate for every detection types detection_ta_mapping = {} @@ -167,16 +166,16 @@ def main(): for subdir, _, files in os.walk(f"security_content/tests/{detection_type}"): print(subdir) + for file in files: filepath = subdir + os.sep + file supported_ta_list = [] tas_with_data_list = [] detection_obj = load_file(filepath) - source_type = ( - detection_obj.get("tests")[0] - .get("attack_data")[0] - .get("sourcetype") - ) + source_types = [] + for data in detection_obj.get("tests")[0].get("attack_data"): + source_types.append(data.get("sourcetype")) + detection_file_name = ( detection_obj.get("tests")[0] .get("file") @@ -191,7 +190,6 @@ def main(): except FileNotFoundError: continue - if is_valid_detection_file(filepath): for ta_cim_mapping_file in os.listdir( "./ta_cim_mapping_reports/ta_cim_mapping/cim_mapping_reports/latest/" @@ -217,10 +215,12 @@ def main(): ta_cim_map.get("ta_name").get("name") ) ta_sourcetype = ta_cim_map["sourcetypes"] - if source_type in ta_sourcetype: - tas_with_data_list.append( - ta_cim_map.get("ta_name").get("name") - ) + for source_type in source_types: + + if source_type in ta_sourcetype and ta_cim_map.get("ta_name").get("name") not in tas_with_data_list: + tas_with_data_list.append( + ta_cim_map.get("ta_name").get("name") + ) detection_ta_mapping[detection_file_name] = {} if supported_ta_list: @@ -242,9 +242,9 @@ def main(): keyname ] = tas_with_data_list - # security_content_repo_obj.index.add( - # [filepath.strip("security_content/")] - # ) + security_content_repo_obj.index.add( + [filepath.strip("security_content/")] + ) print("done") with io.open( @@ -254,29 +254,29 @@ def main(): detection_ta_mapping, outfile, default_flow_style=False, allow_unicode=True ) - # security_content_repo_obj.index.commit( - # "Updated detection files with supported TA list." - # ) + security_content_repo_obj.index.commit( + "Updated detection files with supported TA list." + ) - # epoch_time = str(int(time.time())) - # branch_name = "security_content_automation_" + epoch_time - # security_content_repo_obj.git.checkout("-b", branch_name) + epoch_time = str(int(time.time())) + branch_name = "security_content_automation_" + epoch_time + security_content_repo_obj.git.checkout("-b", branch_name) - # security_content_repo_obj.git.push("--set-upstream", "origin", branch_name) - # repo = g.get_repo("kirtankhatana-crest/security_content") + security_content_repo_obj.git.push("--set-upstream", "origin", branch_name) + repo = g.get_repo("kirtankhatana-crest/security_content") - # pr = repo.create_pull( - # title="Enrich Detection PR " + branch_name, - # body="This is a dummy PR", - # head=branch_name, - # base="develop", - # ) + pr = repo.create_pull( + title="Enrich Detection PR " + branch_name, + body="This is a dummy PR", + head=branch_name, + base="develop", + ) - # try: - # shutil.rmtree("./security_content") - # shutil.rmtree("./ta_cim_mapping_reports") - # except OSError as e: - # print("Error: %s - %s." % (e.filename, e.strerror)) + try: + shutil.rmtree("./security_content") + shutil.rmtree("./ta_cim_mapping_reports") + except OSError as e: + print("Error: %s - %s." % (e.filename, e.strerror)) if __name__ == "__main__": From a5dcbab86c8639cb217fe359fbebc5b64124eaad Mon Sep 17 00:00:00 2001 From: Detection Testing Service Date: Fri, 24 Dec 2021 13:31:15 +0530 Subject: [PATCH 05/25] test: updated code with some minor fixes --- .github/workflows/build-and-validate.yml | 8 ++ .../enrich_detections.py | 95 ++++++------------- security_content_automation/requirements.txt | 3 +- 3 files changed, 38 insertions(+), 68 deletions(-) diff --git a/.github/workflows/build-and-validate.yml b/.github/workflows/build-and-validate.yml index 4d2fe4bbf1..2f8500ba6d 100644 --- a/.github/workflows/build-and-validate.yml +++ b/.github/workflows/build-and-validate.yml @@ -464,6 +464,14 @@ jobs: source venv/bin/activate python3 bin/doc_gen.py --path . --output docs -v + - name: Enrich detections with TAs + env: + GIT_TOKEN: ${{ secrets.GIT_TOKEN }} + run: | + source venv/bin/activate + python3 -m pip install security_content_automation/requirements.txt + python3 security_content_automation/enrich_detections.py + - name: Make YAMLs Pretty run: | source venv/bin/activate diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index 8d96cf197b..b1d0f986af 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -1,21 +1,15 @@ -# 1. Take github token, branch_name from user to raise a PR for enriched detection of security_content repo -# 2. Iterate through each detection file -# 3. For each detection iterate through ta_cim_mapping report -# 4. map detection file and ta_cim_mapping reports and finalise the TA required for particular detection -# 5. Add the list of TA's in detection file -# 6. Create a new branch and raise an MR for it - -import os -import git -import sys -import shutil -import yaml -import json -import time import argparse -import logging import io +import json +import logging +import os import re +import shutil +import sys +import time + +import git +import yaml from github import Github @@ -75,14 +69,7 @@ def map_required_fields(cim_summary, datamodel, required_fields): def is_valid_detection_file(filepath) -> bool: - """ - check if detection file have valid analytic type and have valid - data-model name. - :param detection_test_path: detection test path i.e. security_content/tests/cloud - :param test_file: detection test file name - :param detection_products: detection tag product list for which detection test will filterised - :return: boolean - """ + detection_analytic_type = ["ttp", "anomaly"] detection_with_valid_analytic_type = False detection_with_valid_datamodel = False @@ -98,7 +85,6 @@ def is_valid_detection_file(filepath) -> bool: def enrich_detection_file(file, ta_list, keyname): - # file_path = 'security_content/detections/' + test['detection_result']['detection_file'] detection_obj = load_file(file) detection_obj["tags"][keyname] = ta_list @@ -108,37 +94,16 @@ def enrich_detection_file(file, ta_list, keyname): def main(): - parser = argparse.ArgumentParser( - description="Enrich detections with relevant TA names" - ) - parser.add_argument( - "-scr", - "--security_content_repo", - required=False, - default="kirtankhatana-crest/security_content", - help="specify the url of the security content repository", - ) - parser.add_argument( - "-scb", - "--security_content_branch", - required=False, - default="develop", - help="specify the security content branch", - ) - parser.add_argument( - "-gt", - "--github_token", - required=False, - default=os.environ.get("GIT_TOKEN"), - help="specify the github token for the PR", - ) + security_content_repo = "splunk/security_content" + security_content_branch = "develop" - args = parser.parse_args() - security_content_repo = args.security_content_repo - security_content_branch = args.security_content_branch - github_token = args.github_token + ta_cim_field_reports_repo = "splunk/ta-cim-field-reports" + ta_cim_field_reports_branch = "main" + github_token = os.environ.get("GIT_TOKEN") g = Github(github_token) detection_types = ["cloud", "endpoint", "network"] + cim_report_path = "ta_cim_mapping_reports/ta_cim_mapping/cim_mapping_reports/latest/" + detection_ta_mapping = {} # clone security content repository security_content_repo_obj = git.Repo.clone_from( @@ -155,17 +120,15 @@ def main(): "https://" + github_token + ":x-oauth-basic@github.com/" - + "splunk/ta-cim-field-reports", + + ta_cim_field_reports_repo, "ta_cim_mapping_reports", - branch="main", + branch=ta_cim_field_reports_branch, ) # iterate for every detection types - detection_ta_mapping = {} for detection_type in detection_types: for subdir, _, files in os.walk(f"security_content/tests/{detection_type}"): - print(subdir) for file in files: filepath = subdir + os.sep + file @@ -185,18 +148,16 @@ def main(): filepath = "security_content/detections/" + detection_obj.get("tests")[ 0 ].get("file") - try: - fo = open(filepath) - except FileNotFoundError: + if not os.path.isfile(filepath): continue if is_valid_detection_file(filepath): for ta_cim_mapping_file in os.listdir( - "./ta_cim_mapping_reports/ta_cim_mapping/cim_mapping_reports/latest/" + cim_report_path ): ta_cim_map = fetch_ta_cim_mapping_report( - "./ta_cim_mapping_reports/ta_cim_mapping/cim_mapping_reports/latest/" + cim_report_path + ta_cim_mapping_file ) @@ -225,7 +186,6 @@ def main(): if supported_ta_list: keyname = "supported_tas" - print(filepath) enrich_detection_file(filepath, cim_version, "cim_version") enrich_detection_file(filepath, supported_ta_list, keyname) detection_ta_mapping[detection_file_name][ @@ -246,14 +206,15 @@ def main(): [filepath.strip("security_content/")] ) - print("done") with io.open( - r"./security_content_automation/detection_ta_mapping.yml", "w", encoding="utf8" + r"./security_content/security_content_automation/detection_ta_mapping.yml", "w", encoding="utf8" ) as outfile: yaml.safe_dump( detection_ta_mapping, outfile, default_flow_style=False, allow_unicode=True ) - + security_content_repo_obj.index.add( + ["security_content_automation/detection_ta_mapping.yml"] + ) security_content_repo_obj.index.commit( "Updated detection files with supported TA list." ) @@ -263,11 +224,11 @@ def main(): security_content_repo_obj.git.checkout("-b", branch_name) security_content_repo_obj.git.push("--set-upstream", "origin", branch_name) - repo = g.get_repo("kirtankhatana-crest/security_content") + repo = g.get_repo("splunk/security_content") pr = repo.create_pull( title="Enrich Detection PR " + branch_name, - body="This is a dummy PR", + body="Enriched the detections with supported TAs", head=branch_name, base="develop", ) diff --git a/security_content_automation/requirements.txt b/security_content_automation/requirements.txt index 8552a5cfcb..3cfcdd61da 100644 --- a/security_content_automation/requirements.txt +++ b/security_content_automation/requirements.txt @@ -1,2 +1,3 @@ GitPython==3.1.24 -PyYAML==6.0 \ No newline at end of file +PyYAML==6.0 +PyGithub==1.55 \ No newline at end of file From 8f4c7ea68f0ab8c5280e8aaeea4db1c23db979b0 Mon Sep 17 00:00:00 2001 From: Detection Testing Service Date: Mon, 27 Dec 2021 16:03:28 +0530 Subject: [PATCH 06/25] test: encoded git token --- .../enrich_detections.py | 36 ++++++++++++------- 1 file changed, 23 insertions(+), 13 deletions(-) diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index b1d0f986af..1769bb4214 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -1,4 +1,4 @@ -import argparse +import base64 import io import json import logging @@ -99,10 +99,17 @@ def main(): ta_cim_field_reports_repo = "splunk/ta-cim-field-reports" ta_cim_field_reports_branch = "main" - github_token = os.environ.get("GIT_TOKEN") + + # Decoding GIT_TOKEN from base64 + git_token_base64_bytes = os.environ.get("GIT_TOKEN").encode('ascii') + git_token_bytes = base64.b64decode(git_token_base64_bytes) + github_token = git_token_bytes.decode('ascii') + g = Github(github_token) detection_types = ["cloud", "endpoint", "network"] - cim_report_path = "ta_cim_mapping_reports/ta_cim_mapping/cim_mapping_reports/latest/" + cim_report_path = ( + "ta_cim_mapping_reports/ta_cim_mapping/cim_mapping_reports/latest/" + ) detection_ta_mapping = {} # clone security content repository @@ -129,7 +136,7 @@ def main(): for detection_type in detection_types: for subdir, _, files in os.walk(f"security_content/tests/{detection_type}"): - + for file in files: filepath = subdir + os.sep + file supported_ta_list = [] @@ -152,13 +159,10 @@ def main(): continue if is_valid_detection_file(filepath): - for ta_cim_mapping_file in os.listdir( - cim_report_path - ): + for ta_cim_mapping_file in os.listdir(cim_report_path): ta_cim_map = fetch_ta_cim_mapping_report( - cim_report_path - + ta_cim_mapping_file + cim_report_path + ta_cim_mapping_file ) detection_obj = load_file(filepath) @@ -178,7 +182,11 @@ def main(): ta_sourcetype = ta_cim_map["sourcetypes"] for source_type in source_types: - if source_type in ta_sourcetype and ta_cim_map.get("ta_name").get("name") not in tas_with_data_list: + if ( + source_type in ta_sourcetype + and ta_cim_map.get("ta_name").get("name") + not in tas_with_data_list + ): tas_with_data_list.append( ta_cim_map.get("ta_name").get("name") ) @@ -207,14 +215,16 @@ def main(): ) with io.open( - r"./security_content/security_content_automation/detection_ta_mapping.yml", "w", encoding="utf8" + r"./security_content/security_content_automation/detection_ta_mapping.yml", + "w", + encoding="utf8", ) as outfile: yaml.safe_dump( detection_ta_mapping, outfile, default_flow_style=False, allow_unicode=True ) security_content_repo_obj.index.add( - ["security_content_automation/detection_ta_mapping.yml"] - ) + ["security_content_automation/detection_ta_mapping.yml"] + ) security_content_repo_obj.index.commit( "Updated detection files with supported TA list." ) From c13428f57b84d5db8a9bedfc67279388d16068bb Mon Sep 17 00:00:00 2001 From: truptilangalia-crest <79827058+truptilangalia-crest@users.noreply.github.com> Date: Mon, 27 Dec 2021 17:10:22 +0530 Subject: [PATCH 07/25] Update README.md --- README.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/README.md b/README.md index a51b983a1d..bc31b6b48c 100644 --- a/README.md +++ b/README.md @@ -97,6 +97,9 @@ A complete use case, specifically built to detect, investigate, and respond to a * [dashboards/](dashboards/): JSON definitions of Mission Control dashboards, to be used as a response task. Currently not used. * [macros/](macros/): Implements Splunk’s search macros, shortcuts to commonly used search patterns like sysmon source type. More on how macros are used to customize content below. * [lookups/](lookups/): Implements Splunk’s lookup, usually to provide a list of static values like commonly used ransomware extensions. +* [security_content_automation/](security_content_automation/): It contains scripts for enriching detection with relevant supported TAs and for publishing github release assets to Pre-QA on every tag release. + + # Contribution 🥰 We welcome feedback and contributions from the community! Please see our [contributing to the project](https://github.com/splunk/security_content/wiki/Contributing-to-the-Project) for more information on how to get involved. From 9da1778b53f7584ed94b2e0a30b9059c07fdbf5a Mon Sep 17 00:00:00 2001 From: truptilangalia-crest <79827058+truptilangalia-crest@users.noreply.github.com> Date: Tue, 28 Dec 2021 17:57:15 +0530 Subject: [PATCH 08/25] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index bc31b6b48c..709f42e9b2 100644 --- a/README.md +++ b/README.md @@ -97,7 +97,7 @@ A complete use case, specifically built to detect, investigate, and respond to a * [dashboards/](dashboards/): JSON definitions of Mission Control dashboards, to be used as a response task. Currently not used. * [macros/](macros/): Implements Splunk’s search macros, shortcuts to commonly used search patterns like sysmon source type. More on how macros are used to customize content below. * [lookups/](lookups/): Implements Splunk’s lookup, usually to provide a list of static values like commonly used ransomware extensions. -* [security_content_automation/](security_content_automation/): It contains scripts for enriching detection with relevant supported TAs and for publishing github release assets to Pre-QA on every tag release. +* [security_content_automation/](security_content_automation/): It contains scripts for enriching detection with relevant supported TAs and also contains script for publishing github release assets to [Pre-QA artifactory](https://repo.splunk.com/artifactory/Solutions/DA/Pre-QA/) on every tag release. From 500986bfb4afdc8acd4683fa36be394c91f35d06 Mon Sep 17 00:00:00 2001 From: truptilangalia-crest <79827058+truptilangalia-crest@users.noreply.github.com> Date: Tue, 28 Dec 2021 18:00:14 +0530 Subject: [PATCH 09/25] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 709f42e9b2..f33a34b3d7 100644 --- a/README.md +++ b/README.md @@ -97,7 +97,7 @@ A complete use case, specifically built to detect, investigate, and respond to a * [dashboards/](dashboards/): JSON definitions of Mission Control dashboards, to be used as a response task. Currently not used. * [macros/](macros/): Implements Splunk’s search macros, shortcuts to commonly used search patterns like sysmon source type. More on how macros are used to customize content below. * [lookups/](lookups/): Implements Splunk’s lookup, usually to provide a list of static values like commonly used ransomware extensions. -* [security_content_automation/](security_content_automation/): It contains scripts for enriching detection with relevant supported TAs and also contains script for publishing github release assets to [Pre-QA artifactory](https://repo.splunk.com/artifactory/Solutions/DA/Pre-QA/) on every tag release. +* [security_content_automation/](security_content_automation/): It contains script for enriching detection with relevant supported TAs and also contains script for publishing release build to [Pre-QA artifactory](https://repo.splunk.com/artifactory/Solutions/DA/Pre-QA/) on every tag release. From d7b159aea37be2a511b1f7127c68f2055dc6d6ed Mon Sep 17 00:00:00 2001 From: Arjun Khunti Date: Wed, 29 Dec 2021 13:27:38 +0530 Subject: [PATCH 10/25] test: fixed a typo --- security_content_automation/enrich_detections.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index 1769bb4214..ca35b5ba7f 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -19,7 +19,7 @@ def fetch_ta_cim_mapping_report(file_name): cim_field_report = json.load(file_content) return cim_field_report except Exception as error: - error_message = f"Unexpected error occurred while reading file. Error: {error}" + error_message = "Unexpected error occurred while reading file." logging.error(error_message) From 7fab0d38e02cb2a53ed0f8be789171b334395eb9 Mon Sep 17 00:00:00 2001 From: Detection Testing Service Date: Thu, 30 Dec 2021 20:48:04 +0530 Subject: [PATCH 11/25] test: git token variable name update --- .github/workflows/build-and-validate.yml | 2 +- security_content_automation/enrich_detections.py | 9 +++++---- 2 files changed, 6 insertions(+), 5 deletions(-) diff --git a/.github/workflows/build-and-validate.yml b/.github/workflows/build-and-validate.yml index 2f8500ba6d..1a41ed39a9 100644 --- a/.github/workflows/build-and-validate.yml +++ b/.github/workflows/build-and-validate.yml @@ -466,7 +466,7 @@ jobs: - name: Enrich detections with TAs env: - GIT_TOKEN: ${{ secrets.GIT_TOKEN }} + GITHUB_ACCESS_TOKEN: ${{ secrets.GITHUB_ACCESS_TOKEN }} run: | source venv/bin/activate python3 -m pip install security_content_automation/requirements.txt diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index ca35b5ba7f..73c01de2f5 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -100,11 +100,11 @@ def main(): ta_cim_field_reports_repo = "splunk/ta-cim-field-reports" ta_cim_field_reports_branch = "main" - # Decoding GIT_TOKEN from base64 - git_token_base64_bytes = os.environ.get("GIT_TOKEN").encode('ascii') + # Decodin GITHUB_ACCESS_TOKEN from base64 + git_token_base64_bytes = os.environ.get("GITHUB_ACCESS_TOKEN").encode('ascii') git_token_bytes = base64.b64decode(git_token_base64_bytes) github_token = git_token_bytes.decode('ascii') - + g = Github(github_token) detection_types = ["cloud", "endpoint", "network"] cim_report_path = ( @@ -247,7 +247,8 @@ def main(): shutil.rmtree("./security_content") shutil.rmtree("./ta_cim_mapping_reports") except OSError as e: - print("Error: %s - %s." % (e.filename, e.strerror)) + error_message = "Unexpected error occurred while deleting files." + logging.error(error_message) if __name__ == "__main__": From 6fd7a4e81240665383b7c3bcd40d440f41b296b0 Mon Sep 17 00:00:00 2001 From: Detection Testing Service Date: Mon, 17 Jan 2022 14:13:50 +0530 Subject: [PATCH 12/25] test: updated supported_tas to recommended_tas --- ...mber_of_cloud_infrastructure_api_calls.yml | 6 +- ...mber_of_cloud_security_group_api_calls.yml | 7 +- ...alls_from_previously_unseen_user_roles.yml | 6 +- ...ance_created_by_previously_unseen_user.yml | 6 +- ...ce_created_in_previously_unused_region.yml | 6 +- ...e_created_with_previously_unseen_image.yml | 6 +- ...d_with_previously_unseen_instance_type.yml | 6 +- ...e_modified_with_previously_unseen_user.yml | 6 +- ...ovisioning_from_previously_unseen_city.yml | 6 +- ...sioning_from_previously_unseen_country.yml | 6 +- ...ning_from_previously_unseen_ip_address.yml | 6 +- ...isioning_from_previously_unseen_region.yml | 6 +- .../active_setup_registry_autostart.yml | 4 +- ...d_defaultuser_and_password_in_registry.yml | 4 +- .../adsisearcher_account_discovery.yml | 3 +- ...ound_traffic_by_firewall_rule_registry.yml | 4 +- .../allow_operation_with_consent_admin.yml | 4 +- .../endpoint/anomalous_usage_of_7zip.yml | 4 +- .../endpoint/attacker_tools_on_endpoint.yml | 4 +- ..._to_add_certificate_to_untrusted_store.yml | 4 +- .../auto_admin_logon_registry_entry.yml | 4 +- .../endpoint/batch_file_write_to_system32.yml | 4 +- ...dedit_command_back_to_normal_mode_boot.yml | 4 +- .../bcdedit_failure_recovery_modification.yml | 4 +- .../change_default_file_association.yml | 4 +- ...hange_to_safe_mode_with_network_config.yml | 4 +- .../check_elevated_cmd_using_whoami.yml | 4 +- .../curl_download_and_bash_execution.yml | 4 +- .../endpoint/detect_exchange_web_shell.yml | 4 +- .../detect_regasm_spawning_a_process.yml | 4 +- .../detect_regsvcs_spawning_a_process.yml | 4 +- ...tect_sharphound_command_line_arguments.yml | 4 +- ..._cmd_exe_to_launch_script_interpreters.yml | 4 +- .../disable_amsi_through_registry.yml | 4 +- .../endpoint/disable_etw_through_registry.yml | 4 +- .../endpoint/disable_logs_using_wevtutil.yml | 4 +- detections/endpoint/disable_registry_tool.yml | 4 +- detections/endpoint/disable_schedule_task.yml | 4 +- .../endpoint/disable_windows_app_hotkeys.yml | 4 +- .../disable_windows_behavior_monitoring.yml | 4 +- .../endpoint/disabling_cmd_application.yml | 4 +- .../endpoint/disabling_controlpanel.yml | 4 +- ...isabling_folderoptions_windows_feature.yml | 4 +- .../endpoint/disabling_norun_windows_app.yml | 4 +- .../disabling_systemrestore_in_registry.yml | 4 +- .../endpoint/disabling_task_manager.yml | 4 +- .../domain_account_discovery_with_net_app.yml | 4 +- .../domain_account_discovery_with_wmic.yml | 4 +- ...main_group_discovery_with_adsisearcher.yml | 3 +- .../endpoint/dsquery_domain_discovery.yml | 4 +- .../endpoint/dump_lsass_via_procdump.yml | 4 +- ...levated_group_discovery_with_powerview.yml | 3 +- .../enable_rdp_in_other_port_number.yml | 4 +- detections/endpoint/eventvwr_uac_bypass.yml | 4 +- .../excessive_attempt_to_disable_services.yml | 4 +- ...ocesses_created_in_windows_temp_folder.yml | 6 +- ...r_of_service_control_start_as_disabled.yml | 4 +- ...excessive_number_of_taskhost_processes.yml | 6 +- .../endpoint/excessive_usage_of_cacls_app.yml | 4 +- .../endpoint/excessive_usage_of_taskkill.yml | 4 +- ...le_written_in_administrative_smb_share.yml | 3 +- ..._or_script_creation_in_suspicious_path.yml | 4 +- ...cute_javascript_with_jscript_com_clsid.yml | 4 +- ...ution_of_file_with_multiple_extensions.yml | 4 +- .../endpoint/file_with_samsam_extension.yml | 4 +- .../firewall_allowed_program_enable.yml | 4 +- detections/endpoint/fodhelper_uac_bypass.yml | 4 +- detections/endpoint/fsutil_zeroing_file.yml | 4 +- ...ordpolicy_with_powershell_script_block.yml | 3 +- ...et_aduser_with_powershell_script_block.yml | 3 +- ...esultantpasswordpolicy_with_powershell.yml | 4 +- ...ordpolicy_with_powershell_script_block.yml | 3 +- .../get_domainpolicy_with_powershell.yml | 4 +- ...ainpolicy_with_powershell_script_block.yml | 3 +- .../get_domainuser_with_powershell.yml | 4 +- ...omainuser_with_powershell_script_block.yml | 3 +- ...resttrust_with_powershell_script_block.yml | 3 +- ...dcomputer_with_powershell_script_block.yml | 3 +- ...etadgroup_with_powershell_script_block.yml | 3 +- ...rent_user_with_powershell_script_block.yml | 3 +- ...ncomputer_with_powershell_script_block.yml | 3 +- ...ontroller_with_powershell_script_block.yml | 3 +- ...maingroup_with_powershell_script_block.yml | 3 +- ...localuser_with_powershell_script_block.yml | 3 +- ...onnection_with_powershell_script_block.yml | 3 +- ..._computer_with_powershell_script_block.yml | 3 +- ..._ds_group_with_powershell_script_block.yml | 3 +- .../getwmiobject_ds_user_with_powershell.yml | 4 +- ...t_ds_user_with_powershell_script_block.yml | 3 +- ...r_account_with_powershell_script_block.yml | 3 +- .../hide_user_account_from_sign_in_screen.yml | 4 +- ..._files_and_directories_with_attrib_exe.yml | 4 +- detections/endpoint/icacls_deny_command.yml | 4 +- detections/endpoint/icacls_grant_command.yml | 4 +- ...ion_on_remote_endpoint_with_powershell.yml | 3 +- ...class_file_download_by_java_user_agent.yml | 4 +- .../jscript_execution_using_cscript_app.yml | 4 +- ...add_files_in_known_crontab_directories.yml | 3 + .../linux_at_allow_config_file_creation.yml | 3 + .../linux_at_application_execution.yml | 4 + .../linux_change_file_owner_to_root.yml | 4 + .../linux_doas_conf_file_creation.yml | 3 + .../endpoint/linux_doas_tool_execution.yml | 4 + ...ile_created_in_kernel_driver_directory.yml | 3 + ...x_file_creation_in_init_boot_directory.yml | 3 + ...nux_file_creation_in_profile_directory.yml | 3 + ...ert_kernel_module_using_insmod_utility.yml | 4 + ...l_kernel_module_using_modprobe_utility.yml | 4 + .../linux_nopasswd_entry_in_sudoers_file.yml | 4 + ...ss_or_modification_of_sshd_config_file.yml | 4 + ...ux_possible_access_to_credential_files.yml | 4 + .../linux_possible_access_to_sudoers_file.yml | 4 + ...append_command_to_at_allow_config_file.yml | 4 + ..._append_command_to_profile_config_file.yml | 4 + .../linux_possible_ssh_key_file_creation.yml | 3 + .../linux_preload_hijack_library_calls.yml | 4 + ...vice_file_created_in_systemd_directory.yml | 3 + .../endpoint/linux_service_restarted.yml | 4 + .../linux_service_started_or_enabled.yml | 4 + .../linux_setuid_using_chmod_utility.yml | 4 + .../linux_setuid_using_setcap_utility.yml | 4 + .../linux_sudoers_tmp_file_creation.yml | 3 + .../linux_visudo_utility_execution.yml | 4 + .../logon_script_event_trigger_execution.yml | 4 +- ...dify_acl_permission_to_files_or_folder.yml | 4 +- .../msmpeng_application_dll_side_loading.yml | 4 +- ..._authenticate_from_host_using_kerberos.yml | 3 +- ..._authenticate_from_host_using_kerberos.yml | 3 +- ...g_to_authenticate_from_host_using_ntlm.yml | 3 +- ...uthenticate_using_explicit_credentials.yml | 3 +- ..._authenticate_from_host_using_kerberos.yml | 3 +- ...g_to_authenticate_from_host_using_ntlm.yml | 3 +- ...s_failing_to_authenticate_from_process.yml | 3 +- ...tely_failing_to_authenticate_from_host.yml | 3 +- .../endpoint/net_profiler_uac_bypass.yml | 4 +- .../nltest_domain_trust_discovery.yml | 4 +- detections/endpoint/ntdsutil_export_ntds.yml | 4 +- .../overwriting_accessibility_binaries.yml | 4 +- ...mission_modification_using_takeown_app.yml | 4 +- .../powershell_execute_com_object.yml | 8 +- ...up_discovery_with_script_block_logging.yml | 3 +- ...nt_automatic_repair_mode_using_bcdedit.yml | 4 +- ...eating_lnk_file_in_suspicious_location.yml | 4 +- .../endpoint/process_execution_via_wmi.yml | 4 +- .../endpoint/processes_launching_netsh.yml | 4 +- ...ulating_windows_services_registry_keys.yml | 4 +- .../registry_keys_used_for_persistence.yml | 4 +- ...n_via_dcom_and_powershell_script_block.yml | 3 +- ..._via_winrm_and_powershell_script_block.yml | 3 +- ...on_via_wmi_and_powershell_script_block.yml | 3 +- ...ote_system_discovery_with_adsisearcher.yml | 3 +- .../endpoint/remote_wmi_command_attempt.yml | 4 +- .../endpoint/resize_shadowstorage_volume.yml | 4 +- .../endpoint/revil_common_exec_parameter.yml | 4 +- detections/endpoint/revil_registry_entry.yml | 4 +- .../endpoint/ryuk_wake_on_lan_command.yml | 4 +- .../endpoint/samsam_test_file_write.yml | 4 +- .../sc_exe_manipulating_windows_services.yml | 4 +- ...eduled_task_deleted_or_created_via_cmd.yml | 4 +- .../endpoint/schtasks_run_task_on_demand.yml | 4 +- ...htasks_scheduling_job_on_remote_system.yml | 4 +- .../schtasks_used_for_forcing_a_reboot.yml | 4 +- .../screensaver_event_trigger_execution.yml | 4 +- .../endpoint/script_execution_via_wmi.yml | 4 +- detections/endpoint/sdclt_uac_bypass.yml | 4 +- .../secretdumps_offline_ntds_dumping_tool.yml | 4 +- ...incipalnames_discovery_with_powershell.yml | 3 +- detections/endpoint/services_escalate_exe.yml | 4 +- ...ution_policy_to_unrestricted_or_bypass.yml | 4 +- ...nstallation_with_suspicious_parameters.yml | 4 +- .../endpoint/short_lived_windows_accounts.yml | 5 +- .../endpoint/silentcleanup_uac_bypass.yml | 4 +- .../single_letter_process_on_endpoint.yml | 4 +- detections/endpoint/slui_runas_elevated.yml | 4 +- .../endpoint/slui_spawning_a_process.yml | 4 +- detections/endpoint/spoolsv_writing_a_dll.yml | 4 +- .../start_up_during_safe_mode_boot.yml | 4 +- .../suspicious_mshta_child_process.yml | 4 +- .../endpoint/suspicious_process_file_path.yml | 4 +- .../endpoint/suspicious_reg_exe_process.yml | 4 +- ...s_scheduled_task_from_public_directory.yml | 4 +- .../endpoint/suspicious_wevtutil_usage.yml | 4 +- ...system_information_discovery_detection.yml | 4 +- ...rocesses_run_from_unexpected_locations.yml | 4 +- .../time_provider_persistence_registry.yml | 4 +- ...d_messaging_service_spawning_a_process.yml | 4 +- .../endpoint/uninstall_app_using_msiexec.yml | 4 +- .../endpoint/unload_sysmon_filter_driver.yml | 4 +- ..._with_env_vars_powershell_script_block.yml | 3 +- detections/endpoint/usn_journal_deletion.yml | 4 +- .../wbadmin_delete_system_backups.yml | 4 +- .../wget_download_and_bash_execution.yml | 4 +- detections/endpoint/windows_adfind_exe.yml | 4 +- .../windows_disableantispyware_reg.yml | 4 +- ...e_created_with_suspicious_service_path.yml | 3 +- ...ows_service_created_within_public_path.yml | 3 +- detections/endpoint/wsreset_uac_bypass.yml | 4 +- .../xsl_script_execution_with_wmic.yml | 4 +- .../print_processor_registry_autostart.yml | 4 +- ...randomly_generated_scheduled_task_name.yml | 3 +- ...andomly_generated_windows_service_name.yml | 3 +- ..._of_computer_service_tickets_requested.yml | 3 +- ..._remote_endpoint_authentication_events.yml | 5 +- ...ry_length_with_high_standard_deviation.yml | 4 +- .../detection_ta_mapping.yml | 413 ++++++++++++------ .../enrich_detections.py | 20 +- 206 files changed, 705 insertions(+), 527 deletions(-) diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index d8cf44e97d..ee6c454a5d 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -66,8 +66,8 @@ tags: - All_Changes.status risk_score: 15 security_domain: network - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_nix - Splunk_TA_rsa-securid @@ -81,5 +81,5 @@ tags: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: + supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index cd98ed56be..5a3ace2c14 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -72,8 +72,8 @@ tags: - All_Changes.user risk_score: 15 security_domain: network - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_nix - Splunk_TA_rsa-securid @@ -84,7 +84,8 @@ tags: - splunk_ta_o365 - Splunk_TA_cyberark - Splunk_TA_box + - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: + supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml index 67fca34b3f..aae78a3cb3 100644 --- a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml +++ b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml @@ -68,13 +68,13 @@ tags: - All_Changes.object risk_score: 36 security_domain: threat - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_aws-kinesis-firehose - Splunk_TA_rsa_securid_cas - splunk_ta_o365 - Splunk_TA_box - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: + supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index 8b24e673f2..f5b751eb86 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -69,8 +69,8 @@ tags: - All_Changes.vendor_region risk_score: 18 security_domain: threat - cim_version: 4.20.2 + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_aws-kinesis-firehose supported_tas: - Splunk_TA_aws-kinesis-firehose - tas_with_data: - - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml index 05c8aca596..a13257095b 100644 --- a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml +++ b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml @@ -74,8 +74,8 @@ tags: - All_Changes.user risk_score: 42 security_domain: threat - cim_version: 4.20.2 + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_aws-kinesis-firehose supported_tas: - Splunk_TA_aws-kinesis-firehose - tas_with_data: - - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml index a98e27c661..689bdacfb9 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml @@ -69,8 +69,8 @@ tags: - All_Changes.user risk_score: 36 security_domain: threat - cim_version: 4.20.2 + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_aws-kinesis-firehose supported_tas: - Splunk_TA_aws-kinesis-firehose - tas_with_data: - - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index 0d63084016..f3e5904b50 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -69,8 +69,8 @@ tags: - All_Changes.user risk_score: 30 security_domain: threat - cim_version: 4.20.2 + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_aws-kinesis-firehose supported_tas: - Splunk_TA_aws-kinesis-firehose - tas_with_data: - - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml index eab8044aff..4f210a4a96 100644 --- a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml @@ -71,8 +71,8 @@ tags: - All_Changes.user risk_score: 42 security_domain: threat - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_nix - Splunk_TA_rsa-securid @@ -84,5 +84,5 @@ tags: - Splunk_TA_cyberark - Splunk_TA_box - Splunk_TA_salesforce - tas_with_data: + supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml index be22dff240..07b141ead5 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml @@ -90,8 +90,8 @@ tags: - All_Changes.command risk_score: 18 security_domain: threat - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose @@ -103,5 +103,5 @@ tags: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: + supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml index e75d9325c3..c5407d0e50 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml @@ -90,8 +90,8 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose @@ -103,5 +103,5 @@ tags: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: + supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml index 572740fc52..a4c2b5518b 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml @@ -89,8 +89,8 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose @@ -100,5 +100,5 @@ tags: - Splunk_TA_cyberark - Splunk_TA_box - Splunk_TA_salesforce - tas_with_data: + supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml index 7ca098bbcc..4b7bac3d92 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml @@ -90,8 +90,8 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose @@ -103,5 +103,5 @@ tags: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: + supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index 0cadcc83db..44cfc57585 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -69,6 +69,6 @@ tags: - Registry.registry_value_name risk_score: 64 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml index 031d18581b..9081ca14b8 100644 --- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml +++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml @@ -60,6 +60,6 @@ tags: - Registry.dest risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml index 07fe3eaed1..44c73e3766 100644 --- a/detections/endpoint/adsisearcher_account_discovery.yml +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-24' author: Teoderick Contreras, Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain groups. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index dc6d46a0f5..70ee2deb1d 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -65,6 +65,6 @@ tags: - Registry.user risk_score: 3 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/allow_operation_with_consent_admin.yml b/detections/endpoint/allow_operation_with_consent_admin.yml index f44cfc4dd2..7ae6eb8d28 100644 --- a/detections/endpoint/allow_operation_with_consent_admin.yml +++ b/detections/endpoint/allow_operation_with_consent_admin.yml @@ -65,6 +65,6 @@ tags: - Registry.dest risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index 1f9f5f1c42..2539223518 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -82,6 +82,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 8eae53f6f0..cb6225b0fb 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -86,7 +86,7 @@ tags: - Processes.parent_process risk_score: 64 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index 977f5b7446..b38e4f89d0 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -84,6 +84,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/auto_admin_logon_registry_entry.yml b/detections/endpoint/auto_admin_logon_registry_entry.yml index 566bf334c1..c7f309228e 100644 --- a/detections/endpoint/auto_admin_logon_registry_entry.yml +++ b/detections/endpoint/auto_admin_logon_registry_entry.yml @@ -60,6 +60,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index ec9a4f196f..a9ec853d55 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -83,8 +83,8 @@ tags: - Processes.dest risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows diff --git a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml index bd4cd72547..058fa2c5c5 100644 --- a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml +++ b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml @@ -65,6 +65,6 @@ tags: - Processes.user risk_score: 35 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/bcdedit_failure_recovery_modification.yml b/detections/endpoint/bcdedit_failure_recovery_modification.yml index 4590eb2e90..9b8fa771c0 100644 --- a/detections/endpoint/bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/bcdedit_failure_recovery_modification.yml @@ -75,7 +75,7 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/change_default_file_association.yml b/detections/endpoint/change_default_file_association.yml index 39b2a1a629..4d24bab7a4 100644 --- a/detections/endpoint/change_default_file_association.yml +++ b/detections/endpoint/change_default_file_association.yml @@ -66,6 +66,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/change_to_safe_mode_with_network_config.yml b/detections/endpoint/change_to_safe_mode_with_network_config.yml index 335f555d66..52f57fc4c5 100644 --- a/detections/endpoint/change_to_safe_mode_with_network_config.yml +++ b/detections/endpoint/change_to_safe_mode_with_network_config.yml @@ -64,6 +64,6 @@ tags: - Processes.user risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/check_elevated_cmd_using_whoami.yml b/detections/endpoint/check_elevated_cmd_using_whoami.yml index 42f46c1742..bcf82b1b1f 100644 --- a/detections/endpoint/check_elevated_cmd_using_whoami.yml +++ b/detections/endpoint/check_elevated_cmd_using_whoami.yml @@ -65,6 +65,6 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/curl_download_and_bash_execution.yml b/detections/endpoint/curl_download_and_bash_execution.yml index 8c748b1dda..653d943a75 100644 --- a/detections/endpoint/curl_download_and_bash_execution.yml +++ b/detections/endpoint/curl_download_and_bash_execution.yml @@ -77,6 +77,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml index 7fd099c6fe..205bd2a81e 100644 --- a/detections/endpoint/detect_exchange_web_shell.yml +++ b/detections/endpoint/detect_exchange_web_shell.yml @@ -94,7 +94,7 @@ tags: - Filesystem.user risk_score: 81 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml index 919417998b..2f4ea79251 100644 --- a/detections/endpoint/detect_regasm_spawning_a_process.yml +++ b/detections/endpoint/detect_regasm_spawning_a_process.yml @@ -87,6 +87,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_regsvcs_spawning_a_process.yml b/detections/endpoint/detect_regsvcs_spawning_a_process.yml index c81cfc81a6..7d90b69783 100644 --- a/detections/endpoint/detect_regsvcs_spawning_a_process.yml +++ b/detections/endpoint/detect_regsvcs_spawning_a_process.yml @@ -86,6 +86,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_sharphound_command_line_arguments.yml b/detections/endpoint/detect_sharphound_command_line_arguments.yml index 9e0b7d70e7..18268a168d 100644 --- a/detections/endpoint/detect_sharphound_command_line_arguments.yml +++ b/detections/endpoint/detect_sharphound_command_line_arguments.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_id risk_score: 24 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index 703f0ee4ea..39d61af635 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -67,6 +67,6 @@ tags: - Processes.dest risk_score: 35 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_amsi_through_registry.yml b/detections/endpoint/disable_amsi_through_registry.yml index 302620ef30..33ff3e6082 100644 --- a/detections/endpoint/disable_amsi_through_registry.yml +++ b/detections/endpoint/disable_amsi_through_registry.yml @@ -47,6 +47,6 @@ tags: - Registry.dest - Registry.registry_value_name security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_etw_through_registry.yml b/detections/endpoint/disable_etw_through_registry.yml index 6fcd28fa2d..21690db7bf 100644 --- a/detections/endpoint/disable_etw_through_registry.yml +++ b/detections/endpoint/disable_etw_through_registry.yml @@ -46,6 +46,6 @@ tags: - Registry.dest - Registry.registry_value_name security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_logs_using_wevtutil.yml b/detections/endpoint/disable_logs_using_wevtutil.yml index 34f0b28e17..60b2bb04df 100644 --- a/detections/endpoint/disable_logs_using_wevtutil.yml +++ b/detections/endpoint/disable_logs_using_wevtutil.yml @@ -61,6 +61,6 @@ tags: - Processes.process_guid risk_score: 24 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_registry_tool.yml b/detections/endpoint/disable_registry_tool.yml index 93c3c28487..6dd2e5de12 100644 --- a/detections/endpoint/disable_registry_tool.yml +++ b/detections/endpoint/disable_registry_tool.yml @@ -60,6 +60,6 @@ tags: - Registry.registry_value_name risk_score: 40 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_schedule_task.yml b/detections/endpoint/disable_schedule_task.yml index bfd54fd4f3..33e228ae36 100644 --- a/detections/endpoint/disable_schedule_task.yml +++ b/detections/endpoint/disable_schedule_task.yml @@ -60,7 +60,7 @@ tags: - Processes.dest risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/disable_windows_app_hotkeys.yml b/detections/endpoint/disable_windows_app_hotkeys.yml index 12750778fc..1c0a14c31d 100644 --- a/detections/endpoint/disable_windows_app_hotkeys.yml +++ b/detections/endpoint/disable_windows_app_hotkeys.yml @@ -61,6 +61,6 @@ tags: - Registry.dest Registry.user risk_score: 40 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index b463e4baeb..6897c468eb 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -68,6 +68,6 @@ tags: - Registry.registry_value_name risk_score: 40 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_cmd_application.yml b/detections/endpoint/disabling_cmd_application.yml index 36a8aba4f0..a55f0de313 100644 --- a/detections/endpoint/disabling_cmd_application.yml +++ b/detections/endpoint/disabling_cmd_application.yml @@ -63,6 +63,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_controlpanel.yml b/detections/endpoint/disabling_controlpanel.yml index 6136144cd8..841f607ffc 100644 --- a/detections/endpoint/disabling_controlpanel.yml +++ b/detections/endpoint/disabling_controlpanel.yml @@ -62,6 +62,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_folderoptions_windows_feature.yml b/detections/endpoint/disabling_folderoptions_windows_feature.yml index 8e10371085..2632fc415e 100644 --- a/detections/endpoint/disabling_folderoptions_windows_feature.yml +++ b/detections/endpoint/disabling_folderoptions_windows_feature.yml @@ -64,6 +64,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_norun_windows_app.yml b/detections/endpoint/disabling_norun_windows_app.yml index 99a8091abe..e28f8263ef 100644 --- a/detections/endpoint/disabling_norun_windows_app.yml +++ b/detections/endpoint/disabling_norun_windows_app.yml @@ -66,6 +66,6 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_systemrestore_in_registry.yml b/detections/endpoint/disabling_systemrestore_in_registry.yml index 50fd4dd24f..335d48ac4a 100644 --- a/detections/endpoint/disabling_systemrestore_in_registry.yml +++ b/detections/endpoint/disabling_systemrestore_in_registry.yml @@ -66,6 +66,6 @@ tags: - Registry.registry_value_name risk_score: 49 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_task_manager.yml b/detections/endpoint/disabling_task_manager.yml index 80f5d43f38..2be8bcff43 100644 --- a/detections/endpoint/disabling_task_manager.yml +++ b/detections/endpoint/disabling_task_manager.yml @@ -64,6 +64,6 @@ tags: - Registry.registry_value_name risk_score: 42 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/domain_account_discovery_with_net_app.yml b/detections/endpoint/domain_account_discovery_with_net_app.yml index de64911d86..5fa36727e6 100644 --- a/detections/endpoint/domain_account_discovery_with_net_app.yml +++ b/detections/endpoint/domain_account_discovery_with_net_app.yml @@ -70,6 +70,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index bbf37808f7..0f9b7664db 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/domain_group_discovery_with_adsisearcher.yml b/detections/endpoint/domain_group_discovery_with_adsisearcher.yml index 29010d86d3..202cb361d1 100644 --- a/detections/endpoint/domain_group_discovery_with_adsisearcher.yml +++ b/detections/endpoint/domain_group_discovery_with_adsisearcher.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-25' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain groups. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate diff --git a/detections/endpoint/dsquery_domain_discovery.yml b/detections/endpoint/dsquery_domain_discovery.yml index af145534f6..e8ff5f98ef 100644 --- a/detections/endpoint/dsquery_domain_discovery.yml +++ b/detections/endpoint/dsquery_domain_discovery.yml @@ -93,7 +93,7 @@ tags: - Processes.parent_process_id risk_score: 72 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/dump_lsass_via_procdump.yml b/detections/endpoint/dump_lsass_via_procdump.yml index 64fd57e696..f116ed0de0 100644 --- a/detections/endpoint/dump_lsass_via_procdump.yml +++ b/detections/endpoint/dump_lsass_via_procdump.yml @@ -89,7 +89,7 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/elevated_group_discovery_with_powerview.yml b/detections/endpoint/elevated_group_discovery_with_powerview.yml index a23c18ea20..8a9f22a77d 100644 --- a/detections/endpoint/elevated_group_discovery_with_powerview.yml +++ b/detections/endpoint/elevated_group_discovery_with_powerview.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-25' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainGroupMember` commandlet. `Get-DomainGroupMember` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. diff --git a/detections/endpoint/enable_rdp_in_other_port_number.yml b/detections/endpoint/enable_rdp_in_other_port_number.yml index 5793ae1027..3ea8522448 100644 --- a/detections/endpoint/enable_rdp_in_other_port_number.yml +++ b/detections/endpoint/enable_rdp_in_other_port_number.yml @@ -60,6 +60,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/eventvwr_uac_bypass.yml b/detections/endpoint/eventvwr_uac_bypass.yml index 9a4726888b..3fd7702c63 100644 --- a/detections/endpoint/eventvwr_uac_bypass.yml +++ b/detections/endpoint/eventvwr_uac_bypass.yml @@ -68,6 +68,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/excessive_attempt_to_disable_services.yml b/detections/endpoint/excessive_attempt_to_disable_services.yml index 58f9ca8413..181c0984b7 100644 --- a/detections/endpoint/excessive_attempt_to_disable_services.yml +++ b/detections/endpoint/excessive_attempt_to_disable_services.yml @@ -64,7 +64,7 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml b/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml index 19c9759a67..08ada8e06a 100644 --- a/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml +++ b/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml @@ -58,12 +58,12 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm - tas_with_data: + supported_tas: - Splunk_TA_windows diff --git a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml index f197a4fa92..76e57b909c 100644 --- a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml +++ b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml @@ -73,6 +73,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/excessive_number_of_taskhost_processes.yml b/detections/endpoint/excessive_number_of_taskhost_processes.yml index cc24ef4511..0c8c37cf5b 100644 --- a/detections/endpoint/excessive_number_of_taskhost_processes.yml +++ b/detections/endpoint/excessive_number_of_taskhost_processes.yml @@ -67,11 +67,11 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR - tas_with_data: + supported_tas: - Splunk_TA_windows diff --git a/detections/endpoint/excessive_usage_of_cacls_app.yml b/detections/endpoint/excessive_usage_of_cacls_app.yml index 5b6ba5c553..a86afa11a5 100644 --- a/detections/endpoint/excessive_usage_of_cacls_app.yml +++ b/detections/endpoint/excessive_usage_of_cacls_app.yml @@ -64,7 +64,7 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/excessive_usage_of_taskkill.yml b/detections/endpoint/excessive_usage_of_taskkill.yml index 7bda8bf2b0..03fb010842 100644 --- a/detections/endpoint/excessive_usage_of_taskkill.yml +++ b/detections/endpoint/excessive_usage_of_taskkill.yml @@ -68,7 +68,7 @@ tags: - Processes.process_id risk_score: 28 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml index d4cdc813b6..223f9a1c16 100644 --- a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml +++ b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml @@ -4,8 +4,7 @@ version: 2 date: '2021-11-18' author: Teoderick Contreras, Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic identifies executable files (.exe or .dll) being written to Windows administrative SMB shares (Admin$, IPC$, C$). This represents suspicious behavior as its commonly used by tools like like PsExec/PaExec and others diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index 4500a5bb6c..1464e2ba5f 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -76,7 +76,7 @@ tags: - Filesystem.user risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml index 56a7ab51ab..9126fe1ccd 100644 --- a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml +++ b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml @@ -74,6 +74,6 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index b20a051979..9a4ff21cb1 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -74,7 +74,7 @@ tags: - Processes.parent_process risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml index e07ae71118..ecb4d1cd2d 100644 --- a/detections/endpoint/file_with_samsam_extension.yml +++ b/detections/endpoint/file_with_samsam_extension.yml @@ -69,8 +69,8 @@ tags: - Filesystem.file_name risk_score: 90 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - splunk_ta_o365 diff --git a/detections/endpoint/firewall_allowed_program_enable.yml b/detections/endpoint/firewall_allowed_program_enable.yml index 58760edba9..62534e7cad 100644 --- a/detections/endpoint/firewall_allowed_program_enable.yml +++ b/detections/endpoint/firewall_allowed_program_enable.yml @@ -67,6 +67,6 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/fodhelper_uac_bypass.yml b/detections/endpoint/fodhelper_uac_bypass.yml index 7b4e5303bf..e801b4e354 100644 --- a/detections/endpoint/fodhelper_uac_bypass.yml +++ b/detections/endpoint/fodhelper_uac_bypass.yml @@ -86,6 +86,6 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/fsutil_zeroing_file.yml b/detections/endpoint/fsutil_zeroing_file.yml index a1870be40e..3c35656489 100644 --- a/detections/endpoint/fsutil_zeroing_file.yml +++ b/detections/endpoint/fsutil_zeroing_file.yml @@ -57,6 +57,6 @@ tags: - Processes.parent_process risk_score: 54 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml b/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml index 8496fa6eca..f165a51153 100644 --- a/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml +++ b/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-26' author: Teoderick Contreras, Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-ADDefaultDomainPasswordPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries diff --git a/detections/endpoint/get_aduser_with_powershell_script_block.yml b/detections/endpoint/get_aduser_with_powershell_script_block.yml index 8f3f227eae..b9c271f9a2 100644 --- a/detections/endpoint/get_aduser_with_powershell_script_block.yml +++ b/detections/endpoint/get_aduser_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-24' author: Teoderick Contreras, Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-AdGUser` commandlet. The `Get-AdUser` commandlet is used to return a list of all domain users. Red Teams and adversaries may leverage diff --git a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml index fe0a8167ce..728d9e9a9b 100644 --- a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml +++ b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml index 896a9754c9..a465b42fa2 100644 --- a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml +++ b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-26' author: Teoderick Contreras, MAuricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-ADUserResultantPasswordPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries diff --git a/detections/endpoint/get_domainpolicy_with_powershell.yml b/detections/endpoint/get_domainpolicy_with_powershell.yml index 38d3d42baa..90280b3e02 100644 --- a/detections/endpoint/get_domainpolicy_with_powershell.yml +++ b/detections/endpoint/get_domainpolicy_with_powershell.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_name risk_score: 30 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml b/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml index 720ef6d6c7..0e2c27fac2 100644 --- a/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml +++ b/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-26' author: Teoderick Contreras, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get DomainPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml index 55214d9ee5..ec2699b7b1 100644 --- a/detections/endpoint/get_domainuser_with_powershell.yml +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/get_domainuser_with_powershell_script_block.yml b/detections/endpoint/get_domainuser_with_powershell_script_block.yml index aec6b0b367..9836eea84e 100644 --- a/detections/endpoint/get_domainuser_with_powershell_script_block.yml +++ b/detections/endpoint/get_domainuser_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-24' author: Teoderick Contreras, Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainUser` commandlet. `GetDomainUser` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. diff --git a/detections/endpoint/get_foresttrust_with_powershell_script_block.yml b/detections/endpoint/get_foresttrust_with_powershell_script_block.yml index f29a1814c8..d04a74656a 100644 --- a/detections/endpoint/get_foresttrust_with_powershell_script_block.yml +++ b/detections/endpoint/get_foresttrust_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-09-02' author: Michael Haag, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output diff --git a/detections/endpoint/getadcomputer_with_powershell_script_block.yml b/detections/endpoint/getadcomputer_with_powershell_script_block.yml index b66b1e4c1c..f38cf2f2a9 100644 --- a/detections/endpoint/getadcomputer_with_powershell_script_block.yml +++ b/detections/endpoint/getadcomputer_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-09-01' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-AdGroup` commandlet. The `Get-AdGroup` commandlet is used to return a list of all domain computers. Red Teams and adversaries may diff --git a/detections/endpoint/getadgroup_with_powershell_script_block.yml b/detections/endpoint/getadgroup_with_powershell_script_block.yml index 203d37d465..7c1119fa15 100644 --- a/detections/endpoint/getadgroup_with_powershell_script_block.yml +++ b/detections/endpoint/getadgroup_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-25' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-AdGroup` commandlet. The `Get-AdGroup` commandlet is used to return a list of all domain groups. Red Teams and adversaries may leverage diff --git a/detections/endpoint/getcurrent_user_with_powershell_script_block.yml b/detections/endpoint/getcurrent_user_with_powershell_script_block.yml index 3c55722713..d1892d1e2a 100644 --- a/detections/endpoint/getcurrent_user_with_powershell_script_block.yml +++ b/detections/endpoint/getcurrent_user_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-09-13' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `GetCurrent` method of the WindowsIdentity .NET class. This method returns an object that represents the current Windows user. Red diff --git a/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml b/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml index 290fc2a46e..67a9791ec1 100644 --- a/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml +++ b/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-09-02' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainComputer` commandlet. `GetDomainComputer` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. diff --git a/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml b/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml index a77676da0f..92f51f5444 100644 --- a/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml +++ b/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-09-02' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainController` commandlet. `Get-DomainController` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. diff --git a/detections/endpoint/getdomaingroup_with_powershell_script_block.yml b/detections/endpoint/getdomaingroup_with_powershell_script_block.yml index fdc3b7c0e9..6cac522789 100644 --- a/detections/endpoint/getdomaingroup_with_powershell_script_block.yml +++ b/detections/endpoint/getdomaingroup_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-26' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainGroup` commandlet. `Get-DomainGroup` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. diff --git a/detections/endpoint/getlocaluser_with_powershell_script_block.yml b/detections/endpoint/getlocaluser_with_powershell_script_block.yml index 22774af191..ee832bdb05 100644 --- a/detections/endpoint/getlocaluser_with_powershell_script_block.yml +++ b/detections/endpoint/getlocaluser_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-23' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-LocalUser` commandlet. The `Get-LocalUser` commandlet is used to return a list of all local users. Red Teams and adversaries diff --git a/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml b/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml index 9372384b1d..3444f85812 100644 --- a/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml +++ b/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-09-10' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-NetTcpconnection ` commandlet. This commandlet is used to return a listing of network connections on a compromised system. Red diff --git a/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml index 00004d900e..85d1f0325e 100644 --- a/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-09-01' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet. The `DS_Computer` class parameter leverages WMI to query for all domain computers. Red Teams and adversaries diff --git a/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml index 913a3c5b12..90cb20dc8b 100644 --- a/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-25' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet used with specific parameters . The `DS_Group` parameter leverages WMI to query for all domain groups. Red Teams diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml index bb07d66e57..4ccf31d24f 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -73,6 +73,6 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml index 3ba1b7dae8..b37def5d6a 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-24' author: Teoderick Contreras, Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet. The `DS_User` class parameter leverages WMI to query for all domain users. Red Teams and adversaries diff --git a/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml index e56990abe9..10779deb4b 100644 --- a/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-23' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-WmiObject` commandlet used with specific parameters. The `Win32_UserAccount` parameter is used to return a list of all local users. Red diff --git a/detections/endpoint/hide_user_account_from_sign_in_screen.yml b/detections/endpoint/hide_user_account_from_sign_in_screen.yml index f23e24a339..bc922181e5 100644 --- a/detections/endpoint/hide_user_account_from_sign_in_screen.yml +++ b/detections/endpoint/hide_user_account_from_sign_in_screen.yml @@ -70,6 +70,6 @@ tags: - Registry.dest Registry.user risk_score: 72 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index 6adfa9e437..63e66d8e73 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -74,7 +74,7 @@ tags: - Processes.dest risk_score: 72 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows diff --git a/detections/endpoint/icacls_deny_command.yml b/detections/endpoint/icacls_deny_command.yml index b3455a9b2a..e914117b5a 100644 --- a/detections/endpoint/icacls_deny_command.yml +++ b/detections/endpoint/icacls_deny_command.yml @@ -65,7 +65,7 @@ tags: - Processes.process risk_score: 72 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/icacls_grant_command.yml b/detections/endpoint/icacls_grant_command.yml index 9b8c725594..7577f5d5fd 100644 --- a/detections/endpoint/icacls_grant_command.yml +++ b/detections/endpoint/icacls_grant_command.yml @@ -65,7 +65,7 @@ tags: - Processes.process risk_score: 49 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml b/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml index 3f8090e1e6..eb2c580a34 100644 --- a/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml +++ b/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-11-18' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the usage of the `Enter-PSSession`. This commandlet can be used to open an interactive session on a remote endpoint leveraging the WinRM protocol. Red Teams diff --git a/detections/endpoint/java_class_file_download_by_java_user_agent.yml b/detections/endpoint/java_class_file_download_by_java_user_agent.yml index 3af444ccda..4146d277c7 100644 --- a/detections/endpoint/java_class_file_download_by_java_user_agent.yml +++ b/detections/endpoint/java_class_file_download_by_java_user_agent.yml @@ -67,8 +67,8 @@ tags: - Web.http_user_agent risk_score: 40 security_domain: network - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_nginx - Splunk_TA_microsoft-iis diff --git a/detections/endpoint/jscript_execution_using_cscript_app.yml b/detections/endpoint/jscript_execution_using_cscript_app.yml index dc3b4a6983..0f2b8f9134 100644 --- a/detections/endpoint/jscript_execution_using_cscript_app.yml +++ b/detections/endpoint/jscript_execution_using_cscript_app.yml @@ -69,6 +69,6 @@ tags: - Processes.user risk_score: 49 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_add_files_in_known_crontab_directories.yml b/detections/endpoint/linux_add_files_in_known_crontab_directories.yml index 37bbd7ea38..e83a0eea80 100644 --- a/detections/endpoint/linux_add_files_in_known_crontab_directories.yml +++ b/detections/endpoint/linux_add_files_in_known_crontab_directories.yml @@ -70,3 +70,6 @@ tags: - Filesystem.file_path risk_score: 25 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_at_allow_config_file_creation.yml b/detections/endpoint/linux_at_allow_config_file_creation.yml index 44c01c5905..19593a3a33 100644 --- a/detections/endpoint/linux_at_allow_config_file_creation.yml +++ b/detections/endpoint/linux_at_allow_config_file_creation.yml @@ -69,3 +69,6 @@ tags: - Filesystem.file_path risk_score: 25 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_at_application_execution.yml b/detections/endpoint/linux_at_application_execution.yml index 07a98f45d8..0b05d1a797 100644 --- a/detections/endpoint/linux_at_application_execution.yml +++ b/detections/endpoint/linux_at_application_execution.yml @@ -71,3 +71,7 @@ tags: - Processes.parent_process_id risk_score: 9 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_change_file_owner_to_root.yml b/detections/endpoint/linux_change_file_owner_to_root.yml index bee64e143f..b0c6002f44 100644 --- a/detections/endpoint/linux_change_file_owner_to_root.yml +++ b/detections/endpoint/linux_change_file_owner_to_root.yml @@ -72,3 +72,7 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_doas_conf_file_creation.yml b/detections/endpoint/linux_doas_conf_file_creation.yml index 1a0d7dce2b..ba17e9086a 100644 --- a/detections/endpoint/linux_doas_conf_file_creation.yml +++ b/detections/endpoint/linux_doas_conf_file_creation.yml @@ -70,3 +70,6 @@ tags: - Filesystem.file_path risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_doas_tool_execution.yml b/detections/endpoint/linux_doas_tool_execution.yml index 0997182fa7..937816c218 100644 --- a/detections/endpoint/linux_doas_tool_execution.yml +++ b/detections/endpoint/linux_doas_tool_execution.yml @@ -73,3 +73,7 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml b/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml index c8e48e229c..34093ccfdd 100644 --- a/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml +++ b/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml @@ -71,3 +71,6 @@ tags: - Filesystem.file_path risk_score: 72 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_file_creation_in_init_boot_directory.yml b/detections/endpoint/linux_file_creation_in_init_boot_directory.yml index 28b9fee84d..d45f4adbb3 100644 --- a/detections/endpoint/linux_file_creation_in_init_boot_directory.yml +++ b/detections/endpoint/linux_file_creation_in_init_boot_directory.yml @@ -67,3 +67,6 @@ tags: - Filesystem.file_path risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_file_creation_in_profile_directory.yml b/detections/endpoint/linux_file_creation_in_profile_directory.yml index 7ad259ac67..e39de96166 100644 --- a/detections/endpoint/linux_file_creation_in_profile_directory.yml +++ b/detections/endpoint/linux_file_creation_in_profile_directory.yml @@ -69,3 +69,6 @@ tags: - Filesystem.file_path risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml b/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml index 9efacdd220..d1d9c576eb 100644 --- a/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml +++ b/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml @@ -71,3 +71,7 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml b/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml index 9825cd8934..d35b0729b0 100644 --- a/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml +++ b/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml @@ -72,3 +72,7 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml index f3c9be8b15..ed04f50b91 100644 --- a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml +++ b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml @@ -73,3 +73,7 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml b/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml index 22818a0ab6..318d61af9f 100644 --- a/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml +++ b/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml @@ -72,3 +72,7 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_access_to_credential_files.yml b/detections/endpoint/linux_possible_access_to_credential_files.yml index 3b695cc0f6..086fc87057 100644 --- a/detections/endpoint/linux_possible_access_to_credential_files.yml +++ b/detections/endpoint/linux_possible_access_to_credential_files.yml @@ -73,3 +73,7 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_access_to_sudoers_file.yml b/detections/endpoint/linux_possible_access_to_sudoers_file.yml index 4d287e68ca..1d3d679792 100644 --- a/detections/endpoint/linux_possible_access_to_sudoers_file.yml +++ b/detections/endpoint/linux_possible_access_to_sudoers_file.yml @@ -71,3 +71,7 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml b/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml index 4eb48d7d79..bb2dda20cd 100644 --- a/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml +++ b/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml @@ -73,3 +73,7 @@ tags: - Processes.parent_process_id risk_score: 9 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml b/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml index e3ec58909f..90dc1a35cb 100644 --- a/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml +++ b/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml @@ -73,3 +73,7 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_ssh_key_file_creation.yml b/detections/endpoint/linux_possible_ssh_key_file_creation.yml index 6945aed5fc..119678e666 100644 --- a/detections/endpoint/linux_possible_ssh_key_file_creation.yml +++ b/detections/endpoint/linux_possible_ssh_key_file_creation.yml @@ -68,3 +68,6 @@ tags: - Filesystem.file_path risk_score: 36 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_preload_hijack_library_calls.yml b/detections/endpoint/linux_preload_hijack_library_calls.yml index 97c79b0d14..f6c34e4c35 100644 --- a/detections/endpoint/linux_preload_hijack_library_calls.yml +++ b/detections/endpoint/linux_preload_hijack_library_calls.yml @@ -70,3 +70,7 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_service_file_created_in_systemd_directory.yml b/detections/endpoint/linux_service_file_created_in_systemd_directory.yml index 999fecc6a8..78d8928eaf 100644 --- a/detections/endpoint/linux_service_file_created_in_systemd_directory.yml +++ b/detections/endpoint/linux_service_file_created_in_systemd_directory.yml @@ -75,3 +75,6 @@ tags: - Filesystem.file_path risk_score: 64 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_service_restarted.yml b/detections/endpoint/linux_service_restarted.yml index f8791b39ec..9a3df28e33 100644 --- a/detections/endpoint/linux_service_restarted.yml +++ b/detections/endpoint/linux_service_restarted.yml @@ -75,3 +75,7 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_service_started_or_enabled.yml b/detections/endpoint/linux_service_started_or_enabled.yml index f49665180d..d8f31ee12e 100644 --- a/detections/endpoint/linux_service_started_or_enabled.yml +++ b/detections/endpoint/linux_service_started_or_enabled.yml @@ -75,3 +75,7 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_setuid_using_chmod_utility.yml b/detections/endpoint/linux_setuid_using_chmod_utility.yml index 9c0993d9d1..a6a0d817d1 100644 --- a/detections/endpoint/linux_setuid_using_chmod_utility.yml +++ b/detections/endpoint/linux_setuid_using_chmod_utility.yml @@ -75,3 +75,7 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_setuid_using_setcap_utility.yml b/detections/endpoint/linux_setuid_using_setcap_utility.yml index a9b84716e8..15f935c30b 100644 --- a/detections/endpoint/linux_setuid_using_setcap_utility.yml +++ b/detections/endpoint/linux_setuid_using_setcap_utility.yml @@ -76,3 +76,7 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_sudoers_tmp_file_creation.yml b/detections/endpoint/linux_sudoers_tmp_file_creation.yml index 1df4b0d961..04ffef309c 100644 --- a/detections/endpoint/linux_sudoers_tmp_file_creation.yml +++ b/detections/endpoint/linux_sudoers_tmp_file_creation.yml @@ -69,3 +69,6 @@ tags: - Filesystem.file_path risk_score: 72 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_visudo_utility_execution.yml b/detections/endpoint/linux_visudo_utility_execution.yml index 4acdf38f55..14c435443f 100644 --- a/detections/endpoint/linux_visudo_utility_execution.yml +++ b/detections/endpoint/linux_visudo_utility_execution.yml @@ -72,3 +72,7 @@ tags: - Processes.parent_process_id risk_score: 16 security_domain: endpoint + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/logon_script_event_trigger_execution.yml b/detections/endpoint/logon_script_event_trigger_execution.yml index 06a4dcd38e..17c7454063 100644 --- a/detections/endpoint/logon_script_event_trigger_execution.yml +++ b/detections/endpoint/logon_script_event_trigger_execution.yml @@ -64,6 +64,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/modify_acl_permission_to_files_or_folder.yml b/detections/endpoint/modify_acl_permission_to_files_or_folder.yml index e137540de9..5f575a26b8 100644 --- a/detections/endpoint/modify_acl_permission_to_files_or_folder.yml +++ b/detections/endpoint/modify_acl_permission_to_files_or_folder.yml @@ -62,7 +62,7 @@ tags: - Processes.process_id risk_score: 32 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/msmpeng_application_dll_side_loading.yml b/detections/endpoint/msmpeng_application_dll_side_loading.yml index e8f0cffc91..fdb3cb30d3 100644 --- a/detections/endpoint/msmpeng_application_dll_side_loading.yml +++ b/detections/endpoint/msmpeng_application_dll_side_loading.yml @@ -47,7 +47,7 @@ tags: - Filesystem.user - Filesystem.file_path security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml b/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml index 415b3d1c90..8e60ca1557 100644 --- a/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml +++ b/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-04-14' author: Mauricio Velazco, Splunk type: Anomaly -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic identifies one source endpoint failing to authenticate with multiple disabled domain users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory diff --git a/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml b/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml index 963bf4798f..3612834bee 100644 --- a/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml +++ b/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-04-14' author: Mauricio Velazco, Splunk type: Anomaly -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic identifies one source endpoint failing to authenticate with multiple invalid domain users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory diff --git a/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml b/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml index 151c4529bf..70aa1593b0 100644 --- a/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml +++ b/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-04-15' author: Mauricio Velazco, Splunk type: Anomaly -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic identifies one source endpoint failing to authenticate with multiple invalid users using the NTLM protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment diff --git a/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml b/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml index 5e26a71bed..84430a2b77 100644 --- a/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml +++ b/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-04-13' author: Mauricio Velazco, Splunk type: Anomaly -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic identifies a source user failing to authenticate with multiple users using explicit credentials on a host. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment diff --git a/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml b/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml index 37598d8b2d..2cc0ffadc0 100644 --- a/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml +++ b/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-04-08' author: Mauricio Velazco, Splunk type: Anomaly -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic identifies one source endpoint failing to authenticate with multiple valid users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment diff --git a/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml b/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml index 845ed682fa..63f533b44f 100644 --- a/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml +++ b/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-04-13' author: Mauricio Velazco, Splunk type: Anomaly -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic identifies one source endpoint failing to authenticate with multiple valid users using the NTLM protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment diff --git a/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml b/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml index d03cfac314..1496df5d6c 100644 --- a/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml +++ b/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-04-13' author: Mauricio Velazco, Splunk type: Anomaly -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic identifies a source process name failing to authenticate with multiple users. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to obtain initial access diff --git a/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml b/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml index b9d616aeaf..5b9049e85a 100644 --- a/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml +++ b/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-04-13' author: Mauricio Velazco, Splunk type: Anomaly -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic identifies a source host failing to authenticate against a remote host with multiple users. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to diff --git a/detections/endpoint/net_profiler_uac_bypass.yml b/detections/endpoint/net_profiler_uac_bypass.yml index e8ff97bed0..b557812d7a 100644 --- a/detections/endpoint/net_profiler_uac_bypass.yml +++ b/detections/endpoint/net_profiler_uac_bypass.yml @@ -62,6 +62,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/nltest_domain_trust_discovery.yml b/detections/endpoint/nltest_domain_trust_discovery.yml index 97e810bb0f..82c1470541 100644 --- a/detections/endpoint/nltest_domain_trust_discovery.yml +++ b/detections/endpoint/nltest_domain_trust_discovery.yml @@ -75,6 +75,6 @@ tags: - Processes.parent_process_id risk_score: 15 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/ntdsutil_export_ntds.yml b/detections/endpoint/ntdsutil_export_ntds.yml index c60ffba0e9..35929d61ae 100644 --- a/detections/endpoint/ntdsutil_export_ntds.yml +++ b/detections/endpoint/ntdsutil_export_ntds.yml @@ -78,6 +78,6 @@ tags: - Processes.parent_process_id risk_score: 50 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index ac58c00a8f..751021d879 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -69,8 +69,8 @@ tags: - Filesystem.dest risk_score: 72 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_ossec - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/permission_modification_using_takeown_app.yml b/detections/endpoint/permission_modification_using_takeown_app.yml index fe3cfd7855..4261e53f6c 100644 --- a/detections/endpoint/permission_modification_using_takeown_app.yml +++ b/detections/endpoint/permission_modification_using_takeown_app.yml @@ -65,6 +65,6 @@ tags: - Processes.process_guid risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/powershell_execute_com_object.yml b/detections/endpoint/powershell_execute_com_object.yml index 21b359f9ae..32b4bce387 100644 --- a/detections/endpoint/powershell_execute_com_object.yml +++ b/detections/endpoint/powershell_execute_com_object.yml @@ -58,8 +58,9 @@ tags: - _time risk_score: 5 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_microsoft-cloudservices - Splunk_TA_cisco-ucs - Splunk_TA_citrix-netscaler - Splunk_TA_nix @@ -100,6 +101,7 @@ tags: - Splunk_TA_ibm-was - Splunk_TA_microsoft-hyperv - Splunk_TA_windows + - Splunk_TA_stream_wire_data - Splunk_TA_mcafee-wg - Splunk_TA_isc-dhcp - Splunk_TA_websense-dlp @@ -115,5 +117,5 @@ tags: - Splunk_TA_cyberark_epm - Splunk_TA_linux - Splunk_TA_oracle - tas_with_data: + supported_tas: - Splunk_TA_windows diff --git a/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml b/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml index 1faf799219..44df06b235 100644 --- a/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml +++ b/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-09-14' author: Michael Haag, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify suspicious PowerShell execution. Script Block Logging captures the command sent to PowerShell, the full command to be executed. Upon enabling, logs will output diff --git a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml index bd5b6ba08c..f69506cda0 100644 --- a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml +++ b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml @@ -66,6 +66,6 @@ tags: - Processes.process_guid risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml index 4f3e9afb9f..83da35da82 100644 --- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml +++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml @@ -80,7 +80,7 @@ tags: - Filesystem.user risk_score: 63 security_domain: network - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/process_execution_via_wmi.yml b/detections/endpoint/process_execution_via_wmi.yml index 1cfcf8e22f..d75597a1ca 100644 --- a/detections/endpoint/process_execution_via_wmi.yml +++ b/detections/endpoint/process_execution_via_wmi.yml @@ -71,7 +71,7 @@ tags: - Processes.process_name risk_score: 49 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index 079e1f5f90..2d5181b2a0 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -76,6 +76,6 @@ tags: - Processes.dest risk_score: 42 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml index b6ba6acd3d..03417bcd68 100644 --- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml +++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml @@ -79,7 +79,7 @@ tags: - Processes.dest risk_score: 45 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 37418d8290..1d0db92fda 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -89,6 +89,6 @@ tags: - Registry.user risk_score: 76 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml index 15389b529a..9bfba7f9c8 100644 --- a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml +++ b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-11-15' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of PowerShell with arguments utilized to start a process on a remote endpoint by abusing the DCOM protocol. Specifically, this search looks diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml index 3482d16ebd..e11ab6af7d 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-11-16' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of PowerShell with arguments utilized to start a process on a remote endpoint by abusing the WinRM protocol. Specifically, this search looks diff --git a/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block.yml b/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block.yml index abd9d37eec..5d9f138111 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-11-15' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Invoke-WmiMethod` commandlet with arguments utilized to start a process on a remote endpoint by abusing WMI. Red Teams and adversaries diff --git a/detections/endpoint/remote_system_discovery_with_adsisearcher.yml b/detections/endpoint/remote_system_discovery_with_adsisearcher.yml index 1d06fc7ca0..bbfba4500d 100644 --- a/detections/endpoint/remote_system_discovery_with_adsisearcher.yml +++ b/detections/endpoint/remote_system_discovery_with_adsisearcher.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-09-01' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain computers. Red Teams and adversaries may leverage `[Adsisearcher]` to diff --git a/detections/endpoint/remote_wmi_command_attempt.yml b/detections/endpoint/remote_wmi_command_attempt.yml index 4bf052f1f3..6322b3fe5e 100644 --- a/detections/endpoint/remote_wmi_command_attempt.yml +++ b/detections/endpoint/remote_wmi_command_attempt.yml @@ -76,6 +76,6 @@ tags: - Processes.process_id risk_score: 36 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/resize_shadowstorage_volume.yml b/detections/endpoint/resize_shadowstorage_volume.yml index c9e27ec8ae..f9a4e86e63 100644 --- a/detections/endpoint/resize_shadowstorage_volume.yml +++ b/detections/endpoint/resize_shadowstorage_volume.yml @@ -73,7 +73,7 @@ tags: - Processes.user risk_score: 72 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/revil_common_exec_parameter.yml b/detections/endpoint/revil_common_exec_parameter.yml index c31284b8e2..34ca80dd8f 100644 --- a/detections/endpoint/revil_common_exec_parameter.yml +++ b/detections/endpoint/revil_common_exec_parameter.yml @@ -67,6 +67,6 @@ tags: - Processes.process_guid risk_score: 54 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/revil_registry_entry.yml b/detections/endpoint/revil_registry_entry.yml index 632f0a5cc7..5bd711e5d0 100644 --- a/detections/endpoint/revil_registry_entry.yml +++ b/detections/endpoint/revil_registry_entry.yml @@ -65,6 +65,6 @@ tags: - Registry.registry_key_name risk_score: 60 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/ryuk_wake_on_lan_command.yml b/detections/endpoint/ryuk_wake_on_lan_command.yml index 178ddca5d3..c0c1b085f8 100644 --- a/detections/endpoint/ryuk_wake_on_lan_command.yml +++ b/detections/endpoint/ryuk_wake_on_lan_command.yml @@ -73,6 +73,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/samsam_test_file_write.yml b/detections/endpoint/samsam_test_file_write.yml index 0864c56b63..d28121eff5 100644 --- a/detections/endpoint/samsam_test_file_write.yml +++ b/detections/endpoint/samsam_test_file_write.yml @@ -62,8 +62,8 @@ tags: - Filesystem.file_path risk_score: 12 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - splunk_ta_o365 diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index e42a5a3200..f13355af48 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -78,7 +78,7 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index 7f3437a7c2..426e2d0265 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -71,6 +71,6 @@ tags: - Processes.dest risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/schtasks_run_task_on_demand.yml b/detections/endpoint/schtasks_run_task_on_demand.yml index 17c489729b..0edf0ce49f 100644 --- a/detections/endpoint/schtasks_run_task_on_demand.yml +++ b/detections/endpoint/schtasks_run_task_on_demand.yml @@ -66,7 +66,7 @@ tags: - Processes.user risk_score: 48 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index cd8779b806..9953a4056f 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -73,7 +73,7 @@ tags: - Processes.user risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index 64971ebcfd..3fc0c0b660 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -70,7 +70,7 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml index 098bb5af5f..1954c0955e 100644 --- a/detections/endpoint/screensaver_event_trigger_execution.yml +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -67,6 +67,6 @@ tags: - Registry.registry_value_name risk_score: 72 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/script_execution_via_wmi.yml b/detections/endpoint/script_execution_via_wmi.yml index 7b0f972204..9fdb3c319d 100644 --- a/detections/endpoint/script_execution_via_wmi.yml +++ b/detections/endpoint/script_execution_via_wmi.yml @@ -65,8 +65,8 @@ tags: - Processes.dest risk_score: 36 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows diff --git a/detections/endpoint/sdclt_uac_bypass.yml b/detections/endpoint/sdclt_uac_bypass.yml index 2909953f4f..2c07e09f51 100644 --- a/detections/endpoint/sdclt_uac_bypass.yml +++ b/detections/endpoint/sdclt_uac_bypass.yml @@ -62,6 +62,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index 24cd6152f1..005f3fb6f4 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -68,6 +68,6 @@ tags: - Processes.process_guid risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/serviceprincipalnames_discovery_with_powershell.yml b/detections/endpoint/serviceprincipalnames_discovery_with_powershell.yml index 6430c8a73b..ea52e4a955 100644 --- a/detections/endpoint/serviceprincipalnames_discovery_with_powershell.yml +++ b/detections/endpoint/serviceprincipalnames_discovery_with_powershell.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-10-14' author: Michael Haag, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic identifies `powershell.exe` usage, using Script Block Logging EventCode 4104, related to querying the domain for Service Principle Names. typically, this is a precursor activity related to kerberoasting or the silver diff --git a/detections/endpoint/services_escalate_exe.yml b/detections/endpoint/services_escalate_exe.yml index 9b5d49aaa8..d498e06881 100644 --- a/detections/endpoint/services_escalate_exe.yml +++ b/detections/endpoint/services_escalate_exe.yml @@ -75,6 +75,6 @@ tags: - Processes.parent_process_id risk_score: 76 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index 5647bf7d47..ab3d4acfd4 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -71,6 +71,6 @@ tags: - Registry.dest risk_score: 48 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index 04d2595b95..222f9046cc 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -68,7 +68,7 @@ tags: - Processes.user risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index c23ae2d576..1a792d52c7 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -63,8 +63,9 @@ tags: - All_Changes.dest risk_score: 63 security_domain: access - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_microsoft-cloudservices - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose - Splunk_TA_cyberark diff --git a/detections/endpoint/silentcleanup_uac_bypass.yml b/detections/endpoint/silentcleanup_uac_bypass.yml index f4d7ee0fda..d486a01bb7 100644 --- a/detections/endpoint/silentcleanup_uac_bypass.yml +++ b/detections/endpoint/silentcleanup_uac_bypass.yml @@ -60,6 +60,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index 3a1badfb11..a7bcd3d9c5 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -66,8 +66,8 @@ tags: - Processes.process_name risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows diff --git a/detections/endpoint/slui_runas_elevated.yml b/detections/endpoint/slui_runas_elevated.yml index 4f19e1fde7..d966f6345d 100644 --- a/detections/endpoint/slui_runas_elevated.yml +++ b/detections/endpoint/slui_runas_elevated.yml @@ -72,6 +72,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/slui_spawning_a_process.yml b/detections/endpoint/slui_spawning_a_process.yml index d3cda3ac54..74ea2763af 100644 --- a/detections/endpoint/slui_spawning_a_process.yml +++ b/detections/endpoint/slui_spawning_a_process.yml @@ -70,6 +70,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml index 64f313ed08..630db87662 100644 --- a/detections/endpoint/spoolsv_writing_a_dll.yml +++ b/detections/endpoint/spoolsv_writing_a_dll.yml @@ -81,8 +81,8 @@ tags: - Processes.dest risk_score: 72 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows diff --git a/detections/endpoint/start_up_during_safe_mode_boot.yml b/detections/endpoint/start_up_during_safe_mode_boot.yml index 7221f234df..207d1b46df 100644 --- a/detections/endpoint/start_up_during_safe_mode_boot.yml +++ b/detections/endpoint/start_up_during_safe_mode_boot.yml @@ -59,6 +59,6 @@ tags: - Registry.dest risk_score: 42 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index 50c468f624..40514b30ee 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -79,6 +79,6 @@ tags: - Processes.user risk_score: 40 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index 726fbc4664..e7a20ed9d5 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -72,6 +72,6 @@ tags: - Processes.user risk_score: 35 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index d245184887..31e7dff7ff 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -78,7 +78,7 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index 5c7bf0a49b..6e5616636d 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -73,6 +73,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index 2cd0a8901e..1b00a621a3 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -77,7 +77,7 @@ tags: - Processes.user risk_score: 28 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/system_information_discovery_detection.yml b/detections/endpoint/system_information_discovery_detection.yml index 4448f1972b..f098533737 100644 --- a/detections/endpoint/system_information_discovery_detection.yml +++ b/detections/endpoint/system_information_discovery_detection.yml @@ -66,8 +66,8 @@ tags: - Processes.dest risk_score: 15 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index 9ce0208ecf..0bf3f0e869 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -82,7 +82,7 @@ tags: - Processes.process_hash risk_score: 49 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml index 5f64813caa..5e305337a5 100644 --- a/detections/endpoint/time_provider_persistence_registry.yml +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -67,6 +67,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/unified_messaging_service_spawning_a_process.yml b/detections/endpoint/unified_messaging_service_spawning_a_process.yml index 1726cd5cf6..875bb25a4e 100644 --- a/detections/endpoint/unified_messaging_service_spawning_a_process.yml +++ b/detections/endpoint/unified_messaging_service_spawning_a_process.yml @@ -71,6 +71,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/uninstall_app_using_msiexec.yml b/detections/endpoint/uninstall_app_using_msiexec.yml index d6f01d390a..c554e89da5 100644 --- a/detections/endpoint/uninstall_app_using_msiexec.yml +++ b/detections/endpoint/uninstall_app_using_msiexec.yml @@ -65,6 +65,6 @@ tags: - Processes.parent_process_id risk_score: 30 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index 1d0a956510..35dc22a6ea 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -65,7 +65,7 @@ tags: - Processes.user risk_score: 45 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml b/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml index f72163eef3..cfa68d3777 100644 --- a/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml +++ b/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-09-13' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the use of PowerShell environment variables to identify the current logged user. Red Teams and adversaries may leverage this method to identify the diff --git a/detections/endpoint/usn_journal_deletion.yml b/detections/endpoint/usn_journal_deletion.yml index ca9e6d9bef..24034384ed 100644 --- a/detections/endpoint/usn_journal_deletion.yml +++ b/detections/endpoint/usn_journal_deletion.yml @@ -70,6 +70,6 @@ tags: - Processes.dest risk_score: 45 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/wbadmin_delete_system_backups.yml b/detections/endpoint/wbadmin_delete_system_backups.yml index a7013ed7d7..56af59a5e7 100644 --- a/detections/endpoint/wbadmin_delete_system_backups.yml +++ b/detections/endpoint/wbadmin_delete_system_backups.yml @@ -64,7 +64,7 @@ tags: - Processes.user risk_score: 15 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/wget_download_and_bash_execution.yml b/detections/endpoint/wget_download_and_bash_execution.yml index 19fc18ddc7..41141ae6e7 100644 --- a/detections/endpoint/wget_download_and_bash_execution.yml +++ b/detections/endpoint/wget_download_and_bash_execution.yml @@ -78,6 +78,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/windows_adfind_exe.yml b/detections/endpoint/windows_adfind_exe.yml index 494d1774c2..e16c0d6e7b 100644 --- a/detections/endpoint/windows_adfind_exe.yml +++ b/detections/endpoint/windows_adfind_exe.yml @@ -58,6 +58,6 @@ tags: - Processes.process_id - Processes.parent_process_id security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/windows_disableantispyware_reg.yml b/detections/endpoint/windows_disableantispyware_reg.yml index 89e638c918..0bf3326238 100644 --- a/detections/endpoint/windows_disableantispyware_reg.yml +++ b/detections/endpoint/windows_disableantispyware_reg.yml @@ -68,6 +68,6 @@ tags: - Registry.registry_path risk_score: 24 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/windows_service_created_with_suspicious_service_path.yml b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml index c3fa2d88f7..59d1a719bc 100644 --- a/detections/endpoint/windows_service_created_with_suspicious_service_path.yml +++ b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml @@ -4,8 +4,7 @@ version: 2 date: '2021-11-22' author: Teoderick Contreras, Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytc uses Windows Event Id 7045, `New Service Was Installed`, to identify the creation of a Windows Service where the service binary path path is located in a non-common Service folder in Windows. Red Teams and adversaries diff --git a/detections/endpoint/windows_service_created_within_public_path.yml b/detections/endpoint/windows_service_created_within_public_path.yml index 483bbb5954..af64377a16 100644 --- a/detections/endpoint/windows_service_created_within_public_path.yml +++ b/detections/endpoint/windows_service_created_within_public_path.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-11-22' author: Mauricio Velazco, Splunk type: TTP -datamodel: -- Endpoint +datamodel: [] description: The following analytc uses Windows Event Id 7045, `New Service Was Installed`, to identify the creation of a Windows Service where the service binary path is located in public paths. This behavior could represent the installation of a malicious service. diff --git a/detections/endpoint/wsreset_uac_bypass.yml b/detections/endpoint/wsreset_uac_bypass.yml index 5b9a81bbfb..75b25a90d1 100644 --- a/detections/endpoint/wsreset_uac_bypass.yml +++ b/detections/endpoint/wsreset_uac_bypass.yml @@ -61,6 +61,6 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/xsl_script_execution_with_wmic.yml b/detections/endpoint/xsl_script_execution_with_wmic.yml index dd69f41f6e..4c96db18e3 100644 --- a/detections/endpoint/xsl_script_execution_with_wmic.yml +++ b/detections/endpoint/xsl_script_execution_with_wmic.yml @@ -77,6 +77,6 @@ tags: - Processes.user risk_score: 49 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/experimental/endpoint/print_processor_registry_autostart.yml b/detections/experimental/endpoint/print_processor_registry_autostart.yml index f654e0db1e..48e2c132e1 100644 --- a/detections/experimental/endpoint/print_processor_registry_autostart.yml +++ b/detections/experimental/endpoint/print_processor_registry_autostart.yml @@ -67,6 +67,6 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/detections/experimental/endpoint/randomly_generated_scheduled_task_name.yml b/detections/experimental/endpoint/randomly_generated_scheduled_task_name.yml index 197d64c2c3..5d4a7ebb1a 100644 --- a/detections/experimental/endpoint/randomly_generated_scheduled_task_name.yml +++ b/detections/experimental/endpoint/randomly_generated_scheduled_task_name.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-11-29' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following hunting analytic leverages Event ID 4698, `A scheduled task was created`, to identify the creation of a Scheduled Task with a suspicious, high entropy, Task Name. To achieve this, this analytic also leverages the `ut_shannon` diff --git a/detections/experimental/endpoint/randomly_generated_windows_service_name.yml b/detections/experimental/endpoint/randomly_generated_windows_service_name.yml index ea1bffb29f..7f857f29e1 100644 --- a/detections/experimental/endpoint/randomly_generated_windows_service_name.yml +++ b/detections/experimental/endpoint/randomly_generated_windows_service_name.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-11-29' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: The following hunting analytic leverages Event ID 7045, `A new service was installed in the system`, to identify the installation of a Windows Service with a suspicious, high entropy, Service Name. To achieve this, this analytic also diff --git a/detections/experimental/endpoint/unusual_number_of_computer_service_tickets_requested.yml b/detections/experimental/endpoint/unusual_number_of_computer_service_tickets_requested.yml index c382b71c0d..68f71a22c7 100644 --- a/detections/experimental/endpoint/unusual_number_of_computer_service_tickets_requested.yml +++ b/detections/experimental/endpoint/unusual_number_of_computer_service_tickets_requested.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-12-01' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: 'The following hunting analytic leverages Event ID 4769, `A Kerberos service ticket was requested`, to identify an unusual number of computer service ticket requests from one source. When a domain joined endpoint connects to a remote diff --git a/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml b/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml index 47668c6ddf..7badfa0288 100644 --- a/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml +++ b/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-12-01' author: Mauricio Velazco, Splunk type: Hunting -datamodel: -- Endpoint +datamodel: [] description: 'The following hunting analytic leverages Event ID 4624, `An account was successfully logged on`, to identify an unusual number of remote authentication attempts coming from one source. An endpoint authenticating to a large number of @@ -23,7 +22,7 @@ search: ' `wineventlog_security` EventCode=4624 Logon_Type=3 Account_Name!="*$" AS unique_targets values(ComputerName) as target_hosts by _time, Source_Network_Address, Source_Account | eventstats avg(unique_targets) as comp_avg , stdev(unique_targets) as comp_std by Source_Network_Address, Source_Account | eval upperBound=(comp_avg+comp_std*3) - | eval isOutlier=if(unique_targets >10 and unique_targets >= upperBound, 1, 0) `unusual_number_of_remote_endpoint_authentication_events_filter`' + | eval isOutlier=if(unique_targets >10 and unique_targets >= upperBound, 1, 0) | `unusual_number_of_remote_endpoint_authentication_events_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers aas well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs diff --git a/detections/network/dns_query_length_with_high_standard_deviation.yml b/detections/network/dns_query_length_with_high_standard_deviation.yml index 6141540fa0..151e3d36c3 100644 --- a/detections/network/dns_query_length_with_high_standard_deviation.yml +++ b/detections/network/dns_query_length_with_high_standard_deviation.yml @@ -66,8 +66,8 @@ tags: - DNS.query risk_score: 56 security_domain: network - cim_version: 4.20.2 - supported_tas: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_isc-bind - Splunk_TA_CrowdStrike_FDR - Splunk_TA_infoblox diff --git a/security_content_automation/detection_ta_mapping.yml b/security_content_automation/detection_ta_mapping.yml index c9ba50693b..9d2eaae45e 100644 --- a/security_content_automation/detection_ta_mapping.yml +++ b/security_content_automation/detection_ta_mapping.yml @@ -1,6 +1,8 @@ abnormally_high_number_of_cloud_infrastructure_api_calls: cim_version: 5.0.0 supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_nix - Splunk_TA_rsa-securid @@ -14,11 +16,11 @@ abnormally_high_number_of_cloud_infrastructure_api_calls: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose abnormally_high_number_of_cloud_security_group_api_calls: cim_version: 5.0.0 supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_nix - Splunk_TA_rsa-securid @@ -32,107 +34,107 @@ abnormally_high_number_of_cloud_security_group_api_calls: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose active_setup_registry_autostart: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack add_defaultuser_and_password_in_registr: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack allow_inbound_traffic_by_firewall_rule_registr: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack allow_operation_with_consent_admin: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack anomalous_usage_of_7zip: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack attacker_tools_on_endpoint: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows attempt_to_add_certificate_to_untrusted_store: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack auto_admin_logon_registry_entr: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack batch_file_write_to_system32: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR bcdedit_command_back_to_normal_mode_boot: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack bcdedit_failure_recovery_modification: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR change_default_file_association: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack change_to_safe_mode_with_network_config: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack check_elevated_cmd_using_whoami: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack cloud_api_calls_from_previously_unseen_user_roles: cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose + tas_with_cim_mapping: + - Splunk_TA_aws-kinesis-firehose - Splunk_TA_rsa_securid_cas - splunk_ta_o365 - Splunk_TA_box - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose cloud_compute_instance_created_by_previously_unseen_user: cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose - tas_with_data: + tas_with_cim_mapping: - Splunk_TA_aws-kinesis-firehose cloud_compute_instance_created_in_previously_unused_region: cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose - tas_with_data: + tas_with_cim_mapping: - Splunk_TA_aws-kinesis-firehose cloud_compute_instance_created_with_previously_unseen_image: cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose - tas_with_data: + tas_with_cim_mapping: - Splunk_TA_aws-kinesis-firehose cloud_compute_instance_created_with_previously_unseen_instance_type: cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose - tas_with_data: + tas_with_cim_mapping: - Splunk_TA_aws-kinesis-firehose cloud_instance_modified_with_previously_unseen_user: cim_version: 5.0.0 supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_nix - Splunk_TA_rsa-securid @@ -144,11 +146,11 @@ cloud_instance_modified_with_previously_unseen_user: - Splunk_TA_cyberark - Splunk_TA_box - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose cloud_provisioning_from_previously_unseen_cit: cim_version: 5.0.0 supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose @@ -160,11 +162,11 @@ cloud_provisioning_from_previously_unseen_cit: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose cloud_provisioning_from_previously_unseen_countr: cim_version: 5.0.0 supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose @@ -176,11 +178,11 @@ cloud_provisioning_from_previously_unseen_countr: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose cloud_provisioning_from_previously_unseen_ip_address: cim_version: 5.0.0 supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose @@ -190,11 +192,11 @@ cloud_provisioning_from_previously_unseen_ip_address: - Splunk_TA_cyberark - Splunk_TA_box - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose cloud_provisioning_from_previously_unseen_region: cim_version: 5.0.0 supported_tas: + - Splunk_TA_aws-kinesis-firehose + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose @@ -206,173 +208,171 @@ cloud_provisioning_from_previously_unseen_region: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce - tas_with_data: - - Splunk_TA_aws-kinesis-firehose curl_download_and_bash_execution: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack detect_exchange_web_she: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR detect_regasm_spawning_a_process: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack detect_regsvcs_spawning_a_process: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack detect_sharphound_command_line_arguments: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack detect_use_of_cmd_exe_to_launch_script_interpreters: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disable_amsi_through_registr: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disable_etw_through_registr: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disable_logs_using_wevtuti: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disable_registry_too: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disable_schedule_task: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR disable_windows_app_hotkeys: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disable_windows_behavior_monitoring: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disabling_cmd_application: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disabling_controlpane: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disabling_folderoptions_windows_feature: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disabling_norun_windows_app: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disabling_systemrestore_in_registr: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack disabling_task_manager: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack dns_query_length_with_high_standard_deviation: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_isc-bind - Splunk_TA_CrowdStrike_FDR - Splunk_TA_infoblox domain_account_discovery_with_net_app: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack domain_account_discovery_with_wmic: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack dsquery_domain_discover: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR dump_lsass_via_procdump: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR enable_rdp_in_other_port_number: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack eventvwr_uac_bypass: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack excessive_attempt_to_disable_services: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR excessive_number_of_distinct_processes_created_in_windows_temp_folder: cim_version: 5.0.0 supported_tas: + - Splunk_TA_windows + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm - tas_with_data: - - Splunk_TA_windows excessive_number_of_service_control_start_as_disabled: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack excessive_number_of_taskhost_processes: cim_version: 5.0.0 supported_tas: + - Splunk_TA_windows + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR - tas_with_data: - - Splunk_TA_windows excessive_usage_of_cacls_app: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR excessive_usage_of_taskki: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR executables_or_script_creation_in_suspicious_path: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR execute_javascript_with_jscript_com_clsid: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack execution_of_file_with_multiple_extensions: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows file_with_samsam_extension: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - splunk_ta_o365 @@ -382,54 +382,175 @@ file_with_samsam_extension: - Splunk_TA_CrowdStrike_FDR firewall_allowed_program_enable: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack fodhelper_uac_bypass: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack fsutil_zeroing_file: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack get_aduserresultantpasswordpolicy_with_powershe: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack get_domainpolicy_with_powershe: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack get_domainuser_with_powershe: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack getwmiobject_ds_user_with_powershe: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack hide_user_account_from_sign_in_screen: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack hiding_files_and_directories_with_attrib_exe: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_windows icacls_deny_command: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR icacls_grant_command: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_add_files_in_known_crontab_directories: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack +inux_at_allow_config_file_creation: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack +inux_at_application_execution: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_change_file_owner_to_root: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_doas_conf_file_creation: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack +inux_doas_tool_execution: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_file_created_in_kernel_driver_director: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack +inux_file_creation_in_init_boot_director: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack +inux_file_creation_in_profile_director: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack +inux_insert_kernel_module_using_insmod_utilit: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_install_kernel_module_using_modprobe_utilit: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_nopasswd_entry_in_sudoers_file: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_possible_access_or_modification_of_sshd_config_file: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_possible_access_to_credential_files: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_possible_access_to_sudoers_file: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_possible_append_command_to_at_allow_config_file: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_possible_append_command_to_profile_config_file: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_possible_ssh_key_file_creation: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack +inux_preload_hijack_library_calls: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_service_file_created_in_systemd_director: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack +inux_service_restarted: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_service_started_or_enabled: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_setuid_using_chmod_utilit: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_setuid_using_setcap_utilit: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_CrowdStrike_FDR +inux_sudoers_tmp_file_creation: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack +inux_visudo_utility_execution: + cim_version: 5.0.0 + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR java_class_file_download_by_java_user_agent: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_citrix-netscaler - Splunk_TA_nginx - Splunk_TA_microsoft-iis @@ -440,32 +561,32 @@ java_class_file_download_by_java_user_agent: - Splunk_TA_cisco-wsa jscript_execution_using_cscript_app: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack net_profiler_uac_bypass: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack nltest_domain_trust_discover: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack ntdsutil_export_ntds: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack odify_acl_permission_to_files_or_folder: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR ogon_script_event_trigger_execution: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack overwriting_accessibility_binaries: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_ossec - Splunk_TA_bit9-carbonblack @@ -476,11 +597,14 @@ overwriting_accessibility_binaries: - Splunk_TA_CrowdStrike_FDR permission_modification_using_takeown_app: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack powershell_execute_com_object: cim_version: 5.0.0 supported_tas: + - Splunk_TA_windows + tas_with_cim_mapping: + - Splunk_TA_microsoft-cloudservices - Splunk_TA_cisco-ucs - Splunk_TA_citrix-netscaler - Splunk_TA_nix @@ -537,63 +661,61 @@ powershell_execute_com_object: - Splunk_TA_cyberark_epm - Splunk_TA_linux - Splunk_TA_oracle - tas_with_data: - - Splunk_TA_windows prevent_automatic_repair_mode_using_bcdedit: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack print_processor_registry_autostart: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack process_creating_lnk_file_in_suspicious_location: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR process_execution_via_wmi: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR processes_launching_netsh: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack reg_exe_manipulating_windows_services_registry_keys: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR registry_keys_used_for_persistence: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack remote_wmi_command_attempt: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack resize_shadowstorage_volume: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR revil_common_exec_parameter: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack revil_registry_entr: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack ryuk_wake_on_lan_command: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack samsam_test_file_write: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - splunk_ta_o365 @@ -603,35 +725,35 @@ samsam_test_file_write: - Splunk_TA_CrowdStrike_FDR sc_exe_manipulating_windows_services: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR scheduled_task_deleted_or_created_via_cmd: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack schtasks_run_task_on_demand: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR schtasks_scheduling_job_on_remote_syste: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR schtasks_used_for_forcing_a_reboot: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR screensaver_event_trigger_execution: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack script_execution_via_wmi: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows @@ -639,38 +761,39 @@ script_execution_via_wmi: - Splunk_TA_cyberark_epm sdclt_uac_bypass: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack secretdumps_offline_ntds_dumping_too: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack services_escalate_exe: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack set_default_powershell_execution_policy_to_unrestricted_or_bypass: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack shim_database_installation_with_suspicious_parameters: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR short_lived_windows_accounts: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: + - Splunk_TA_microsoft-cloudservices - Splunk_TA_rsa-securid - Splunk_TA_aws-kinesis-firehose - Splunk_TA_cyberark silentcleanup_uac_bypass: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack single_letter_process_on_endpoint: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows @@ -678,53 +801,53 @@ single_letter_process_on_endpoint: - Splunk_TA_cyberark_epm slui_runas_elevated: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack slui_spawning_a_process: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack smpeng_application_dll_side_loading: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR spoolsv_writing_a_d: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR start_up_during_safe_mode_boot: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack suspicious_mshta_child_process: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack suspicious_process_file_path: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack suspicious_reg_exe_process: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR suspicious_scheduled_task_from_public_director: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack suspicious_wevtutil_usage: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR system_information_discovery_detection: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - Splunk_TA_windows @@ -732,52 +855,52 @@ system_information_discovery_detection: - Splunk_TA_cyberark_epm system_processes_run_from_unexpected_locations: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR time_provider_persistence_registr: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack unified_messaging_service_spawning_a_process: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack uninstall_app_using_msiexec: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack unload_sysmon_filter_driver: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR usn_journal_deletion: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack wbadmin_delete_system_backups: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - Splunk_TA_CrowdStrike_FDR wget_download_and_bash_execution: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack windows_adfind_exe: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack windows_disableantispyware_reg: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack wsreset_uac_bypass: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack xsl_script_execution_with_wmic: cim_version: 5.0.0 - supported_tas: + tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index 73c01de2f5..3c6670c630 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -38,6 +38,7 @@ def map_required_fields(cim_summary, datamodel, required_fields): add_addon = True flag = 0 for item in required_fields: + # Only required field with valid format will be mapped if re.match("^[A-Za-z0-9_.]*$", item): if item == "_time" or item == "_times": continue @@ -139,7 +140,7 @@ def main(): for file in files: filepath = subdir + os.sep + file - supported_ta_list = [] + recommended_ta_list = [] tas_with_data_list = [] detection_obj = load_file(filepath) source_types = [] @@ -176,7 +177,7 @@ def main(): cim_version = ta_cim_map["cim_version"] if result: - supported_ta_list.append( + recommended_ta_list.append( ta_cim_map.get("ta_name").get("name") ) ta_sourcetype = ta_cim_map["sourcetypes"] @@ -192,19 +193,19 @@ def main(): ) detection_ta_mapping[detection_file_name] = {} - if supported_ta_list: - keyname = "supported_tas" + if recommended_ta_list: + keyname = "tas_with_cim_mapping" enrich_detection_file(filepath, cim_version, "cim_version") - enrich_detection_file(filepath, supported_ta_list, keyname) + enrich_detection_file(filepath, recommended_ta_list, keyname) detection_ta_mapping[detection_file_name][ "cim_version" ] = cim_version detection_ta_mapping[detection_file_name][ keyname - ] = supported_ta_list + ] = recommended_ta_list if tas_with_data_list: - keyname = "tas_with_data" + keyname = "supported_tas" enrich_detection_file(filepath, tas_with_data_list, keyname) detection_ta_mapping[detection_file_name][ keyname @@ -226,19 +227,18 @@ def main(): ["security_content_automation/detection_ta_mapping.yml"] ) security_content_repo_obj.index.commit( - "Updated detection files with supported TA list." + "Updated detection files with recommended TA list." ) epoch_time = str(int(time.time())) branch_name = "security_content_automation_" + epoch_time security_content_repo_obj.git.checkout("-b", branch_name) - security_content_repo_obj.git.push("--set-upstream", "origin", branch_name) repo = g.get_repo("splunk/security_content") pr = repo.create_pull( title="Enrich Detection PR " + branch_name, - body="Enriched the detections with supported TAs", + body="Enriched the detections with recommended TAs", head=branch_name, base="develop", ) From f25735d8315b13b651c076a51646ecb3418f35b8 Mon Sep 17 00:00:00 2001 From: Detection Testing Service Date: Tue, 25 Jan 2022 18:03:28 +0530 Subject: [PATCH 13/25] test: updated logic to remove unneccesary tas --- security_content_automation/enrich_detections.py | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index 3c6670c630..7adafed1d8 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -35,7 +35,7 @@ def load_file(file_path): def map_required_fields(cim_summary, datamodel, required_fields): datasets_fields = {} - add_addon = True + add_addon = False flag = 0 for item in required_fields: # Only required field with valid format will be mapped @@ -65,6 +65,9 @@ def map_required_fields(cim_summary, datamodel, required_fields): cim_fields = e_type.get("fields", []) if set(datasets_fields[dataset]).issubset(set(cim_fields)): add_addon = True + else: + add_addon = False + return add_addon return add_addon From 5bc6118cb04dc5d8e7a64e3ea732d2b70089de55 Mon Sep 17 00:00:00 2001 From: Detection Testing Service Date: Thu, 27 Jan 2022 02:18:31 +0530 Subject: [PATCH 14/25] test:updated logic to remove unnesseary tas --- .../add_or_set_windows_defender_exclusion.yml | 13 +-- .../attempt_to_stop_security_service.yml | 2 + ...detect_autosuid_post_exploitation_tool.yml | 55 +++++++++++++ .../endpoint/detect_linenum_execution.yml | 63 +++++++++++++++ .../endpoint/detect_linpeas_execution.yml | 63 +++++++++++++++ ...tect_linux_exploit_suggester_execution.yml | 57 +++++++++++++ detections/endpoint/detect_mimipenguin.yml | 54 +++++++++++++ ...ve_file_deletion_in_windefender_folder.yml | 75 +++++++++++++++++ ..._or_script_creation_in_suspicious_path.yml | 9 ++- .../endpoint/high_file_deletion_frequency.yml | 2 + .../endpoint/ping_sleep_batch_command.yml | 81 +++++++++++++++++++ .../powershell_execute_com_object.yml | 61 -------------- ...hell_remove_windows_defender_directory.yml | 67 +++++++++++++++ ...ll_windows_defender_exclusion_commands.yml | 2 + ...process_deleting_its_process_file_path.yml | 12 +-- ...ssa___anomalous_usage_of_archive_tools.yml | 1 + .../ssa___attempt_to_delete_services.yml | 2 +- .../ssa___attempt_to_disable_services.yml | 2 +- ...dential_dump_from_registry_via_reg_exe.yml | 2 +- ..._bcdedit_failure_recovery_modification.yml | 2 +- .../endpoint/ssa___delete_a_net_user.yml | 2 +- ...___deny_permission_using_cacls_utility.yml | 2 +- ...detect_dump_lsass_memory_using_comsvcs.yml | 2 +- ...ssa___detect_rclone_command_line_usage.yml | 1 + .../ssa___disable_net_user_account.yml | 2 +- ...___dns_exfiltration_using_nslookup_app.yml | 3 +- .../endpoint/ssa___fsutil_zeroing_file.yml | 5 +- ...__grant_permission_using_cacls_utility.yml | 2 +- ...fy_acls_permission_of_files_or_folders.yml | 2 +- ...sh_observed_at_the_destination_device.yml} | 2 +- ...bserved_by_an_event_collecting_device.yml} | 2 +- .../ssa___resize_shadowstorage_volume.yml | 2 +- .../ssa___sdelete_application_execution.yml | 1 + ...cess_running_from_unexpected_location.yml} | 2 +- ...unusual_lolbas_in_short_period_of_time.yml | 6 +- .../ssa___wbadmin_delete_system_backups.yml | 5 +- .../ssa___wevtutil_usage_to_disable_logs.yml | 2 +- ...dows_curl_upload_to_remote_destination.yml | 1 + .../endpoint/suspicious_process_file_path.yml | 12 +-- ...picious_process_with_discord_dns_query.yml | 73 +++++++++++++++++ ...dows_defender_exclusion_registry_entry.yml | 15 +++- ...pt_or_cscript_suspicious_child_process.yml | 19 ++--- ...xcessive_number_of_office_files_copied.yml | 1 + .../ssa___high_file_deletion_frequency.yml | 1 + ..._remote_endpoint_authentication_events.yml | 3 +- .../detection_ta_mapping.yml | 62 -------------- .../enrich_detections.py | 3 - 47 files changed, 678 insertions(+), 180 deletions(-) create mode 100644 detections/endpoint/detect_autosuid_post_exploitation_tool.yml create mode 100644 detections/endpoint/detect_linenum_execution.yml create mode 100644 detections/endpoint/detect_linpeas_execution.yml create mode 100644 detections/endpoint/detect_linux_exploit_suggester_execution.yml create mode 100644 detections/endpoint/detect_mimipenguin.yml create mode 100644 detections/endpoint/excessive_file_deletion_in_windefender_folder.yml create mode 100644 detections/endpoint/ping_sleep_batch_command.yml create mode 100644 detections/endpoint/powershell_remove_windows_defender_directory.yml rename detections/endpoint/{ssa___ptt_pth_kerb_ntlm_dest_device.yml => ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml} (99%) rename detections/endpoint/{ssa___ptt_pth_kerb_ntlm_origin_device.yml => ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml} (99%) rename detections/endpoint/{ssa___system_process_running_unexpected_location.yml => ssa___system_process_running_from_unexpected_location.yml} (99%) create mode 100644 detections/endpoint/suspicious_process_with_discord_dns_query.yml rename detections/{ => experimental}/endpoint/ssa___excessive_number_of_office_files_copied.yml (98%) rename detections/{ => experimental}/endpoint/ssa___high_file_deletion_frequency.yml (99%) diff --git a/detections/endpoint/add_or_set_windows_defender_exclusion.yml b/detections/endpoint/add_or_set_windows_defender_exclusion.yml index 8fe360863f..d75c943cd9 100644 --- a/detections/endpoint/add_or_set_windows_defender_exclusion.yml +++ b/detections/endpoint/add_or_set_windows_defender_exclusion.yml @@ -6,10 +6,10 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: This analytic will detect a suspicious process commandline related to - windows defender exclusion feature. This command is abused by adversaries, malware - author and red teams to bypassed Windows Defender Anti-Virus product by excluding folder - path, file path, process, extensions and etc. from its real time or schedule scan +description: This analytic will identify a suspicious process command-line related + to Windows Defender exclusion feature. This command is abused by adversaries, malware + authors and red teams to bypass Windows Defender Antivirus products by excluding + folder path, file path, process and extensions. From its real time or schedule scan to execute their malicious code. This is a good indicator for defense evasion and to look further for events after this behavior. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) @@ -23,14 +23,17 @@ how_to_implement: To successfully implement this search you need to be ingesting on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. -known_false_positives: admin or user may choose to use this windows features. +known_false_positives: Admin or user may choose to use this windows features. Filter + as needed. references: - https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html - https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - Remcos - Windows Defense Evasion Tactics + - WhisperGate automated_detection_testing: passed confidence: 80 context: diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index 1f5645aacf..fe2fd4b662 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -25,10 +25,12 @@ known_false_positives: None identified. Attempts to disable security-related ser should be identified and understood. references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - Disabling Security Tools - Trickbot + - WhisperGate asset_type: Endpoint automated_detection_testing: passed cis20: diff --git a/detections/endpoint/detect_autosuid_post_exploitation_tool.yml b/detections/endpoint/detect_autosuid_post_exploitation_tool.yml new file mode 100644 index 0000000000..32a52632b2 --- /dev/null +++ b/detections/endpoint/detect_autosuid_post_exploitation_tool.yml @@ -0,0 +1,55 @@ +name: Detect AutoSUID post exploitation tool +id: 0edd5862-56c9-11ec-b990-acde48001122 +version: 1 +date: '2021-12-06' +author: Rod Soto +type: TTP +datamodel: +- Endpoint +description: This search, detects Linux post exploitation tool AutoSUID, which is + an a tool that searches for SUID executables files in order to escalate privileges. +search: ' `sysmon_linux` CommandLine="find / -xdev -user root ( -perm -4000 -o -perm + -2000 -o -perm -6000 )" | stats count by Computer process process_current_directory + process_path | `detect_autosuid_post_exploitation_tool_filter`' +how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux. + Need to install this add-on to parse fields correctly and execute detection search. +known_false_positives: Unless an administrator is using these commands to troubleshoot + or audit a system, the execution of these commands should be monitored. +references: +- https://attack.mitre.org/matrices/enterprise/linux/ +- https://github.com/IvanGlinkin/AutoSUID +tags: + analytic_story: + - Linux Post-Exploitation + automated_detection_testing: passed + confidence: 90 + context: + - Source: Endpoint + - Stage: Discovery + dataset: + - https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/autoSUID.txt + impact: 90 + kill_chain_phases: + - Exploitation + - Privilege Escalation + message: AutoSUID post exploitation tool detected + mitre_attack_id: + - T1069 + - T1222 + observable: + - name: Computer + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Computer + - process + - process_path + - process_current_directory + risk_score: 81 + security_domain: endpoint diff --git a/detections/endpoint/detect_linenum_execution.yml b/detections/endpoint/detect_linenum_execution.yml new file mode 100644 index 0000000000..cea9fb1517 --- /dev/null +++ b/detections/endpoint/detect_linenum_execution.yml @@ -0,0 +1,63 @@ +name: Detect LinEnum execution +id: 570e5278-5479-11ec-89c8-acde48001122 +version: 1 +date: '2021-12-03' +author: Rod Soto +type: TTP +datamodel: +- Endpoint +description: LinEnum is a bash script that performs discovery commands for accounts, + processes, kernel version, applications, services, and uses the information from + these commands to present operator with ways of escalating privileges or further + exploitation of targeted host. +search: ' `sysmon_linux` CommandLine="grep -w aria2c\\|arp\\|ash\\|awk\\|base64\\|bash\\|busybox\\|cat\\|chmod\\|chown\\|cp\\|csh\\|curl\\|cut\\|dash\\|date\\|dd\\|diff\\|dmsetup\\|docker\\|ed\\|emacs\\|env\\|expand\\|expect\\|file\\|find\\|flock\\|fmt\\|fold\\|ftp\\|gawk\\|gdb\\|gimp\\|git\\|grep\\|head\\|ht\\|iftop\\|ionice\\|ip$\\|irb\\|jjs\\|jq\\|jrunscript\\|ksh\\|ld.so\\|ldconfig\\|less\\|logsave\\|lua\\|make\\|man\\|mawk\\|more\\|mv\\|mysql\\|nano\\|nawk\\|nc\\|netcat\\|nice\\|nl\\|nmap\\|node\\|od\\|openssl\\|perl\\|pg\\|php\\|pic\\|pico\\|python\\|readelf\\|rlwrap\\|rpm\\|rpmquery\\|rsync\\|ruby\\|run-parts\\|rvim\\|scp\\|script\\|sed\\|setarch\\|sftp\\|sh\\|shuf\\|socat\\|sort\\|sqlite3\\|ssh$\\|start-stop-daemon\\|stdbuf\\|strace\\|systemctl\\|tail\\|tar\\|taskset\\|tclsh\\|tee\\|telnet\\|tftp\\|time\\|timeout\\|ul\\|unexpand\\|uniq\\|unshare\\|vi\\|vim\\|watch\\|wget\\|wish\\|xargs\\|xxd\\|zip\\|zsh" + | stats count by Computer CommandLine user process_exec process_current_directory + | `detect_linenum_execution_filter` ' +how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux. + Need to install this add-on to parse fields correctly and execute detection search. +known_false_positives: Very rare to perform such an extensive grep on a system, however + certain monitoring tools can produce similar results. It is important if monitoring + tools are in place to verify what is the actual process directory of execution. +references: +- https://github.com/rebootuser/LinEnum +- https://book.hacktricks.xyz/linux-unix/linux-privilege-escalation-checklist +tags: + analytic_story: + - Linux Post-Exploitation + automated_detection_testing: passed + confidence: 90 + context: + - Source: endpoint + - Stage: discovery + dataset: + - https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/LinuxEnumd.txt + impact: 50 + kill_chain_phases: + - Privilege Escalation + message: LinEnum post exploitation tool detected + mitre_attack_id: + - T1087 + - T1069 + - T1083 + - T1057 + - T1518 + - T1082 + - T1016 + - T1033 + observable: + - name: Computer + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - CommandLine + - user + - process_exec + - process_current_directory + risk_score: 45 + security_domain: endpoint diff --git a/detections/endpoint/detect_linpeas_execution.yml b/detections/endpoint/detect_linpeas_execution.yml new file mode 100644 index 0000000000..527ab77df7 --- /dev/null +++ b/detections/endpoint/detect_linpeas_execution.yml @@ -0,0 +1,63 @@ +name: Detect LinPeas Execution +id: 4ea6fa10-547c-11ec-a4f9-acde48001122 +version: 1 +date: '2021-12-03' +author: Rod Soto +type: TTP +datamodel: +- Endpoint +description: Linux local Privilege Escalation Awesome Script (linPEAS) is a script + that searches for possible paths to escalate privileges. +search: ' `sysmon_linux` CommandLine!=null parent_process_exec=sudo OR parent_process_exec=bash + OR CommandLine="cve-list" | stats count by Computer CommandLine user parent_process_exec + process_path | `detect_linpeas_execution_filter`' +how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux. + Need to install this add-on to parse fields correctly and execute detection search. +known_false_positives: This search may produce false positives as it will display + many sudo executed processess however, the cve-list within the command line it is + a clear indicator, operator is searching for local vulnerabilites. +references: +- https://book.hacktricks.xyz/linux-unix/linux-privilege-escalation-checklist +- https://github.com/carlospolop/PEASS-ng/tree/master/linPEAS +- https://attack.mitre.org/matrices/enterprise/linux/ +tags: + analytic_story: + - Linux Post-Exploitation + confidence: 100 + context: + - Source: endpoint + - Stage: discovery + dataset: + - https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/linpeasdataset.txt + impact: 90 + kill_chain_phases: + - Exploitation + - Privilege Escalation + message: LinPEAS post exploitation tool detected + mitre_attack_id: + - T1082 + - T1083 + - T1033 + - T1087 + - T1046 + - T1057 + - T1518 + - T1033 + observable: + - name: Computer + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Computer + - CommandLine + - user + - parent_process_exec + - process_path + risk_score: 90 + security_domain: endpoint diff --git a/detections/endpoint/detect_linux_exploit_suggester_execution.yml b/detections/endpoint/detect_linux_exploit_suggester_execution.yml new file mode 100644 index 0000000000..44c9b56699 --- /dev/null +++ b/detections/endpoint/detect_linux_exploit_suggester_execution.yml @@ -0,0 +1,57 @@ +name: Detect Linux Exploit Suggester Execution +id: a4f34d5c-547b-11ec-ba88-acde48001122 +version: 1 +date: '2021-12-03' +author: Rod Soto +type: TTP +datamodel: +- Endpoint +description: This search detects Linux Exploit Suggester tool execution. This is a + tool that searches for vulnerabilities based on Kernel and Distribution versions + then queries public exploit databases. +search: ' `sysmon_linux` CommandLine="cvelist-file:" OR CommandLine="uname -a" OR + CommandLine="*exploit*" OR CommandLine="*exploit-db*" | stats count by CommandLine,user,Computer,action,signature, + process_name | `detect_linux_exploit_suggester_execution_filter`' +how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux. + Need to install this add-on to parse fields correctly and execute detection search. +known_false_positives: Monitoring tools may produce similar commands although the + presence of "exploit-db" is very unusual. +references: +- https://book.hacktricks.xyz/linux-unix/linux-privilege-escalation-checklist +- https://attack.mitre.org/matrices/enterprise/linux/ +tags: + analytic_story: + - Linux Post-Exploitation + automated_detection_testing: passed + confidence: 100 + context: + - Source: endpoint + - Stage: discovery + dataset: + - https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/linuxexploitsuggesterdatasets.txt + impact: 90 + kill_chain_phases: + - Exploitation + - Privilege Escalation + message: Linux Exploit Suggester post exploitation tool detected. + mitre_attack_id: + - T1087 + - T1083 + - T1069 + - T1057 + - T1518 + - T1082 + observable: + - name: Computer + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - CommandLine + risk_score: 90 + security_domain: endpoint diff --git a/detections/endpoint/detect_mimipenguin.yml b/detections/endpoint/detect_mimipenguin.yml new file mode 100644 index 0000000000..50dcd97758 --- /dev/null +++ b/detections/endpoint/detect_mimipenguin.yml @@ -0,0 +1,54 @@ +name: Detect MimiPenguin +id: 1ad20afa-547b-11ec-b4e7-acde48001122 +version: 1 +date: '2021-12-03' +author: Rod Soto +type: TTP +datamodel: +- Endpoint +description: MimiPenguin is a tool that dumps login passwords from current linux destop + users. This search detects execution of this tool. +search: ' `sysmon_linux` CommandLine="strings -e /etc/apache2/apache2.conf" OR CommandLine="strings + -e /etc/ssh/sshd_config" OR CommandLine="strings -e /etc/shadow" | stats count + by Computer parent_process process_current_directory user CommandLine | `detect_mimipenguin_filter`' +how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux. + Need to install this add-on to parse fields correctly and execute detection search. +known_false_positives: Some of these commands may be executed by sysadmin however + not in the proximity and frequency, specially if querying for tools are that knonwn + not to be installed at target system. +references: +- https://github.com/huntergregal/mimipenguin +- https://attack.mitre.org/matrices/enterprise/linux/ +tags: + analytic_story: + - Linux Post-Exploitation + automated_detection_testing: passed + confidence: 70 + context: + - Source: endpoint + - Stage: discovery + dataset: + - https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/mimipenguin.txt + impact: 50 + kill_chain_phases: + - Privilege Escalation + message: MimiPenguin post exploitation tool detected + mitre_attack_id: + - T1552 + observable: + - name: Computer + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - user + - Computer + - parent_process + - process_current_directory + risk_score: 35 + security_domain: endpoint diff --git a/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml b/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml new file mode 100644 index 0000000000..6802ab9d27 --- /dev/null +++ b/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml @@ -0,0 +1,75 @@ +name: Excessive File Deletion In WinDefender Folder +id: b5baa09a-7a05-11ec-8da4-acde48001122 +version: 1 +date: '2022-01-20' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic will identify excessive file deletion events in the Windows + Defender folder. This technique was seen in the WhisperGate malware campaign in + which adversaries abused Nirsofts advancedrun.exe to gain administrative privilege + to then execute PowerShell commands to delete files within the Windows Defender + application folder. This behavior is a good indicator the offending process is trying + to corrupt a Windows Defender installation. +search: '`sysmon` EventCode=23 TargetFilename = "*\\ProgramData\\Microsoft\\Windows + Defender*" | stats values(TargetFilename) as deleted_files min(_time) as firstTime + max(_time) as lastTime count by user EventCode Image ProcessID Computer |where count + >=50 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `excessive_file_deletion_in_windefender_folder_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, TargetFilename, and ProcessID executions from your endpoints. + If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +known_false_positives: Windows Defender AV updates may cause this alert. Please update + the filter macros to remove false positives. +references: +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +tags: + analytic_story: + - WhisperGate + automated_detection_testing: passed + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 50 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_del_in_windefender_dir/sysmon.log + impact: 50 + kill_chain_phases: + - Exploitation + message: High frequency file deletion activity detected on host $Computer$ + mitre_attack_id: + - T1485 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: Computer + type: Endpoint + role: + - Victim + - name: deleted_files + type: File Name + role: + - Target + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - TargetFilename + - Computer + - user + - Image + - ProcessID + risk_score: 25 + security_domain: endpoint diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index 1464e2ba5f..1fd09e4f38 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -21,9 +21,10 @@ search: '|tstats `security_content_summariesonly` values(Filesystem.file_path) a = *\\Users\\Administrator\\Music\\* OR Filesystem.file_path = *\\Windows\\servicing\\* OR Filesystem.file_path = *\\Users\\Default\\* OR Filesystem.file_path = *Recycle.bin* OR Filesystem.file_path = *\\Windows\\Media\\* OR Filesystem.file_path = *\\Windows\\repair\\* - OR Filesystem.file_path = *\\AppData\\Local\\Temp*) by Filesystem.file_create_time - Filesystem.process_id Filesystem.file_name Filesystem.user | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `executables_or_script_creation_in_suspicious_path_filter`' + OR Filesystem.file_path = *\\AppData\\Local\\Temp* OR Filesystem.file_path = *\\PerfLogs\\*) + by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.user + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `executables_or_script_creation_in_suspicious_path_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. @@ -31,10 +32,12 @@ known_false_positives: Administrators may allow creation of script or exe in the specified. Filter as needed. references: - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - XMRig - Remcos + - WhisperGate automated_detection_testing: passed confidence: 70 context: diff --git a/detections/endpoint/high_file_deletion_frequency.yml b/detections/endpoint/high_file_deletion_frequency.yml index b94a60f156..0a10071263 100644 --- a/detections/endpoint/high_file_deletion_frequency.yml +++ b/detections/endpoint/high_file_deletion_frequency.yml @@ -23,9 +23,11 @@ known_false_positives: user may delete bunch of pictures or files in a folder. references: - https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - Clop Ransomware + - WhisperGate automated_detection_testing: passed confidence: 80 context: diff --git a/detections/endpoint/ping_sleep_batch_command.yml b/detections/endpoint/ping_sleep_batch_command.yml new file mode 100644 index 0000000000..395f97aa89 --- /dev/null +++ b/detections/endpoint/ping_sleep_batch_command.yml @@ -0,0 +1,81 @@ +name: Ping Sleep Batch Command +id: ce058d6c-79f2-11ec-b476-acde48001122 +version: 1 +date: '2022-01-20' +author: Teoderick Contreras, Splunk +type: Anomaly +datamodel: +- Endpoint +description: This analytic will identify the possible execution of ping sleep batch + commands. This technique was seen in several malware samples and is used to trigger + sleep times without explicitly calling sleep functions or commandlets. The goal + is to delay the execution of malicious code and bypass detection or sandbox analysis. + This detection can be a good indicator of a process delaying its execution for + malicious purposes. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_ping` (Processes.parent_process + = "*ping*" Processes.parent_process = *-n* Processes.parent_process="* Nul*"Processes.parent_process="*>*") + OR (Processes.process = "*ping*" Processes.process = *-n* Processes.process="* Nul*"Processes.process="*>*") + by Processes.parent_process_name Processes.parent_process Processes.process_name + Processes.original_file_name Processes.process Processes.process_id Processes.process_guid + Processes.user Processes.dest | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` + |`security_content_ctime(lastTime)` | `ping_sleep_batch_command_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: Administrator or network operator may execute this command. + Please update the filter macros to remove false positives. +references: +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +tags: + analytic_story: + - WhisperGate + automated_detection_testing: passed + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 60 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1497.003/ping_sleep/sysmon.log + impact: 60 + kill_chain_phases: + - Exploitation + message: suspicious $process$ commandline run in $dest$ + mitre_attack_id: + - T1497 + - T1497.003 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 36 + security_domain: endpoint diff --git a/detections/endpoint/powershell_execute_com_object.yml b/detections/endpoint/powershell_execute_com_object.yml index 32b4bce387..30626cd311 100644 --- a/detections/endpoint/powershell_execute_com_object.yml +++ b/detections/endpoint/powershell_execute_com_object.yml @@ -58,64 +58,3 @@ tags: - _time risk_score: 5 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_microsoft-cloudservices - - Splunk_TA_cisco-ucs - - Splunk_TA_citrix-netscaler - - Splunk_TA_nix - - Splunk_TA_nginx - - Splunk_TA_microsoft-iis - - Splunk_TA_microsoft-sqlserver - - Splunk_TA_rsa-securid - - Splunk_TA_remedy - - Splunk_TA_bluecoat-proxysg - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_jboss - - Splunk_TA_websense-cg - - Splunk_TA_ossec - - Splunk_TA_bromium - - Splunk_TA_nagios-core - - Splunk_TA_isc-bind - - Splunk_TA_bit9-carbonblack - - Splunk_TA_snow - - Splunk_TA_squid - - Splunk_TA_apache - - Splunk_TA_imperva-waf - - Splunk_TA_juniper - - Splunk_TA_cisco-esa - - Splunk_TA_microsoft_sysmon - - Splunk_TA_cisco-ise - - splunk_ta_o365 - - Splunk_TA_f5-bigip - - Splunk_TA_symantec-ep - - Splunk_TA_google-cloudplatform - - Splunk_TA_sophos - - Splunk_TA_mcafee_epo_syslog - - Splunk_TA_haproxy - - Splunk_TA_tomcat - - Splunk_TA_jmx - - Splunk_TA_cyberark - - Splunk_TA_symantec-dlp - - Splunk_TA_ibm-was - - Splunk_TA_microsoft-hyperv - - Splunk_TA_windows - - Splunk_TA_stream_wire_data - - Splunk_TA_mcafee-wg - - Splunk_TA_isc-dhcp - - Splunk_TA_websense-dlp - - Splunk_TA_box - - Splunk_TA_microsoft-scom - - Splunk_TA_CrowdStrike_FDR - - Splunk_TA_rsa-dlp - - Splunk_TA_cisco-wsa - - Splunk_TA_mysql - - Splunk_TA_cisco-asa - - Splunk_TA_infoblox - - Splunk_TA_salesforce - - Splunk_TA_cyberark_epm - - Splunk_TA_linux - - Splunk_TA_oracle - supported_tas: - - Splunk_TA_windows diff --git a/detections/endpoint/powershell_remove_windows_defender_directory.yml b/detections/endpoint/powershell_remove_windows_defender_directory.yml new file mode 100644 index 0000000000..d891abf325 --- /dev/null +++ b/detections/endpoint/powershell_remove_windows_defender_directory.yml @@ -0,0 +1,67 @@ +name: Powershell Remove Windows Defender Directory +id: adf47620-79fa-11ec-b248-acde48001122 +version: 1 +date: '2022-01-20' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic will identify a suspicious PowerShell command used to delete + the Windows Defender folder. This technique was seen used by the WhisperGate malware + campaign where it used Nirsofts advancedrun.exe to gain administrative privileges + to then execute a PowerShell command to delete the Windows Defender folder. This + is a good indicator the offending process is trying corrupt a Windows Defender installation. +search: '`powershell` EventCode=4104 Message = "* rmdir *" OR Message = "*\\Microsoft\\Windows + Defender*" | stats count min(_time) as firstTime max(_time) as lastTime by EventCode + Message ComputerName User | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `powershell_remove_windows_defender_directory_filter`' +how_to_implement: To successfully implement this analytic, you will need to enable + PowerShell Script Block Logging on some or all endpoints. Additional setup here + https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. +known_false_positives: unknown +references: +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +tags: + analytic_story: + - WhisperGate + automated_detection_testing: passed + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 90 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/rmdir_defender_pwsh/powershell.log + impact: 100 + kill_chain_phases: + - Exploitation + message: suspicious powershell script $Message$ was executed on the $ComputerName$ + mitre_attack_id: + - T1562.001 + - T1562 + nist: + - DE.CM + observable: + - name: ComputerName + type: Hostname + role: + - Victim + - name: User + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - Message + - ComputerName + - User + risk_score: 90 + security_domain: endpoint diff --git a/detections/endpoint/powershell_windows_defender_exclusion_commands.yml b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml index 77326342b3..73b3d2921e 100644 --- a/detections/endpoint/powershell_windows_defender_exclusion_commands.yml +++ b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml @@ -24,10 +24,12 @@ known_false_positives: admin or user may choose to use this windows features. references: - https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html - https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - Remcos - Windows Defense Evasion Tactics + - WhisperGate automated_detection_testing: passed confidence: 80 context: diff --git a/detections/endpoint/process_deleting_its_process_file_path.yml b/detections/endpoint/process_deleting_its_process_file_path.yml index 10f1aa4c83..92a9f3a6d7 100644 --- a/detections/endpoint/process_deleting_its_process_file_path.yml +++ b/detections/endpoint/process_deleting_its_process_file_path.yml @@ -11,11 +11,11 @@ description: This detection is to identify a suspicious process that tries to de evasion once a certain condition of malware is satisfied or not. Clop ransomware use this technique where it will try to delete its process file path using a .bat command if the keyboard layout is not the layout it tries to infect. -search: '`sysmon` EventCode=1 cmdline = "*/c del*" Image = "*\\cmd.exe" |eval result - = if(like(process,"%".parent_process."%"), "Found", "Not Found") | stats min(_time) - as firstTime max(_time) as lastTime count by Computer user ParentImage ParentCommandLine - Image cmdline EventCode ProcessID result | where result = "Found" | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | `process_deleting_its_process_file_path_filter`' +search: '`sysmon` EventCode=1 cmdline = "* /c *" cmdline = "* del*" Image = "*\\cmd.exe" + |eval result = if(like(process,"%".parent_process."%"), "Found", "Not Found") | + stats min(_time) as firstTime max(_time) as lastTime count by Computer user ParentImage + ParentCommandLine Image cmdline EventCode ProcessID result | where result = "Found" + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `process_deleting_its_process_file_path_filter`' how_to_implement: You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. @@ -25,10 +25,12 @@ known_false_positives: unknown references: - https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html - https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - Clop Ransomware - Remcos + - WhisperGate automated_detection_testing: passed confidence: 100 context: diff --git a/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml b/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml index 4fe9ee9bad..b16e060915 100644 --- a/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml +++ b/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml @@ -76,4 +76,5 @@ tags: - Processes.parent_process_name - Processes.parent_process risk_score: 42 + risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___attempt_to_delete_services.yml b/detections/endpoint/ssa___attempt_to_delete_services.yml index 6453a543b4..7418274594 100644 --- a/detections/endpoint/ssa___attempt_to_delete_services.yml +++ b/detections/endpoint/ssa___attempt_to_delete_services.yml @@ -87,5 +87,5 @@ tags: - process - cmd_line risk_score: 36 - risk_severity: high + risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___attempt_to_disable_services.yml b/detections/endpoint/ssa___attempt_to_disable_services.yml index 88ddd15bcb..3660e44937 100644 --- a/detections/endpoint/ssa___attempt_to_disable_services.yml +++ b/detections/endpoint/ssa___attempt_to_disable_services.yml @@ -86,5 +86,5 @@ tags: - dest_user_id - process risk_score: 36 - risk_severity: medium + risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml index 531fd0e392..05b0c6277c 100644 --- a/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml @@ -77,5 +77,5 @@ tags: - process - cmd_line risk_score: 63 - risk_severity: low + risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml b/detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml index d2c3c44e8f..2284481ef6 100644 --- a/detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml @@ -39,7 +39,7 @@ tags: - Source:Endpoint - Stage:Impact dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-security_bcdedit_wbadmin.log impact: 100 kill_chain_phases: - Actions on Objectives diff --git a/detections/endpoint/ssa___delete_a_net_user.yml b/detections/endpoint/ssa___delete_a_net_user.yml index daae967aa8..6420315de8 100644 --- a/detections/endpoint/ssa___delete_a_net_user.yml +++ b/detections/endpoint/ssa___delete_a_net_user.yml @@ -86,5 +86,5 @@ tags: - process - cmd_line risk_score: 49 - risk_severity: high + risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml b/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml index 6a3ade760d..4c295c9ac6 100644 --- a/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml +++ b/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml @@ -73,5 +73,5 @@ tags: - process - cmd_line risk_score: 35 - risk_severity: medium + risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml index 187ab0a6e6..805aa68620 100644 --- a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml +++ b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml @@ -68,5 +68,5 @@ tags: - dest_device_id - process risk_score: 70 - risk_severity: low + risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___detect_rclone_command_line_usage.yml b/detections/endpoint/ssa___detect_rclone_command_line_usage.yml index b071149c60..6e6f9dfd95 100644 --- a/detections/endpoint/ssa___detect_rclone_command_line_usage.yml +++ b/detections/endpoint/ssa___detect_rclone_command_line_usage.yml @@ -88,4 +88,5 @@ tags: - process - cmd_line risk_score: 35 + risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___disable_net_user_account.yml b/detections/endpoint/ssa___disable_net_user_account.yml index f83a0091bf..0c3c7f76f6 100644 --- a/detections/endpoint/ssa___disable_net_user_account.yml +++ b/detections/endpoint/ssa___disable_net_user_account.yml @@ -85,5 +85,5 @@ tags: - process - cmd_line risk_score: 49 - risk_severity: medium + risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml b/detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml index 28b9bfa6ff..08e143cb3b 100644 --- a/detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml +++ b/detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml @@ -47,7 +47,7 @@ tags: - Source:Endpoint - Stage:Exfiltration dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-security.log impact: 90 kill_chain_phases: - Exploitation @@ -85,4 +85,5 @@ tags: - process - cmd_line risk_score: 72 + risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___fsutil_zeroing_file.yml b/detections/endpoint/ssa___fsutil_zeroing_file.yml index 5b0d131f45..eac803137a 100644 --- a/detections/endpoint/ssa___fsutil_zeroing_file.yml +++ b/detections/endpoint/ssa___fsutil_zeroing_file.yml @@ -37,7 +37,8 @@ tags: context: - Source:Endpoint - stage:Defense Evasion - dataset: [] + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-security.log impact: 60 kill_chain_phases: - Exploitation @@ -78,5 +79,5 @@ tags: - process - cmd_line risk_score: 54 - risk_severity: high + risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml b/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml index cd874d9edd..a61baf888f 100644 --- a/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml +++ b/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml @@ -73,5 +73,5 @@ tags: - process - cmd_line risk_score: 35 - risk_severity: medium + risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml b/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml index 944c08e1bf..ddcc59506f 100644 --- a/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml +++ b/detections/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml @@ -76,5 +76,5 @@ tags: - process - cmd_line risk_score: 35 - risk_severity: medium + risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml b/detections/endpoint/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml similarity index 99% rename from detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml rename to detections/endpoint/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml index 2f0e28df62..9b57893592 100644 --- a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml +++ b/detections/endpoint/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml @@ -93,5 +93,5 @@ tags: - dest_device_id - authentication_method risk_score: 72 - risk_severity: high + risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml b/detections/endpoint/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml similarity index 99% rename from detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml rename to detections/endpoint/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml index 51f2eff5e9..13fc3309bb 100644 --- a/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml +++ b/detections/endpoint/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml @@ -94,5 +94,5 @@ tags: - origin_device_id - authentication_method risk_score: 64 - risk_severity: high + risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___resize_shadowstorage_volume.yml b/detections/endpoint/ssa___resize_shadowstorage_volume.yml index 1ee19a2616..a97db6024c 100644 --- a/detections/endpoint/ssa___resize_shadowstorage_volume.yml +++ b/detections/endpoint/ssa___resize_shadowstorage_volume.yml @@ -85,5 +85,5 @@ tags: - process - cmd_line risk_score: 64 - risk_severity: high + risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___sdelete_application_execution.yml b/detections/endpoint/ssa___sdelete_application_execution.yml index 66a706b8d0..f9538df11b 100644 --- a/detections/endpoint/ssa___sdelete_application_execution.yml +++ b/detections/endpoint/ssa___sdelete_application_execution.yml @@ -91,4 +91,5 @@ tags: - process_path - cmd_line risk_score: 42 + risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___system_process_running_unexpected_location.yml b/detections/endpoint/ssa___system_process_running_from_unexpected_location.yml similarity index 99% rename from detections/endpoint/ssa___system_process_running_unexpected_location.yml rename to detections/endpoint/ssa___system_process_running_from_unexpected_location.yml index 3c49c33a0d..d0a26b352e 100644 --- a/detections/endpoint/ssa___system_process_running_unexpected_location.yml +++ b/detections/endpoint/ssa___system_process_running_from_unexpected_location.yml @@ -272,5 +272,5 @@ tags: - dest_user_id - process_path risk_score: 56 - risk_severity: low + risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml b/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml index c27912632d..21acd9770e 100644 --- a/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml +++ b/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml @@ -1,4 +1,4 @@ -name: More than usual number of LOLBAS applications in short time period +name: Unusual LOLBAS in short period of time id: 59c0dd70-169c-4900-9a1f-bfcf13302f93 version: 2 date: '2020-08-25' @@ -58,8 +58,8 @@ tags: - CIS 8 confidence: 50 context: - - source:endpoint - - stage: Defense Evasion + - Source:Endpoint + - Stage:Defense Evasion impact: 50 kill_chain_phases: - Exploitation diff --git a/detections/endpoint/ssa___wbadmin_delete_system_backups.yml b/detections/endpoint/ssa___wbadmin_delete_system_backups.yml index 424b7dc49a..263ce5b13b 100644 --- a/detections/endpoint/ssa___wbadmin_delete_system_backups.yml +++ b/detections/endpoint/ssa___wbadmin_delete_system_backups.yml @@ -41,7 +41,8 @@ tags: context: - Source:Endpoint - stage:Defense Evasion - dataset: [] + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-security_bcdedit_wbadmin.log impact: 30 kill_chain_phases: - Exploitation @@ -82,5 +83,5 @@ tags: - process - cmd_line risk_score: 15 - risk_severity: high + risk_severity: low security_domain: endpoint diff --git a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml index f16d61ebc4..9b5a7c19ff 100644 --- a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml +++ b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml @@ -74,5 +74,5 @@ tags: - dest_user_id - process risk_score: 63 - risk_severity: high + risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml b/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml index 64d3c29009..da3a6dc607 100644 --- a/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml @@ -96,4 +96,5 @@ tags: - process - cmd_line risk_score: 80 + risk_severity: high security_domain: endpoint diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index e7a20ed9d5..b87fadbac2 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -8,7 +8,7 @@ datamodel: - Endpoint description: The following analytic will detect a suspicious process running in a file path where a process is not commonly seen and is most commonly used by malicious - softtware. This behavior has been used by adversaries where they drop and run an + software. This behavior has been used by adversaries where they drop and run an exe in a path that is accessible without admin privileges. search: '| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) @@ -18,10 +18,10 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces = "*\\Users\\Administrator\\Music\\*" OR Processes.process_path.file_path = "*\\Windows\\servicing\\*" OR Processes.process_path.file_path = "*\\Users\\Default\\*" OR Processes.process_path.file_path = "*Recycle.bin*" OR Processes.process_path = "*\\Windows\\Media\\*" OR Processes.process_path - = "\\Windows\\repair\\*" OR Processes.process_path = "*\\temp\\*" by Processes.parent_process_name - Processes.parent_process Processes.process_path Processes.dest Processes.user | - `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `suspicious_process_file_path_filter`' + = "\\Windows\\repair\\*" OR Processes.process_path = "*\\temp\\*" OR Processes.process_path + = "*\\PerfLogs\\*" by Processes.parent_process_name Processes.parent_process Processes.process_path + Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `suspicious_process_file_path_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. @@ -29,10 +29,12 @@ known_false_positives: Administrators may allow execution of specific binaries i non-standard paths. Filter as needed. references: - https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - XMRig - Remcos + - WhisperGate automated_detection_testing: passed confidence: 50 context: diff --git a/detections/endpoint/suspicious_process_with_discord_dns_query.yml b/detections/endpoint/suspicious_process_with_discord_dns_query.yml new file mode 100644 index 0000000000..25b462deef --- /dev/null +++ b/detections/endpoint/suspicious_process_with_discord_dns_query.yml @@ -0,0 +1,73 @@ +name: Suspicious Process With Discord DNS Query +id: 4d4332ae-792c-11ec-89c1-acde48001122 +version: 1 +date: '2022-01-19' +author: Teoderick Contreras, Splunk +type: Anomaly +datamodel: +- Endpoint +description: This analytic identifies a process making a DNS query to Discord, a well + known instant messaging and digital distribution platform. Discord can be abused + by adversaries, as seen in the WhisperGate campaign, to host and download malicious. + external files. A process resolving a Discord DNS name could be an indicator of + malware trying to download files from Discord for further execution. +search: '`sysmon` EventCode=22 QueryName IN ("*discord*") process_path != "*\\AppData\\Local\\Discord\\*" + AND process_path != "*\\Program Files*" AND process_name != "discord.exe" | stats + count min(_time) as firstTime max(_time) as lastTime by Image QueryName QueryStatus + process_name QueryResults Computer process_path | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `suspicious_process_with_discord_dns_query_filter`' +how_to_implement: his detection relies on sysmon logs with the Event ID 22, DNS Query. +known_false_positives: Noise and false positive can be seen if the following instant + messaging is allowed to use within corporate network. In this case, a filter is + needed. +references: +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3 +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +tags: + analytic_story: + - WhisperGate + automated_detection_testing: passed + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 80 + context: + - Source:Endpoint + - Stage:Execution + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/discord_dnsquery/sysmon.log + impact: 80 + kill_chain_phases: + - Exploitation + message: suspicious process $process_name$ has a dns query in $QueryName$ on $Computer$ + mitre_attack_id: + - T1059.005 + - T1059 + nist: + - DE.CM + observable: + - name: Computer + type: Hostname + role: + - Victim + - name: process_name + type: process name + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Image + - QueryName + - QueryStatus + - process_name + - QueryResults + - Computer + - process_path + risk_score: 64 + security_domain: endpoint diff --git a/detections/endpoint/windows_defender_exclusion_registry_entry.yml b/detections/endpoint/windows_defender_exclusion_registry_entry.yml index c767cc7558..6e8dfa528a 100644 --- a/detections/endpoint/windows_defender_exclusion_registry_entry.yml +++ b/detections/endpoint/windows_defender_exclusion_registry_entry.yml @@ -14,9 +14,17 @@ description: This analytic will detect a suspicious process that modify a regist defense evasion and to look further for events after this behavior. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\SOFTWARE\\Policies\\Microsoft\\Windows - Defender\\Exclusions\\*" by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name - Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` - | `security_content_ctime(firstTime)` | `windows_defender_exclusion_registry_entry_filter`' + Defender\\Exclusions\\*" by _time span=1h Registry.dest Registry.user Registry.registry_path + Registry.registry_value_name Registry.registry_value_data Registry.process_guid + | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name + parent_process process_name process_path process proc_guid registry_path registry_value_name + registry_value_data | `windows_defender_exclusion_registry_entry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure @@ -25,6 +33,7 @@ known_false_positives: admin or user may choose to use this windows features. references: - https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html - https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - Remcos diff --git a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml index a81bbfaa16..71b9b9c4e9 100644 --- a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml +++ b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml @@ -6,13 +6,12 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: This analytic is to detect a suspicious spawned process by wscript or - cscript process. This technique was a common technique used by adversaries and malware - to execute different LOLBIN, other script like powershell or create a suspended - process to inject its code as a defense evasion. This TTP may detect some normal - script that using several application tool that are in the list of the child process - it detects but a good pivot and indicator that a script is may execute suspicious - code. +description: This analytic identifies a suspicious spawned process by WScript or CScript + process. This technique was a common technique used by adversaries and malware to + execute different LOLBIN, other scripts like PowerShell or spawn a suspended process + to inject its code as a defense evasion. This TTP may detect some normal script + that using several application tool that are in the list of the child process it + detects but a good pivot and indicator that a script is may execute suspicious code. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("cscript.exe", "wscript.exe") Processes.process_name IN ("regsvr32.exe", "rundll32.exe","winhlp32.exe","certutil.exe","msbuild.exe","cmd.exe","powershell*","wmic.exe","mshta.exe") @@ -24,15 +23,17 @@ how_to_implement: To successfully implement this search, you need to be ingestin logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -known_false_positives: user may create vbs or js script that use several tool as part - of its execution. +known_false_positives: Administrators may create vbs or js script that use several + tool as part of its execution. Filter as needed. references: - https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120 +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - FIN7 - Remcos - Unusual Processes + - WhisperGate automated_detection_testing: passed confidence: 70 context: diff --git a/detections/endpoint/ssa___excessive_number_of_office_files_copied.yml b/detections/experimental/endpoint/ssa___excessive_number_of_office_files_copied.yml similarity index 98% rename from detections/endpoint/ssa___excessive_number_of_office_files_copied.yml rename to detections/experimental/endpoint/ssa___excessive_number_of_office_files_copied.yml index 52edec9e37..c997c19f28 100644 --- a/detections/endpoint/ssa___excessive_number_of_office_files_copied.yml +++ b/detections/experimental/endpoint/ssa___excessive_number_of_office_files_copied.yml @@ -46,4 +46,5 @@ tags: - file_name - file_path risk_score: 72 + risk_severity: medium security_domain: endpoint diff --git a/detections/endpoint/ssa___high_file_deletion_frequency.yml b/detections/experimental/endpoint/ssa___high_file_deletion_frequency.yml similarity index 99% rename from detections/endpoint/ssa___high_file_deletion_frequency.yml rename to detections/experimental/endpoint/ssa___high_file_deletion_frequency.yml index b377297dc0..44820b1827 100644 --- a/detections/endpoint/ssa___high_file_deletion_frequency.yml +++ b/detections/experimental/endpoint/ssa___high_file_deletion_frequency.yml @@ -67,4 +67,5 @@ tags: - file_name - file_path risk_score: 72 + risk_severity: medium security_domain: endpoint diff --git a/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml b/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml index 7badfa0288..9428f6bd7f 100644 --- a/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml +++ b/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml @@ -22,7 +22,8 @@ search: ' `wineventlog_security` EventCode=4624 Logon_Type=3 Account_Name!="*$" AS unique_targets values(ComputerName) as target_hosts by _time, Source_Network_Address, Source_Account | eventstats avg(unique_targets) as comp_avg , stdev(unique_targets) as comp_std by Source_Network_Address, Source_Account | eval upperBound=(comp_avg+comp_std*3) - | eval isOutlier=if(unique_targets >10 and unique_targets >= upperBound, 1, 0) | `unusual_number_of_remote_endpoint_authentication_events_filter`' + | eval isOutlier=if(unique_targets >10 and unique_targets >= upperBound, 1, 0) | + `unusual_number_of_remote_endpoint_authentication_events_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers aas well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs diff --git a/security_content_automation/detection_ta_mapping.yml b/security_content_automation/detection_ta_mapping.yml index 9d2eaae45e..33ee099a45 100644 --- a/security_content_automation/detection_ta_mapping.yml +++ b/security_content_automation/detection_ta_mapping.yml @@ -599,68 +599,6 @@ permission_modification_using_takeown_app: cim_version: 5.0.0 tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -powershell_execute_com_object: - cim_version: 5.0.0 - supported_tas: - - Splunk_TA_windows - tas_with_cim_mapping: - - Splunk_TA_microsoft-cloudservices - - Splunk_TA_cisco-ucs - - Splunk_TA_citrix-netscaler - - Splunk_TA_nix - - Splunk_TA_nginx - - Splunk_TA_microsoft-iis - - Splunk_TA_microsoft-sqlserver - - Splunk_TA_rsa-securid - - Splunk_TA_remedy - - Splunk_TA_bluecoat-proxysg - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_jboss - - Splunk_TA_websense-cg - - Splunk_TA_ossec - - Splunk_TA_bromium - - Splunk_TA_nagios-core - - Splunk_TA_isc-bind - - Splunk_TA_bit9-carbonblack - - Splunk_TA_snow - - Splunk_TA_squid - - Splunk_TA_apache - - Splunk_TA_imperva-waf - - Splunk_TA_juniper - - Splunk_TA_cisco-esa - - Splunk_TA_microsoft_sysmon - - Splunk_TA_cisco-ise - - splunk_ta_o365 - - Splunk_TA_f5-bigip - - Splunk_TA_symantec-ep - - Splunk_TA_google-cloudplatform - - Splunk_TA_sophos - - Splunk_TA_mcafee_epo_syslog - - Splunk_TA_haproxy - - Splunk_TA_tomcat - - Splunk_TA_jmx - - Splunk_TA_cyberark - - Splunk_TA_symantec-dlp - - Splunk_TA_ibm-was - - Splunk_TA_microsoft-hyperv - - Splunk_TA_windows - - Splunk_TA_stream_wire_data - - Splunk_TA_mcafee-wg - - Splunk_TA_isc-dhcp - - Splunk_TA_websense-dlp - - Splunk_TA_box - - Splunk_TA_microsoft-scom - - Splunk_TA_CrowdStrike_FDR - - Splunk_TA_rsa-dlp - - Splunk_TA_cisco-wsa - - Splunk_TA_mysql - - Splunk_TA_cisco-asa - - Splunk_TA_infoblox - - Splunk_TA_salesforce - - Splunk_TA_cyberark_epm - - Splunk_TA_linux - - Splunk_TA_oracle prevent_automatic_repair_mode_using_bcdedit: cim_version: 5.0.0 tas_with_cim_mapping: diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index 7adafed1d8..9bb21fa6e8 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -65,9 +65,6 @@ def map_required_fields(cim_summary, datamodel, required_fields): cim_fields = e_type.get("fields", []) if set(datasets_fields[dataset]).issubset(set(cim_fields)): add_addon = True - else: - add_addon = False - return add_addon return add_addon From 4e720c0415350bdf6747db1b21901af4d9cdf1f9 Mon Sep 17 00:00:00 2001 From: truptilangalia-crest <79827058+truptilangalia-crest@users.noreply.github.com> Date: Thu, 27 Jan 2022 11:52:54 +0530 Subject: [PATCH 15/25] Delete detect_autosuid_post_exploitation_tool.yml --- ...detect_autosuid_post_exploitation_tool.yml | 55 ------------------- 1 file changed, 55 deletions(-) delete mode 100644 detections/endpoint/detect_autosuid_post_exploitation_tool.yml diff --git a/detections/endpoint/detect_autosuid_post_exploitation_tool.yml b/detections/endpoint/detect_autosuid_post_exploitation_tool.yml deleted file mode 100644 index 32a52632b2..0000000000 --- a/detections/endpoint/detect_autosuid_post_exploitation_tool.yml +++ /dev/null @@ -1,55 +0,0 @@ -name: Detect AutoSUID post exploitation tool -id: 0edd5862-56c9-11ec-b990-acde48001122 -version: 1 -date: '2021-12-06' -author: Rod Soto -type: TTP -datamodel: -- Endpoint -description: This search, detects Linux post exploitation tool AutoSUID, which is - an a tool that searches for SUID executables files in order to escalate privileges. -search: ' `sysmon_linux` CommandLine="find / -xdev -user root ( -perm -4000 -o -perm - -2000 -o -perm -6000 )" | stats count by Computer process process_current_directory - process_path | `detect_autosuid_post_exploitation_tool_filter`' -how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux. - Need to install this add-on to parse fields correctly and execute detection search. -known_false_positives: Unless an administrator is using these commands to troubleshoot - or audit a system, the execution of these commands should be monitored. -references: -- https://attack.mitre.org/matrices/enterprise/linux/ -- https://github.com/IvanGlinkin/AutoSUID -tags: - analytic_story: - - Linux Post-Exploitation - automated_detection_testing: passed - confidence: 90 - context: - - Source: Endpoint - - Stage: Discovery - dataset: - - https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/autoSUID.txt - impact: 90 - kill_chain_phases: - - Exploitation - - Privilege Escalation - message: AutoSUID post exploitation tool detected - mitre_attack_id: - - T1069 - - T1222 - observable: - - name: Computer - type: Endpoint - role: - - Victim - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Computer - - process - - process_path - - process_current_directory - risk_score: 81 - security_domain: endpoint From aea9333e4457a211d93c77d8caceac484c868b71 Mon Sep 17 00:00:00 2001 From: truptilangalia-crest <79827058+truptilangalia-crest@users.noreply.github.com> Date: Thu, 27 Jan 2022 11:53:33 +0530 Subject: [PATCH 16/25] Delete detect_linenum_execution.yml --- .../endpoint/detect_linenum_execution.yml | 63 ------------------- 1 file changed, 63 deletions(-) delete mode 100644 detections/endpoint/detect_linenum_execution.yml diff --git a/detections/endpoint/detect_linenum_execution.yml b/detections/endpoint/detect_linenum_execution.yml deleted file mode 100644 index cea9fb1517..0000000000 --- a/detections/endpoint/detect_linenum_execution.yml +++ /dev/null @@ -1,63 +0,0 @@ -name: Detect LinEnum execution -id: 570e5278-5479-11ec-89c8-acde48001122 -version: 1 -date: '2021-12-03' -author: Rod Soto -type: TTP -datamodel: -- Endpoint -description: LinEnum is a bash script that performs discovery commands for accounts, - processes, kernel version, applications, services, and uses the information from - these commands to present operator with ways of escalating privileges or further - exploitation of targeted host. -search: ' `sysmon_linux` CommandLine="grep -w aria2c\\|arp\\|ash\\|awk\\|base64\\|bash\\|busybox\\|cat\\|chmod\\|chown\\|cp\\|csh\\|curl\\|cut\\|dash\\|date\\|dd\\|diff\\|dmsetup\\|docker\\|ed\\|emacs\\|env\\|expand\\|expect\\|file\\|find\\|flock\\|fmt\\|fold\\|ftp\\|gawk\\|gdb\\|gimp\\|git\\|grep\\|head\\|ht\\|iftop\\|ionice\\|ip$\\|irb\\|jjs\\|jq\\|jrunscript\\|ksh\\|ld.so\\|ldconfig\\|less\\|logsave\\|lua\\|make\\|man\\|mawk\\|more\\|mv\\|mysql\\|nano\\|nawk\\|nc\\|netcat\\|nice\\|nl\\|nmap\\|node\\|od\\|openssl\\|perl\\|pg\\|php\\|pic\\|pico\\|python\\|readelf\\|rlwrap\\|rpm\\|rpmquery\\|rsync\\|ruby\\|run-parts\\|rvim\\|scp\\|script\\|sed\\|setarch\\|sftp\\|sh\\|shuf\\|socat\\|sort\\|sqlite3\\|ssh$\\|start-stop-daemon\\|stdbuf\\|strace\\|systemctl\\|tail\\|tar\\|taskset\\|tclsh\\|tee\\|telnet\\|tftp\\|time\\|timeout\\|ul\\|unexpand\\|uniq\\|unshare\\|vi\\|vim\\|watch\\|wget\\|wish\\|xargs\\|xxd\\|zip\\|zsh" - | stats count by Computer CommandLine user process_exec process_current_directory - | `detect_linenum_execution_filter` ' -how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux. - Need to install this add-on to parse fields correctly and execute detection search. -known_false_positives: Very rare to perform such an extensive grep on a system, however - certain monitoring tools can produce similar results. It is important if monitoring - tools are in place to verify what is the actual process directory of execution. -references: -- https://github.com/rebootuser/LinEnum -- https://book.hacktricks.xyz/linux-unix/linux-privilege-escalation-checklist -tags: - analytic_story: - - Linux Post-Exploitation - automated_detection_testing: passed - confidence: 90 - context: - - Source: endpoint - - Stage: discovery - dataset: - - https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/LinuxEnumd.txt - impact: 50 - kill_chain_phases: - - Privilege Escalation - message: LinEnum post exploitation tool detected - mitre_attack_id: - - T1087 - - T1069 - - T1083 - - T1057 - - T1518 - - T1082 - - T1016 - - T1033 - observable: - - name: Computer - type: Endpoint - role: - - Victim - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - CommandLine - - user - - process_exec - - process_current_directory - risk_score: 45 - security_domain: endpoint From 93a1d467586103e5d6f5f7bcb0fcfbcf2aa9ea33 Mon Sep 17 00:00:00 2001 From: truptilangalia-crest <79827058+truptilangalia-crest@users.noreply.github.com> Date: Thu, 27 Jan 2022 11:53:59 +0530 Subject: [PATCH 17/25] Delete detect_linpeas_execution.yml --- .../endpoint/detect_linpeas_execution.yml | 63 ------------------- 1 file changed, 63 deletions(-) delete mode 100644 detections/endpoint/detect_linpeas_execution.yml diff --git a/detections/endpoint/detect_linpeas_execution.yml b/detections/endpoint/detect_linpeas_execution.yml deleted file mode 100644 index 527ab77df7..0000000000 --- a/detections/endpoint/detect_linpeas_execution.yml +++ /dev/null @@ -1,63 +0,0 @@ -name: Detect LinPeas Execution -id: 4ea6fa10-547c-11ec-a4f9-acde48001122 -version: 1 -date: '2021-12-03' -author: Rod Soto -type: TTP -datamodel: -- Endpoint -description: Linux local Privilege Escalation Awesome Script (linPEAS) is a script - that searches for possible paths to escalate privileges. -search: ' `sysmon_linux` CommandLine!=null parent_process_exec=sudo OR parent_process_exec=bash - OR CommandLine="cve-list" | stats count by Computer CommandLine user parent_process_exec - process_path | `detect_linpeas_execution_filter`' -how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux. - Need to install this add-on to parse fields correctly and execute detection search. -known_false_positives: This search may produce false positives as it will display - many sudo executed processess however, the cve-list within the command line it is - a clear indicator, operator is searching for local vulnerabilites. -references: -- https://book.hacktricks.xyz/linux-unix/linux-privilege-escalation-checklist -- https://github.com/carlospolop/PEASS-ng/tree/master/linPEAS -- https://attack.mitre.org/matrices/enterprise/linux/ -tags: - analytic_story: - - Linux Post-Exploitation - confidence: 100 - context: - - Source: endpoint - - Stage: discovery - dataset: - - https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/linpeasdataset.txt - impact: 90 - kill_chain_phases: - - Exploitation - - Privilege Escalation - message: LinPEAS post exploitation tool detected - mitre_attack_id: - - T1082 - - T1083 - - T1033 - - T1087 - - T1046 - - T1057 - - T1518 - - T1033 - observable: - - name: Computer - type: Endpoint - role: - - Victim - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Computer - - CommandLine - - user - - parent_process_exec - - process_path - risk_score: 90 - security_domain: endpoint From 81809b4dcc1b7b5c02facb89bece686414728a66 Mon Sep 17 00:00:00 2001 From: truptilangalia-crest <79827058+truptilangalia-crest@users.noreply.github.com> Date: Thu, 27 Jan 2022 11:54:16 +0530 Subject: [PATCH 18/25] Delete detect_linux_exploit_suggester_execution.yml --- ...tect_linux_exploit_suggester_execution.yml | 57 ------------------- 1 file changed, 57 deletions(-) delete mode 100644 detections/endpoint/detect_linux_exploit_suggester_execution.yml diff --git a/detections/endpoint/detect_linux_exploit_suggester_execution.yml b/detections/endpoint/detect_linux_exploit_suggester_execution.yml deleted file mode 100644 index 44c9b56699..0000000000 --- a/detections/endpoint/detect_linux_exploit_suggester_execution.yml +++ /dev/null @@ -1,57 +0,0 @@ -name: Detect Linux Exploit Suggester Execution -id: a4f34d5c-547b-11ec-ba88-acde48001122 -version: 1 -date: '2021-12-03' -author: Rod Soto -type: TTP -datamodel: -- Endpoint -description: This search detects Linux Exploit Suggester tool execution. This is a - tool that searches for vulnerabilities based on Kernel and Distribution versions - then queries public exploit databases. -search: ' `sysmon_linux` CommandLine="cvelist-file:" OR CommandLine="uname -a" OR - CommandLine="*exploit*" OR CommandLine="*exploit-db*" | stats count by CommandLine,user,Computer,action,signature, - process_name | `detect_linux_exploit_suggester_execution_filter`' -how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux. - Need to install this add-on to parse fields correctly and execute detection search. -known_false_positives: Monitoring tools may produce similar commands although the - presence of "exploit-db" is very unusual. -references: -- https://book.hacktricks.xyz/linux-unix/linux-privilege-escalation-checklist -- https://attack.mitre.org/matrices/enterprise/linux/ -tags: - analytic_story: - - Linux Post-Exploitation - automated_detection_testing: passed - confidence: 100 - context: - - Source: endpoint - - Stage: discovery - dataset: - - https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/linuxexploitsuggesterdatasets.txt - impact: 90 - kill_chain_phases: - - Exploitation - - Privilege Escalation - message: Linux Exploit Suggester post exploitation tool detected. - mitre_attack_id: - - T1087 - - T1083 - - T1069 - - T1057 - - T1518 - - T1082 - observable: - - name: Computer - type: Endpoint - role: - - Victim - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - CommandLine - risk_score: 90 - security_domain: endpoint From 7cc2713064f3aa6d0ebaefa72344ab4f1c3118b7 Mon Sep 17 00:00:00 2001 From: truptilangalia-crest <79827058+truptilangalia-crest@users.noreply.github.com> Date: Thu, 27 Jan 2022 11:54:33 +0530 Subject: [PATCH 19/25] Delete detect_mimipenguin.yml --- detections/endpoint/detect_mimipenguin.yml | 54 ---------------------- 1 file changed, 54 deletions(-) delete mode 100644 detections/endpoint/detect_mimipenguin.yml diff --git a/detections/endpoint/detect_mimipenguin.yml b/detections/endpoint/detect_mimipenguin.yml deleted file mode 100644 index 50dcd97758..0000000000 --- a/detections/endpoint/detect_mimipenguin.yml +++ /dev/null @@ -1,54 +0,0 @@ -name: Detect MimiPenguin -id: 1ad20afa-547b-11ec-b4e7-acde48001122 -version: 1 -date: '2021-12-03' -author: Rod Soto -type: TTP -datamodel: -- Endpoint -description: MimiPenguin is a tool that dumps login passwords from current linux destop - users. This search detects execution of this tool. -search: ' `sysmon_linux` CommandLine="strings -e /etc/apache2/apache2.conf" OR CommandLine="strings - -e /etc/ssh/sshd_config" OR CommandLine="strings -e /etc/shadow" | stats count - by Computer parent_process process_current_directory user CommandLine | `detect_mimipenguin_filter`' -how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux. - Need to install this add-on to parse fields correctly and execute detection search. -known_false_positives: Some of these commands may be executed by sysadmin however - not in the proximity and frequency, specially if querying for tools are that knonwn - not to be installed at target system. -references: -- https://github.com/huntergregal/mimipenguin -- https://attack.mitre.org/matrices/enterprise/linux/ -tags: - analytic_story: - - Linux Post-Exploitation - automated_detection_testing: passed - confidence: 70 - context: - - Source: endpoint - - Stage: discovery - dataset: - - https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/mimipenguin.txt - impact: 50 - kill_chain_phases: - - Privilege Escalation - message: MimiPenguin post exploitation tool detected - mitre_attack_id: - - T1552 - observable: - - name: Computer - type: Endpoint - role: - - Victim - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - user - - Computer - - parent_process - - process_current_directory - risk_score: 35 - security_domain: endpoint From aa423acfc75a5d3f9e0d1828cc9b8021787c52a2 Mon Sep 17 00:00:00 2001 From: mjobanputra Date: Mon, 31 Jan 2022 17:06:44 +0530 Subject: [PATCH 20/25] Add changes realted generating detection_ta_mapping CSV report --- .../enrich_detections.py | 22 +++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index 9bb21fa6e8..b3114456bf 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -7,6 +7,7 @@ import re import shutil import sys import time +import csv import git import yaml @@ -214,6 +215,27 @@ def main(): security_content_repo_obj.index.add( [filepath.strip("security_content/")] ) + # Generating detection_ta_mapping CSV report + try: + with open(r"./security_content/security_content_automation/detection_ta_mapping.csv", 'w+', newline='') as csv_file: + fieldnames = ['detection_name', 'cim_version', 'supported_tas', 'tas_with_cim_mapping'] + writer = csv.DictWriter(csv_file, fieldnames=fieldnames) + writer.writeheader() + for detection_name, detection_content in detection_ta_mapping.items(): + detection_content.update({ + 'tas_with_cim_mapping': ', '.join(detection_content["tas_with_cim_mapping"]) if detection_content.get( + 'tas_with_cim_mapping') else '', + 'supported_tas': ', '.join(detection_content["supported_tas"]) if detection_content.get( + 'supported_tas') else '', + 'detection_name': detection_name + }) + writer.writerow(detection_content) + except Exception as error: + error_message = f"Unexpected error occurred while generating detection_ta_mapping CSV report, {error}" + logging.error(error_message) + security_content_repo_obj.index.add( + ["security_content_automation/detection_ta_mapping.csv"] + ) with io.open( r"./security_content/security_content_automation/detection_ta_mapping.yml", From 08f0ff6405c8ef8aa53724651260bfa2b09da54e Mon Sep 17 00:00:00 2001 From: truptilangalia-crest Date: Mon, 31 Jan 2022 19:46:09 +0530 Subject: [PATCH 21/25] test: Removed tas with mapping from detection files --- ...mber_of_cloud_infrastructure_api_calls.yml | 14 - ...mber_of_cloud_security_group_api_calls.yml | 14 - ...alls_from_previously_unseen_user_roles.yml | 7 - ...ance_created_by_previously_unseen_user.yml | 2 - ...ce_created_in_previously_unused_region.yml | 2 - ...e_created_with_previously_unseen_image.yml | 2 - ...d_with_previously_unseen_instance_type.yml | 2 - ...e_modified_with_previously_unseen_user.yml | 12 - ...ovisioning_from_previously_unseen_city.yml | 12 - ...sioning_from_previously_unseen_country.yml | 12 - ...ning_from_previously_unseen_ip_address.yml | 10 - ...isioning_from_previously_unseen_region.yml | 12 - .../account_discovery_with_net_app.yml | 3 + .../active_setup_registry_autostart.yml | 4 +- ...d_defaultuser_and_password_in_registry.yml | 4 +- .../add_or_set_windows_defender_exclusion.yml | 3 + ..._file_and_printing_sharing_in_firewall.yml | 3 + ...ound_traffic_by_firewall_rule_registry.yml | 4 +- .../allow_network_discovery_in_firewall.yml | 3 + .../allow_operation_with_consent_admin.yml | 4 +- .../endpoint/anomalous_usage_of_7zip.yml | 4 +- .../endpoint/any_powershell_downloadfile.yml | 3 + .../any_powershell_downloadstring.yml | 3 + .../endpoint/attacker_tools_on_endpoint.yml | 5 +- ..._to_add_certificate_to_untrusted_store.yml | 4 +- .../attempt_to_stop_security_service.yml | 3 + ...dential_dump_from_registry_via_reg_exe.yml | 3 + .../auto_admin_logon_registry_entry.yml | 4 +- .../endpoint/batch_file_write_to_system32.yml | 7 +- ...dedit_command_back_to_normal_mode_boot.yml | 4 +- .../bcdedit_failure_recovery_modification.yml | 5 +- detections/endpoint/bits_job_persistence.yml | 3 + .../endpoint/bitsadmin_download_file.yml | 3 + ...load_with_urlcache_and_split_arguments.yml | 3 + ...oad_with_verifyctl_and_split_arguments.yml | 3 + .../certutil_exe_certificate_extraction.yml | 3 + .../certutil_with_decode_argument.yml | 3 + .../change_default_file_association.yml | 4 +- ...hange_to_safe_mode_with_network_config.yml | 4 +- .../check_elevated_cmd_using_whoami.yml | 4 +- ...ar_unallocated_sector_using_cipher_app.yml | 3 + .../endpoint/clop_common_exec_parameter.yml | 3 + .../endpoint/cmd_echo_pipe___escalation.yml | 3 + ...cmdline_tool_not_executed_in_cmd_shell.yml | 3 + .../endpoint/conti_common_exec_parameter.yml | 3 + ..._loading_from_world_writable_directory.yml | 3 + ...ate_local_admin_accounts_using_net_exe.yml | 3 + ...or_delete_windows_shares_using_net_exe.yml | 3 + .../endpoint/creation_of_shadow_copy.yml | 3 + ...f_shadow_copy_with_wmic_and_powershell.yml | 3 + ...ping_via_copy_command_from_shadow_copy.yml | 3 + ...ial_dumping_via_symlink_to_shadow_copy.yml | 3 + .../curl_download_and_bash_execution.yml | 3 - detections/endpoint/deleting_of_net_users.yml | 3 + .../endpoint/deleting_shadow_copies.yml | 3 + ...tect_azurehound_command_line_arguments.yml | 3 + .../endpoint/detect_exchange_web_shell.yml | 5 +- .../detect_html_help_spawn_child_process.yml | 3 + .../detect_html_help_url_in_command_line.yml | 3 + ...l_help_using_infotech_storage_handlers.yml | 3 + .../detect_mshta_inline_hta_execution.yml | 3 + .../detect_mshta_url_in_command_line.yml | 3 + ...nterception_by_creation_of_program_exe.yml | 3 + ...system_network_configuration_discovery.yml | 3 + .../detect_psexec_with_accepteula_flag.yml | 3 + .../detect_rclone_command_line_usage.yml | 3 + .../detect_regasm_spawning_a_process.yml | 4 +- ..._regasm_with_no_command_line_arguments.yml | 3 + .../detect_regsvcs_spawning_a_process.yml | 4 +- ...regsvcs_with_no_command_line_arguments.yml | 3 + ...ct_regsvr32_application_control_bypass.yml | 3 + ...2_application_control_bypass___advpack.yml | 3 + ..._application_control_bypass___setupapi.yml | 3 + ..._application_control_bypass___syssetup.yml | 3 + .../detect_rundll32_inline_hta_execution.yml | 3 + ...tect_sharphound_command_line_arguments.yml | 4 +- .../endpoint/detect_sharphound_usage.yml | 3 + ..._cmd_exe_to_launch_script_interpreters.yml | 4 +- .../disable_amsi_through_registry.yml | 4 +- .../disable_defender_antivirus_registry.yml | 13 +- ...able_defender_blockatfirstseen_feature.yml | 3 + ...disable_defender_enhanced_notification.yml | 3 + .../disable_defender_mpengine_registry.yml | 3 + .../disable_defender_spynet_reporting.yml | 3 + ...efender_submit_samples_consent_feature.yml | 3 + .../endpoint/disable_etw_through_registry.yml | 4 +- .../endpoint/disable_logs_using_wevtutil.yml | 4 +- detections/endpoint/disable_registry_tool.yml | 4 +- detections/endpoint/disable_schedule_task.yml | 5 +- ...le_security_logs_using_minint_registry.yml | 3 + .../disable_uac_remote_restriction.yml | 3 + .../endpoint/disable_windows_app_hotkeys.yml | 4 +- .../disable_windows_behavior_monitoring.yml | 4 +- .../endpoint/disabling_cmd_application.yml | 4 +- .../endpoint/disabling_controlpanel.yml | 4 +- .../endpoint/disabling_defender_services.yml | 3 + .../disabling_firewall_with_netsh.yml | 3 + ...isabling_folderoptions_windows_feature.yml | 3 - .../endpoint/disabling_net_user_account.yml | 3 + .../endpoint/disabling_norun_windows_app.yml | 4 +- .../disabling_systemrestore_in_registry.yml | 4 +- .../endpoint/disabling_task_manager.yml | 4 +- .../dns_exfiltration_using_nslookup_app.yml | 3 + .../domain_account_discovery_with_net_app.yml | 4 +- .../domain_account_discovery_with_wmic.yml | 4 +- ...omain_controller_discovery_with_nltest.yml | 3 + .../endpoint/dsquery_domain_discovery.yml | 5 +- .../endpoint/dump_lsass_via_comsvcs_dll.yml | 3 + .../endpoint/dump_lsass_via_procdump.yml | 5 +- .../elevated_group_discovery_with_net.yml | 3 + .../elevated_group_discovery_with_wmic.yml | 3 + .../enable_rdp_in_other_port_number.yml | 4 +- ...le_wdigest_uselogoncredential_registry.yml | 3 + detections/endpoint/etw_registry_disabled.yml | 3 + detections/endpoint/eventvwr_uac_bypass.yml | 4 +- .../endpoint/excel_spawning_powershell.yml | 3 + .../excessive_attempt_to_disable_services.yml | 5 +- ...ocesses_created_in_windows_temp_folder.yml | 6 - ...r_of_service_control_start_as_disabled.yml | 4 +- ...excessive_number_of_taskhost_processes.yml | 5 - .../excessive_service_stop_attempt.yml | 3 + .../endpoint/excessive_usage_of_cacls_app.yml | 5 +- .../endpoint/excessive_usage_of_net_app.yml | 3 + .../endpoint/excessive_usage_of_taskkill.yml | 5 +- ..._or_script_creation_in_suspicious_path.yml | 5 +- ...cute_javascript_with_jscript_com_clsid.yml | 4 +- ...ution_of_file_with_multiple_extensions.yml | 5 +- .../endpoint/extraction_of_registry_hives.yml | 3 + .../endpoint/file_with_samsam_extension.yml | 10 +- .../firewall_allowed_program_enable.yml | 4 +- detections/endpoint/fodhelper_uac_bypass.yml | 4 +- detections/endpoint/fsutil_zeroing_file.yml | 4 +- ...esultantpasswordpolicy_with_powershell.yml | 4 +- .../get_domainpolicy_with_powershell.yml | 4 +- .../get_domaintrust_with_powershell.yml | 3 + .../get_domainuser_with_powershell.yml | 4 +- .../get_foresttrust_with_powershell.yml | 3 + .../getdomaincomputer_with_powershell.yml | 3 + .../getdomaingroup_with_powershell.yml | 3 + ...twmiobject_ds_computer_with_powershell.yml | 3 + .../getwmiobject_ds_group_with_powershell.yml | 3 + .../getwmiobject_ds_user_with_powershell.yml | 4 +- .../hide_user_account_from_sign_in_screen.yml | 4 +- ..._files_and_directories_with_attrib_exe.yml | 5 +- detections/endpoint/icacls_deny_command.yml | 5 +- detections/endpoint/icacls_grant_command.yml | 5 +- ...ateral_movement_commandline_parameters.yml | 3 + ...class_file_download_by_java_user_agent.yml | 10 - .../jscript_execution_using_cscript_app.yml | 4 +- ...add_files_in_known_crontab_directories.yml | 3 - .../linux_at_allow_config_file_creation.yml | 3 - .../linux_at_application_execution.yml | 4 - .../linux_change_file_owner_to_root.yml | 4 - .../linux_doas_conf_file_creation.yml | 3 - .../endpoint/linux_doas_tool_execution.yml | 4 - ...ile_created_in_kernel_driver_directory.yml | 3 - ...x_file_creation_in_init_boot_directory.yml | 3 - ...nux_file_creation_in_profile_directory.yml | 3 - ...ert_kernel_module_using_insmod_utility.yml | 4 - ...l_kernel_module_using_modprobe_utility.yml | 4 - .../linux_nopasswd_entry_in_sudoers_file.yml | 4 - ...ss_or_modification_of_sshd_config_file.yml | 4 - ...ux_possible_access_to_credential_files.yml | 4 - .../linux_possible_access_to_sudoers_file.yml | 4 - ...append_command_to_at_allow_config_file.yml | 4 - ..._append_command_to_profile_config_file.yml | 4 - .../linux_possible_ssh_key_file_creation.yml | 3 - .../linux_preload_hijack_library_calls.yml | 4 - ...vice_file_created_in_systemd_directory.yml | 3 - .../endpoint/linux_service_restarted.yml | 4 - .../linux_service_started_or_enabled.yml | 4 - .../linux_setuid_using_chmod_utility.yml | 4 - .../linux_setuid_using_setcap_utility.yml | 4 - .../linux_sudoers_tmp_file_creation.yml | 3 - .../linux_visudo_utility_execution.yml | 4 - .../logon_script_event_trigger_execution.yml | 4 +- ...hell_process___execution_policy_bypass.yml | 3 + ...ll_process_with_obfuscation_techniques.yml | 3 + ...mmc_exe_lolbas_execution_process_spawn.yml | 3 + ...dify_acl_permission_to_files_or_folder.yml | 5 +- ...d_suspicious_spawned_by_script_process.yml | 3 + ..._spawning_rundll32_or_regsvr32_process.yml | 3 + .../msmpeng_application_dll_side_loading.yml | 5 +- .../endpoint/net_profiler_uac_bypass.yml | 4 +- .../endpoint/nishang_powershelltcponeline.yml | 3 + .../nltest_domain_trust_discovery.yml | 4 +- detections/endpoint/ntdsutil_export_ntds.yml | 4 +- ...ice_application_spawn_regsvr32_process.yml | 3 + ...ice_application_spawn_rundll32_process.yml | 3 + ...ment_spawned_child_process_to_download.yml | 3 + .../office_product_spawn_cmd_process.yml | 3 + .../office_product_spawning_bitsadmin.yml | 3 + .../office_product_spawning_certutil.yml | 3 + .../office_product_spawning_mshta.yml | 3 + ..._product_spawning_rundll32_with_no_dll.yml | 3 + .../endpoint/office_product_spawning_wmic.yml | 3 + .../endpoint/office_spawning_control.yml | 3 + .../overwriting_accessibility_binaries.yml | 11 +- ...mission_modification_using_takeown_app.yml | 4 +- .../endpoint/ping_sleep_batch_command.yml | 3 + ...ible_lateral_movement_powershell_spawn.yml | 3 + ...entially_malicious_code_on_commandline.yml | 79 +- ...powershell_disable_security_monitoring.yml | 3 + .../powershell_start_bitstransfer.yml | 3 + ...nt_automatic_repair_mode_using_bcdedit.yml | 4 +- ...eating_lnk_file_in_suspicious_location.yml | 5 +- .../endpoint/process_execution_via_wmi.yml | 5 +- .../process_kill_base_on_file_path.yml | 3 + .../endpoint/processes_launching_netsh.yml | 4 +- ...rsive_delete_of_directory_in_batch_cmd.yml | 3 + ...ulating_windows_services_registry_keys.yml | 5 +- .../registry_keys_used_for_persistence.yml | 4 +- ...2_silent_and_install_param_dll_loading.yml | 3 + ...svr32_with_known_silent_switch_cmdline.yml | 3 + .../remcos_client_registry_install_entry.yml | 3 + ..._instantiation_via_dcom_and_powershell.yml | 3 + ...instantiation_via_winrm_and_powershell.yml | 3 + ...cess_instantiation_via_winrm_and_winrs.yml | 3 + .../remote_process_instantiation_via_wmi.yml | 3 + ...s_instantiation_via_wmi_and_powershell.yml | 3 + .../remote_system_discovery_with_wmic.yml | 3 + .../endpoint/remote_wmi_command_attempt.yml | 4 +- .../endpoint/resize_shadowstorage_volume.yml | 5 +- .../endpoint/revil_common_exec_parameter.yml | 4 +- detections/endpoint/revil_registry_entry.yml | 4 +- ...ontrol_rundll_world_writable_directory.yml | 3 + .../endpoint/rundll32_shimcache_flush.yml | 3 + ...no_command_line_arguments_with_network.yml | 3 + .../rundll_loading_dll_by_ordinal.yml | 3 + .../endpoint/ryuk_wake_on_lan_command.yml | 4 +- .../endpoint/samsam_test_file_write.yml | 10 +- .../sc_exe_manipulating_windows_services.yml | 5 +- ...k_creation_on_remote_endpoint_using_at.yml | 3 + ...eduled_task_deleted_or_created_via_cmd.yml | 4 +- ...led_task_initiation_on_remote_endpoint.yml | 3 + .../endpoint/schtasks_run_task_on_demand.yml | 5 +- ...htasks_scheduling_job_on_remote_system.yml | 5 +- .../schtasks_used_for_forcing_a_reboot.yml | 5 +- .../screensaver_event_trigger_execution.yml | 4 +- .../endpoint/script_execution_via_wmi.yml | 8 +- detections/endpoint/sdclt_uac_bypass.yml | 4 +- .../sdelete_application_execution.yml | 3 + .../secretdumps_offline_ntds_dumping_tool.yml | 4 +- ...ceprincipalnames_discovery_with_setspn.yml | 3 + detections/endpoint/services_escalate_exe.yml | 4 +- ...ces_exe_lolbas_execution_process_spawn.yml | 3 + ...ution_policy_to_unrestricted_or_bypass.yml | 4 +- ...nstallation_with_suspicious_parameters.yml | 5 +- .../endpoint/short_lived_windows_accounts.yml | 6 - .../endpoint/silentcleanup_uac_bypass.yml | 4 +- .../single_letter_process_on_endpoint.yml | 8 +- detections/endpoint/slui_runas_elevated.yml | 4 +- .../endpoint/slui_spawning_a_process.yml | 4 +- .../endpoint/spoolsv_spawning_rundll32.yml | 3 + detections/endpoint/spoolsv_writing_a_dll.yml | 7 +- .../start_up_during_safe_mode_boot.yml | 4 +- .../endpoint/suspicious_copy_on_system32.yml | 3 + ...ious_dllhost_no_command_line_arguments.yml | 3 + ...ous_gpupdate_no_command_line_arguments.yml | 3 + .../suspicious_icedid_rundll32_cmdline.yml | 3 + ...ious_microsoft_workflow_compiler_usage.yml | 3 + .../endpoint/suspicious_msbuild_path.yml | 3 + .../endpoint/suspicious_msbuild_rename.yml | 3 + .../endpoint/suspicious_msbuild_spawn.yml | 3 + .../suspicious_mshta_child_process.yml | 4 +- .../endpoint/suspicious_mshta_spawn.yml | 3 + .../endpoint/suspicious_process_file_path.yml | 4 +- .../endpoint/suspicious_reg_exe_process.yml | 5 +- ...ious_regsvr32_register_suspicious_path.yml | 3 + .../suspicious_rundll32_dllregisterserver.yml | 3 + .../suspicious_rundll32_plugininit.yml | 3 + .../endpoint/suspicious_rundll32_startw.yml | 3 + ...undll32_with_no_command_line_arguments.yml | 3 + ...s_scheduled_task_from_public_directory.yml | 4 +- ...protocolhost_no_command_line_arguments.yml | 3 + .../endpoint/suspicious_wevtutil_usage.yml | 5 +- ...system_information_discovery_detection.yml | 8 +- ...rocesses_run_from_unexpected_locations.yml | 5 +- .../time_provider_persistence_registry.yml | 4 +- ...d_messaging_service_spawning_a_process.yml | 4 +- .../endpoint/uninstall_app_using_msiexec.yml | 4 +- .../endpoint/unload_sysmon_filter_driver.yml | 5 +- detections/endpoint/usn_journal_deletion.yml | 4 +- .../vbscript_execution_using_wscript_app.yml | 3 + detections/endpoint/w3wp_spawning_shell.yml | 3 + .../wbadmin_delete_system_backups.yml | 5 +- ...cess_spawned_cmd_or_powershell_process.yml | 3 + .../wget_download_and_bash_execution.yml | 3 - detections/endpoint/windows_adfind_exe.yml | 4 +- ...ndows_curl_download_to_suspicious_path.yml | 3 + ...dows_curl_upload_to_remote_destination.yml | 3 + ...dows_defender_exclusion_registry_entry.yml | 3 + .../windows_disableantispyware_reg.yml | 4 +- .../endpoint/windows_dism_remove_defender.yml | 3 + ...ows_dotnet_binary_in_non_standard_path.yml | 3 + .../windows_installutil_credential_theft.yml | 3 + ...ndows_installutil_in_non_standard_path.yml | 3 + .../windows_installutil_uninstall_option.yml | 3 + ...indows_installutil_url_in_command_line.yml | 3 + .../endpoint/windows_nirsoft_advancedrun.yml | 3 + ...indows_raccine_scheduled_task_deletion.yml | 3 + ...ws_service_creation_on_remote_endpoint.yml | 3 + ..._service_initiation_on_remote_endpoint.yml | 3 + .../endpoint/winhlp32_spawning_a_process.yml | 3 + detections/endpoint/winword_spawning_cmd.yml | 3 + .../endpoint/winword_spawning_powershell.yml | 3 + .../endpoint/wmic_xsl_execution_via_url.yml | 3 + ...sve_exe_lolbas_execution_process_spawn.yml | 3 + ...pt_or_cscript_suspicious_child_process.yml | 3 + ...ost_exe_lolbas_execution_process_spawn.yml | 3 + detections/endpoint/wsreset_uac_bypass.yml | 4 +- .../xsl_script_execution_with_wmic.yml | 4 +- .../print_processor_registry_autostart.yml | 3 - ...ry_length_with_high_standard_deviation.yml | 6 +- .../detection_ta_mapping.yml | 1622 +++++++++++++++-- .../enrich_detections.py | 36 +- 316 files changed, 2218 insertions(+), 747 deletions(-) diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index ee6c454a5d..f0183ac59b 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -67,19 +67,5 @@ tags: risk_score: 15 security_domain: network cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_citrix-netscaler - - Splunk_TA_nix - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_ossec - - Splunk_TA_juniper - - splunk_ta_o365 - - Splunk_TA_cyberark - - Splunk_TA_box - - Splunk_TA_cisco-asa - - Splunk_TA_infoblox - - Splunk_TA_salesforce supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index 5a3ace2c14..a505241f07 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -73,19 +73,5 @@ tags: risk_score: 15 security_domain: network cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_citrix-netscaler - - Splunk_TA_nix - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_ossec - - Splunk_TA_juniper - - splunk_ta_o365 - - Splunk_TA_cyberark - - Splunk_TA_box - - Splunk_TA_cisco-asa - - Splunk_TA_infoblox - - Splunk_TA_salesforce supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml index aae78a3cb3..35e8bb586e 100644 --- a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml +++ b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml @@ -69,12 +69,5 @@ tags: risk_score: 36 security_domain: threat cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - splunk_ta_o365 - - Splunk_TA_box - - Splunk_TA_infoblox - - Splunk_TA_salesforce supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index f5b751eb86..e229fe1472 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -70,7 +70,5 @@ tags: risk_score: 18 security_domain: threat cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_aws-kinesis-firehose supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml index a13257095b..2828fb9f29 100644 --- a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml +++ b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml @@ -75,7 +75,5 @@ tags: risk_score: 42 security_domain: threat cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_aws-kinesis-firehose supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml index 689bdacfb9..8375de8ef8 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml @@ -70,7 +70,5 @@ tags: risk_score: 36 security_domain: threat cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_aws-kinesis-firehose supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index f3e5904b50..5c1f453703 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -70,7 +70,5 @@ tags: risk_score: 30 security_domain: threat cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_aws-kinesis-firehose supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml index 4f210a4a96..d2c6b9f33e 100644 --- a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml @@ -72,17 +72,5 @@ tags: risk_score: 42 security_domain: threat cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_citrix-netscaler - - Splunk_TA_nix - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_ossec - - Splunk_TA_juniper - - splunk_ta_o365 - - Splunk_TA_cyberark - - Splunk_TA_box - - Splunk_TA_salesforce supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml index 07b141ead5..cd548cd7e2 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml @@ -91,17 +91,5 @@ tags: risk_score: 18 security_domain: threat cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_citrix-netscaler - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_juniper - - splunk_ta_o365 - - Splunk_TA_cyberark - - Splunk_TA_box - - Splunk_TA_cisco-asa - - Splunk_TA_infoblox - - Splunk_TA_salesforce supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml index c5407d0e50..621b6c1d73 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml @@ -91,17 +91,5 @@ tags: risk_score: 42 security_domain: threat cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_citrix-netscaler - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_juniper - - splunk_ta_o365 - - Splunk_TA_cyberark - - Splunk_TA_box - - Splunk_TA_cisco-asa - - Splunk_TA_infoblox - - Splunk_TA_salesforce supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml index a4c2b5518b..c6144ab8ff 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml @@ -90,15 +90,5 @@ tags: risk_score: 42 security_domain: threat cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_citrix-netscaler - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_juniper - - splunk_ta_o365 - - Splunk_TA_cyberark - - Splunk_TA_box - - Splunk_TA_salesforce supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml index 4b7bac3d92..d05b2e7b5d 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml @@ -91,17 +91,5 @@ tags: risk_score: 42 security_domain: threat cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_citrix-netscaler - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_rsa_securid_cas - - Splunk_TA_juniper - - splunk_ta_o365 - - Splunk_TA_cyberark - - Splunk_TA_box - - Splunk_TA_cisco-asa - - Splunk_TA_infoblox - - Splunk_TA_salesforce supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/endpoint/account_discovery_with_net_app.yml b/detections/endpoint/account_discovery_with_net_app.yml index 722368e8b8..fc37a87984 100644 --- a/detections/endpoint/account_discovery_with_net_app.yml +++ b/detections/endpoint/account_discovery_with_net_app.yml @@ -80,3 +80,6 @@ tags: - Processes.parent_process_id risk_score: 5 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index 44cfc57585..ce32db24ec 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -70,5 +70,5 @@ tags: risk_score: 64 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml index 9081ca14b8..aa2671e2a5 100644 --- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml +++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml @@ -61,5 +61,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/add_or_set_windows_defender_exclusion.yml b/detections/endpoint/add_or_set_windows_defender_exclusion.yml index d75c943cd9..d1452fe07d 100644 --- a/detections/endpoint/add_or_set_windows_defender_exclusion.yml +++ b/detections/endpoint/add_or_set_windows_defender_exclusion.yml @@ -76,3 +76,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index 61844a9fb4..b34b637cdd 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -55,3 +55,6 @@ tags: - Processes.process_path - Processes.parent_process_id security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index 70ee2deb1d..d881d3b9f4 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -66,5 +66,5 @@ tags: risk_score: 3 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/allow_network_discovery_in_firewall.yml b/detections/endpoint/allow_network_discovery_in_firewall.yml index a704470b3f..edfdf48b7b 100644 --- a/detections/endpoint/allow_network_discovery_in_firewall.yml +++ b/detections/endpoint/allow_network_discovery_in_firewall.yml @@ -57,3 +57,6 @@ tags: - Processes.process_path - Processes.parent_process_id security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/allow_operation_with_consent_admin.yml b/detections/endpoint/allow_operation_with_consent_admin.yml index 7ae6eb8d28..7037e99b0f 100644 --- a/detections/endpoint/allow_operation_with_consent_admin.yml +++ b/detections/endpoint/allow_operation_with_consent_admin.yml @@ -66,5 +66,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index 2539223518..c5ca19cb68 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -83,5 +83,5 @@ tags: risk_score: 64 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml index 640444b0cf..284b615d7b 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/endpoint/any_powershell_downloadfile.yml @@ -88,3 +88,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml index 6de61407fb..08135b8c62 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/endpoint/any_powershell_downloadstring.yml @@ -82,3 +82,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index cb6225b0fb..ae0d935c58 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -87,6 +87,5 @@ tags: risk_score: 64 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_windows + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index b38e4f89d0..a341612d6a 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -85,5 +85,5 @@ tags: risk_score: 35 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index fe2fd4b662..b7fe41a8ee 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -92,3 +92,6 @@ tags: - Processes.parent_process_id risk_score: 20 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml index c3778c3143..ebc6d0480e 100644 --- a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -86,3 +86,6 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/auto_admin_logon_registry_entry.yml b/detections/endpoint/auto_admin_logon_registry_entry.yml index c7f309228e..eaf227b588 100644 --- a/detections/endpoint/auto_admin_logon_registry_entry.yml +++ b/detections/endpoint/auto_admin_logon_registry_entry.yml @@ -61,5 +61,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index a9ec853d55..3f18d1e201 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -84,8 +84,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_nix - - Splunk_TA_bit9-carbonblack - - Splunk_TA_windows - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml index 058fa2c5c5..1186a5f6e6 100644 --- a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml +++ b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml @@ -66,5 +66,5 @@ tags: risk_score: 35 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/bcdedit_failure_recovery_modification.yml b/detections/endpoint/bcdedit_failure_recovery_modification.yml index 9b8fa771c0..cccd1c231f 100644 --- a/detections/endpoint/bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/bcdedit_failure_recovery_modification.yml @@ -76,6 +76,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/bits_job_persistence.yml b/detections/endpoint/bits_job_persistence.yml index 44262d9858..07befbd67b 100644 --- a/detections/endpoint/bits_job_persistence.yml +++ b/detections/endpoint/bits_job_persistence.yml @@ -86,3 +86,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/bitsadmin_download_file.yml b/detections/endpoint/bitsadmin_download_file.yml index 241dae1127..840d6f5005 100644 --- a/detections/endpoint/bitsadmin_download_file.yml +++ b/detections/endpoint/bitsadmin_download_file.yml @@ -92,3 +92,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml index af05ba2894..907214d425 100644 --- a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml index d35aa4fa46..81517f62c1 100644 --- a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml @@ -85,3 +85,6 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/certutil_exe_certificate_extraction.yml b/detections/endpoint/certutil_exe_certificate_extraction.yml index 4316a29554..c07b4d39e0 100644 --- a/detections/endpoint/certutil_exe_certificate_extraction.yml +++ b/detections/endpoint/certutil_exe_certificate_extraction.yml @@ -74,3 +74,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/certutil_with_decode_argument.yml b/detections/endpoint/certutil_with_decode_argument.yml index 48babdb840..b5de170762 100644 --- a/detections/endpoint/certutil_with_decode_argument.yml +++ b/detections/endpoint/certutil_with_decode_argument.yml @@ -85,3 +85,6 @@ tags: - Processes.parent_process_id risk_score: 40 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/change_default_file_association.yml b/detections/endpoint/change_default_file_association.yml index 4d24bab7a4..8dbf4e8075 100644 --- a/detections/endpoint/change_default_file_association.yml +++ b/detections/endpoint/change_default_file_association.yml @@ -67,5 +67,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/change_to_safe_mode_with_network_config.yml b/detections/endpoint/change_to_safe_mode_with_network_config.yml index 52f57fc4c5..45919b20bd 100644 --- a/detections/endpoint/change_to_safe_mode_with_network_config.yml +++ b/detections/endpoint/change_to_safe_mode_with_network_config.yml @@ -65,5 +65,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/check_elevated_cmd_using_whoami.yml b/detections/endpoint/check_elevated_cmd_using_whoami.yml index bcf82b1b1f..9d8f4e0502 100644 --- a/detections/endpoint/check_elevated_cmd_using_whoami.yml +++ b/detections/endpoint/check_elevated_cmd_using_whoami.yml @@ -66,5 +66,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml index 5b072f7c71..ae3234ff3a 100644 --- a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml +++ b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml @@ -77,3 +77,6 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/clop_common_exec_parameter.yml b/detections/endpoint/clop_common_exec_parameter.yml index 57972f397f..22ac1853f6 100644 --- a/detections/endpoint/clop_common_exec_parameter.yml +++ b/detections/endpoint/clop_common_exec_parameter.yml @@ -81,3 +81,6 @@ tags: - Processes.parent_process_id risk_score: 100 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/cmd_echo_pipe___escalation.yml b/detections/endpoint/cmd_echo_pipe___escalation.yml index 4b39807d71..94218466ce 100644 --- a/detections/endpoint/cmd_echo_pipe___escalation.yml +++ b/detections/endpoint/cmd_echo_pipe___escalation.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml index 36918e047d..d808f8859d 100644 --- a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml @@ -87,3 +87,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/conti_common_exec_parameter.yml b/detections/endpoint/conti_common_exec_parameter.yml index e431e4767b..9633a964b5 100644 --- a/detections/endpoint/conti_common_exec_parameter.yml +++ b/detections/endpoint/conti_common_exec_parameter.yml @@ -78,3 +78,6 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/control_loading_from_world_writable_directory.yml b/detections/endpoint/control_loading_from_world_writable_directory.yml index caf4bf6d2a..7c5f1634a8 100644 --- a/detections/endpoint/control_loading_from_world_writable_directory.yml +++ b/detections/endpoint/control_loading_from_world_writable_directory.yml @@ -86,3 +86,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml index 5c42674597..2a09722d84 100644 --- a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml +++ b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml @@ -86,3 +86,6 @@ tags: - Processes.parent_process_id risk_score: 30 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml index 57a2ce24f5..1d28a87f63 100644 --- a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml +++ b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml @@ -83,3 +83,6 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/creation_of_shadow_copy.yml b/detections/endpoint/creation_of_shadow_copy.yml index 9d6834c7db..4eacd5226c 100644 --- a/detections/endpoint/creation_of_shadow_copy.yml +++ b/detections/endpoint/creation_of_shadow_copy.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml index 74bf3b4f5d..c9e60418ae 100644 --- a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml +++ b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml @@ -82,3 +82,6 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml index 85bd4e7891..bc6485ca67 100644 --- a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml index 9efa0420bb..7330ce6b55 100644 --- a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml @@ -82,3 +82,6 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/curl_download_and_bash_execution.yml b/detections/endpoint/curl_download_and_bash_execution.yml index 653d943a75..fc436a3232 100644 --- a/detections/endpoint/curl_download_and_bash_execution.yml +++ b/detections/endpoint/curl_download_and_bash_execution.yml @@ -77,6 +77,3 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/deleting_of_net_users.yml b/detections/endpoint/deleting_of_net_users.yml index 65ae091a01..d96446ded4 100644 --- a/detections/endpoint/deleting_of_net_users.yml +++ b/detections/endpoint/deleting_of_net_users.yml @@ -81,3 +81,6 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml index 90136285c4..bfc5f20148 100644 --- a/detections/endpoint/deleting_shadow_copies.yml +++ b/detections/endpoint/deleting_shadow_copies.yml @@ -88,3 +88,6 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_azurehound_command_line_arguments.yml b/detections/endpoint/detect_azurehound_command_line_arguments.yml index 609fee47b8..d855ae3284 100644 --- a/detections/endpoint/detect_azurehound_command_line_arguments.yml +++ b/detections/endpoint/detect_azurehound_command_line_arguments.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml index 205bd2a81e..74103fcfe5 100644 --- a/detections/endpoint/detect_exchange_web_shell.yml +++ b/detections/endpoint/detect_exchange_web_shell.yml @@ -95,6 +95,5 @@ tags: risk_score: 81 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_html_help_spawn_child_process.yml b/detections/endpoint/detect_html_help_spawn_child_process.yml index 297d53a3ba..b2f62ca6cf 100644 --- a/detections/endpoint/detect_html_help_spawn_child_process.yml +++ b/detections/endpoint/detect_html_help_spawn_child_process.yml @@ -94,3 +94,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml index 1ee0da1045..6d4e8a89f6 100644 --- a/detections/endpoint/detect_html_help_url_in_command_line.yml +++ b/detections/endpoint/detect_html_help_url_in_command_line.yml @@ -98,3 +98,6 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml index b339a00b1b..6b6adb1c36 100644 --- a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml +++ b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml @@ -95,3 +95,6 @@ tags: - Processes.parent_process_id risk_score: 72 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_mshta_inline_hta_execution.yml b/detections/endpoint/detect_mshta_inline_hta_execution.yml index aa378f0c38..184698eecc 100644 --- a/detections/endpoint/detect_mshta_inline_hta_execution.yml +++ b/detections/endpoint/detect_mshta_inline_hta_execution.yml @@ -90,3 +90,6 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index c49ff33249..86903995d5 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -91,3 +91,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml index 48dc4eac69..d8eee2b082 100644 --- a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml +++ b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml @@ -85,3 +85,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml index 7228b8d762..ab329a527a 100644 --- a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml +++ b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml @@ -88,3 +88,6 @@ tags: - Processes.parent_process_id risk_score: 32 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index a8f9c6fc3c..06ff1f3e4d 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -94,3 +94,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml index 0417b7d8c3..547f1885f5 100644 --- a/detections/endpoint/detect_rclone_command_line_usage.yml +++ b/detections/endpoint/detect_rclone_command_line_usage.yml @@ -84,3 +84,6 @@ tags: - Processes.original_file_name risk_score: 35 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml index 2f4ea79251..56f7bdb6bb 100644 --- a/detections/endpoint/detect_regasm_spawning_a_process.yml +++ b/detections/endpoint/detect_regasm_spawning_a_process.yml @@ -88,5 +88,5 @@ tags: risk_score: 64 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml index e7e3af15e3..fb5bacf3f9 100644 --- a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml @@ -89,3 +89,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_regsvcs_spawning_a_process.yml b/detections/endpoint/detect_regsvcs_spawning_a_process.yml index 7d90b69783..cf0953cb87 100644 --- a/detections/endpoint/detect_regsvcs_spawning_a_process.yml +++ b/detections/endpoint/detect_regsvcs_spawning_a_process.yml @@ -87,5 +87,5 @@ tags: risk_score: 64 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml index f12af4889a..555e08e9c4 100644 --- a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml @@ -89,3 +89,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml index d9c60a5d52..acb50c61f9 100644 --- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml +++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml @@ -96,3 +96,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml index 95e6971170..76bea5fc5b 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml @@ -95,3 +95,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml index a50999441c..3047bb495e 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml @@ -93,3 +93,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml index d7be020574..a47392f985 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml @@ -95,3 +95,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_rundll32_inline_hta_execution.yml b/detections/endpoint/detect_rundll32_inline_hta_execution.yml index b25022b50a..7b86e40cc4 100644 --- a/detections/endpoint/detect_rundll32_inline_hta_execution.yml +++ b/detections/endpoint/detect_rundll32_inline_hta_execution.yml @@ -81,3 +81,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_sharphound_command_line_arguments.yml b/detections/endpoint/detect_sharphound_command_line_arguments.yml index 18268a168d..247acc09ab 100644 --- a/detections/endpoint/detect_sharphound_command_line_arguments.yml +++ b/detections/endpoint/detect_sharphound_command_line_arguments.yml @@ -72,5 +72,5 @@ tags: risk_score: 24 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_sharphound_usage.yml b/detections/endpoint/detect_sharphound_usage.yml index 01e9367191..c9690eedee 100644 --- a/detections/endpoint/detect_sharphound_usage.yml +++ b/detections/endpoint/detect_sharphound_usage.yml @@ -80,3 +80,6 @@ tags: - Processes.parent_process_id risk_score: 24 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index 39d61af635..359c8cf93c 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -68,5 +68,5 @@ tags: risk_score: 35 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_amsi_through_registry.yml b/detections/endpoint/disable_amsi_through_registry.yml index 33ff3e6082..e4b771e25d 100644 --- a/detections/endpoint/disable_amsi_through_registry.yml +++ b/detections/endpoint/disable_amsi_through_registry.yml @@ -48,5 +48,5 @@ tags: - Registry.registry_value_name security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_antivirus_registry.yml b/detections/endpoint/disable_defender_antivirus_registry.yml index bc365d77ff..ab9c466d4c 100644 --- a/detections/endpoint/disable_defender_antivirus_registry.yml +++ b/detections/endpoint/disable_defender_antivirus_registry.yml @@ -12,11 +12,11 @@ description: This particular behavior is typically executed when an adversaries task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender*" Registry.registry_key_name = DisableAntiVirus Registry.registry_value_name="DWORD (0x00000001)" by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data -| `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `disable_defender_antivirus_registry_filter`' + as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows + Defender*" Registry.registry_key_name = DisableAntiVirus Registry.registry_value_name="DWORD + (0x00000001)" by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` | `disable_defender_antivirus_registry_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the @@ -64,3 +64,6 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml index 58020d56e1..c6c9e9c22b 100644 --- a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml +++ b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml @@ -63,3 +63,6 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_enhanced_notification.yml b/detections/endpoint/disable_defender_enhanced_notification.yml index c1c61d9e9d..ddd7057e83 100644 --- a/detections/endpoint/disable_defender_enhanced_notification.yml +++ b/detections/endpoint/disable_defender_enhanced_notification.yml @@ -63,3 +63,6 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_mpengine_registry.yml b/detections/endpoint/disable_defender_mpengine_registry.yml index 1314ebbd59..f2cb19762f 100644 --- a/detections/endpoint/disable_defender_mpengine_registry.yml +++ b/detections/endpoint/disable_defender_mpengine_registry.yml @@ -64,3 +64,6 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_spynet_reporting.yml b/detections/endpoint/disable_defender_spynet_reporting.yml index 591a7c90ff..5b4a8b6d05 100644 --- a/detections/endpoint/disable_defender_spynet_reporting.yml +++ b/detections/endpoint/disable_defender_spynet_reporting.yml @@ -62,3 +62,6 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml index c40ed524a5..e43792b639 100644 --- a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml +++ b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml @@ -62,3 +62,6 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_etw_through_registry.yml b/detections/endpoint/disable_etw_through_registry.yml index 21690db7bf..94f04b19f2 100644 --- a/detections/endpoint/disable_etw_through_registry.yml +++ b/detections/endpoint/disable_etw_through_registry.yml @@ -47,5 +47,5 @@ tags: - Registry.registry_value_name security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_logs_using_wevtutil.yml b/detections/endpoint/disable_logs_using_wevtutil.yml index 60b2bb04df..77ba6e062c 100644 --- a/detections/endpoint/disable_logs_using_wevtutil.yml +++ b/detections/endpoint/disable_logs_using_wevtutil.yml @@ -62,5 +62,5 @@ tags: risk_score: 24 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_registry_tool.yml b/detections/endpoint/disable_registry_tool.yml index 6dd2e5de12..5faa5a2732 100644 --- a/detections/endpoint/disable_registry_tool.yml +++ b/detections/endpoint/disable_registry_tool.yml @@ -61,5 +61,5 @@ tags: risk_score: 40 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_schedule_task.yml b/detections/endpoint/disable_schedule_task.yml index 33e228ae36..a7bfa49691 100644 --- a/detections/endpoint/disable_schedule_task.yml +++ b/detections/endpoint/disable_schedule_task.yml @@ -61,6 +61,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_security_logs_using_minint_registry.yml b/detections/endpoint/disable_security_logs_using_minint_registry.yml index 25742946c7..1b7a7390c0 100644 --- a/detections/endpoint/disable_security_logs_using_minint_registry.yml +++ b/detections/endpoint/disable_security_logs_using_minint_registry.yml @@ -63,3 +63,6 @@ tags: - Registry.registry_value_data risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_uac_remote_restriction.yml b/detections/endpoint/disable_uac_remote_restriction.yml index 15f71bbd67..5432bab990 100644 --- a/detections/endpoint/disable_uac_remote_restriction.yml +++ b/detections/endpoint/disable_uac_remote_restriction.yml @@ -68,3 +68,6 @@ tags: - Registry.registry_value_data risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_windows_app_hotkeys.yml b/detections/endpoint/disable_windows_app_hotkeys.yml index 1c0a14c31d..15a81fe061 100644 --- a/detections/endpoint/disable_windows_app_hotkeys.yml +++ b/detections/endpoint/disable_windows_app_hotkeys.yml @@ -62,5 +62,5 @@ tags: risk_score: 40 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index 6897c468eb..6d5b4da519 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -69,5 +69,5 @@ tags: risk_score: 40 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_cmd_application.yml b/detections/endpoint/disabling_cmd_application.yml index a55f0de313..b25d344ef9 100644 --- a/detections/endpoint/disabling_cmd_application.yml +++ b/detections/endpoint/disabling_cmd_application.yml @@ -64,5 +64,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_controlpanel.yml b/detections/endpoint/disabling_controlpanel.yml index 841f607ffc..3c2314b807 100644 --- a/detections/endpoint/disabling_controlpanel.yml +++ b/detections/endpoint/disabling_controlpanel.yml @@ -63,5 +63,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_defender_services.yml b/detections/endpoint/disabling_defender_services.yml index 1f98df40f2..605b8da81a 100644 --- a/detections/endpoint/disabling_defender_services.yml +++ b/detections/endpoint/disabling_defender_services.yml @@ -65,3 +65,6 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_firewall_with_netsh.yml b/detections/endpoint/disabling_firewall_with_netsh.yml index 14bd3ece53..a06406df67 100644 --- a/detections/endpoint/disabling_firewall_with_netsh.yml +++ b/detections/endpoint/disabling_firewall_with_netsh.yml @@ -71,3 +71,6 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_folderoptions_windows_feature.yml b/detections/endpoint/disabling_folderoptions_windows_feature.yml index 2632fc415e..09632c7e1a 100644 --- a/detections/endpoint/disabling_folderoptions_windows_feature.yml +++ b/detections/endpoint/disabling_folderoptions_windows_feature.yml @@ -64,6 +64,3 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/disabling_net_user_account.yml b/detections/endpoint/disabling_net_user_account.yml index e03f2ee78f..9edc5a6c73 100644 --- a/detections/endpoint/disabling_net_user_account.yml +++ b/detections/endpoint/disabling_net_user_account.yml @@ -78,3 +78,6 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_norun_windows_app.yml b/detections/endpoint/disabling_norun_windows_app.yml index e28f8263ef..674f338ab7 100644 --- a/detections/endpoint/disabling_norun_windows_app.yml +++ b/detections/endpoint/disabling_norun_windows_app.yml @@ -67,5 +67,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_systemrestore_in_registry.yml b/detections/endpoint/disabling_systemrestore_in_registry.yml index 335d48ac4a..5896d077ed 100644 --- a/detections/endpoint/disabling_systemrestore_in_registry.yml +++ b/detections/endpoint/disabling_systemrestore_in_registry.yml @@ -67,5 +67,5 @@ tags: risk_score: 49 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_task_manager.yml b/detections/endpoint/disabling_task_manager.yml index 2be8bcff43..e939195711 100644 --- a/detections/endpoint/disabling_task_manager.yml +++ b/detections/endpoint/disabling_task_manager.yml @@ -65,5 +65,5 @@ tags: risk_score: 42 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml index 2320781457..e7f0cdf812 100644 --- a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml +++ b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml @@ -85,3 +85,6 @@ tags: - Processes.parent_process_id risk_score: 72 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/domain_account_discovery_with_net_app.yml b/detections/endpoint/domain_account_discovery_with_net_app.yml index 5fa36727e6..57b3db2c23 100644 --- a/detections/endpoint/domain_account_discovery_with_net_app.yml +++ b/detections/endpoint/domain_account_discovery_with_net_app.yml @@ -71,5 +71,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index 0f9b7664db..c91fca490b 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -72,5 +72,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/domain_controller_discovery_with_nltest.yml b/detections/endpoint/domain_controller_discovery_with_nltest.yml index 700712c009..e2df023bdf 100644 --- a/detections/endpoint/domain_controller_discovery_with_nltest.yml +++ b/detections/endpoint/domain_controller_discovery_with_nltest.yml @@ -63,3 +63,6 @@ tags: - Processes.parent_process_id risk_score: 21 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/dsquery_domain_discovery.yml b/detections/endpoint/dsquery_domain_discovery.yml index e8ff5f98ef..f7b604c0c2 100644 --- a/detections/endpoint/dsquery_domain_discovery.yml +++ b/detections/endpoint/dsquery_domain_discovery.yml @@ -94,6 +94,5 @@ tags: risk_score: 72 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml index ee1428e64c..162c716972 100644 --- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml +++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/dump_lsass_via_procdump.yml b/detections/endpoint/dump_lsass_via_procdump.yml index f116ed0de0..0d141fff62 100644 --- a/detections/endpoint/dump_lsass_via_procdump.yml +++ b/detections/endpoint/dump_lsass_via_procdump.yml @@ -90,6 +90,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/elevated_group_discovery_with_net.yml b/detections/endpoint/elevated_group_discovery_with_net.yml index c69c5ffe53..39f23584ed 100644 --- a/detections/endpoint/elevated_group_discovery_with_net.yml +++ b/detections/endpoint/elevated_group_discovery_with_net.yml @@ -70,3 +70,6 @@ tags: - Processes.parent_process_id risk_score: 21 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/elevated_group_discovery_with_wmic.yml b/detections/endpoint/elevated_group_discovery_with_wmic.yml index bab8fab7ba..68e797fe47 100644 --- a/detections/endpoint/elevated_group_discovery_with_wmic.yml +++ b/detections/endpoint/elevated_group_discovery_with_wmic.yml @@ -68,3 +68,6 @@ tags: - Processes.parent_process_id risk_score: 21 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/enable_rdp_in_other_port_number.yml b/detections/endpoint/enable_rdp_in_other_port_number.yml index 3ea8522448..f6b1dc6c6b 100644 --- a/detections/endpoint/enable_rdp_in_other_port_number.yml +++ b/detections/endpoint/enable_rdp_in_other_port_number.yml @@ -61,5 +61,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml b/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml index fc583e08b4..07fb4b2a04 100644 --- a/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml +++ b/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml @@ -66,3 +66,6 @@ tags: - Registry.registry_value_data risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/etw_registry_disabled.yml b/detections/endpoint/etw_registry_disabled.yml index 2b457191b9..ae577c1cf1 100644 --- a/detections/endpoint/etw_registry_disabled.yml +++ b/detections/endpoint/etw_registry_disabled.yml @@ -66,3 +66,6 @@ tags: - Registry.registry_value_data risk_score: 90 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/eventvwr_uac_bypass.yml b/detections/endpoint/eventvwr_uac_bypass.yml index 3fd7702c63..a0748deb7b 100644 --- a/detections/endpoint/eventvwr_uac_bypass.yml +++ b/detections/endpoint/eventvwr_uac_bypass.yml @@ -69,5 +69,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excel_spawning_powershell.yml b/detections/endpoint/excel_spawning_powershell.yml index b853bffe4d..565d53ec51 100644 --- a/detections/endpoint/excel_spawning_powershell.yml +++ b/detections/endpoint/excel_spawning_powershell.yml @@ -82,3 +82,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_attempt_to_disable_services.yml b/detections/endpoint/excessive_attempt_to_disable_services.yml index 181c0984b7..802a903b48 100644 --- a/detections/endpoint/excessive_attempt_to_disable_services.yml +++ b/detections/endpoint/excessive_attempt_to_disable_services.yml @@ -65,6 +65,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml b/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml index 08ada8e06a..937c8700fa 100644 --- a/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml +++ b/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml @@ -59,11 +59,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_nix - - Splunk_TA_bit9-carbonblack - - Splunk_TA_windows - - Splunk_TA_CrowdStrike_FDR - - Splunk_TA_cyberark_epm supported_tas: - Splunk_TA_windows diff --git a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml index 76e57b909c..ee71b5f359 100644 --- a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml +++ b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml @@ -74,5 +74,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_number_of_taskhost_processes.yml b/detections/endpoint/excessive_number_of_taskhost_processes.yml index 0c8c37cf5b..46d88e3815 100644 --- a/detections/endpoint/excessive_number_of_taskhost_processes.yml +++ b/detections/endpoint/excessive_number_of_taskhost_processes.yml @@ -68,10 +68,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_nix - - Splunk_TA_bit9-carbonblack - - Splunk_TA_windows - - Splunk_TA_CrowdStrike_FDR supported_tas: - Splunk_TA_windows diff --git a/detections/endpoint/excessive_service_stop_attempt.yml b/detections/endpoint/excessive_service_stop_attempt.yml index 4dda001358..4da5e65371 100644 --- a/detections/endpoint/excessive_service_stop_attempt.yml +++ b/detections/endpoint/excessive_service_stop_attempt.yml @@ -72,3 +72,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_usage_of_cacls_app.yml b/detections/endpoint/excessive_usage_of_cacls_app.yml index a86afa11a5..1cf73e8a56 100644 --- a/detections/endpoint/excessive_usage_of_cacls_app.yml +++ b/detections/endpoint/excessive_usage_of_cacls_app.yml @@ -65,6 +65,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_usage_of_net_app.yml b/detections/endpoint/excessive_usage_of_net_app.yml index 90d4e076d0..090bb8c518 100644 --- a/detections/endpoint/excessive_usage_of_net_app.yml +++ b/detections/endpoint/excessive_usage_of_net_app.yml @@ -76,3 +76,6 @@ tags: - Processes.parent_process_id risk_score: 28 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_usage_of_taskkill.yml b/detections/endpoint/excessive_usage_of_taskkill.yml index 03fb010842..1fd76c86df 100644 --- a/detections/endpoint/excessive_usage_of_taskkill.yml +++ b/detections/endpoint/excessive_usage_of_taskkill.yml @@ -69,6 +69,5 @@ tags: risk_score: 28 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index 1fd09e4f38..01d3cd9741 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -80,6 +80,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml index 9126fe1ccd..28a02c0210 100644 --- a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml +++ b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml @@ -75,5 +75,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index 9a4ff21cb1..eddde66d1e 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -75,6 +75,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_windows + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/extraction_of_registry_hives.yml b/detections/endpoint/extraction_of_registry_hives.yml index 474f424a7e..9da67e0c63 100644 --- a/detections/endpoint/extraction_of_registry_hives.yml +++ b/detections/endpoint/extraction_of_registry_hives.yml @@ -78,3 +78,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml index ecb4d1cd2d..b4013208c3 100644 --- a/detections/endpoint/file_with_samsam_extension.yml +++ b/detections/endpoint/file_with_samsam_extension.yml @@ -70,11 +70,5 @@ tags: risk_score: 90 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_nix - - Splunk_TA_bit9-carbonblack - - splunk_ta_o365 - - Splunk_TA_sophos - - Splunk_TA_cyberark - - Splunk_TA_windows - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/firewall_allowed_program_enable.yml b/detections/endpoint/firewall_allowed_program_enable.yml index 62534e7cad..ce15567e77 100644 --- a/detections/endpoint/firewall_allowed_program_enable.yml +++ b/detections/endpoint/firewall_allowed_program_enable.yml @@ -68,5 +68,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/fodhelper_uac_bypass.yml b/detections/endpoint/fodhelper_uac_bypass.yml index e801b4e354..9e153ef472 100644 --- a/detections/endpoint/fodhelper_uac_bypass.yml +++ b/detections/endpoint/fodhelper_uac_bypass.yml @@ -87,5 +87,5 @@ tags: risk_score: 81 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/fsutil_zeroing_file.yml b/detections/endpoint/fsutil_zeroing_file.yml index 3c35656489..2738bdeb42 100644 --- a/detections/endpoint/fsutil_zeroing_file.yml +++ b/detections/endpoint/fsutil_zeroing_file.yml @@ -58,5 +58,5 @@ tags: risk_score: 54 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml index 728d9e9a9b..865fe4c7ab 100644 --- a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml +++ b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml @@ -72,5 +72,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/get_domainpolicy_with_powershell.yml b/detections/endpoint/get_domainpolicy_with_powershell.yml index 90280b3e02..918f812f1a 100644 --- a/detections/endpoint/get_domainpolicy_with_powershell.yml +++ b/detections/endpoint/get_domainpolicy_with_powershell.yml @@ -72,5 +72,5 @@ tags: risk_score: 30 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/get_domaintrust_with_powershell.yml b/detections/endpoint/get_domaintrust_with_powershell.yml index f0ca412207..a2367a1d36 100644 --- a/detections/endpoint/get_domaintrust_with_powershell.yml +++ b/detections/endpoint/get_domaintrust_with_powershell.yml @@ -71,3 +71,6 @@ tags: - Processes.parent_process_id risk_score: 12 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml index ec2699b7b1..816ab95e37 100644 --- a/detections/endpoint/get_domainuser_with_powershell.yml +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -72,5 +72,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/get_foresttrust_with_powershell.yml b/detections/endpoint/get_foresttrust_with_powershell.yml index b03dd70b8d..661368032d 100644 --- a/detections/endpoint/get_foresttrust_with_powershell.yml +++ b/detections/endpoint/get_foresttrust_with_powershell.yml @@ -72,3 +72,6 @@ tags: - Processes.parent_process_id risk_score: 12 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/getdomaincomputer_with_powershell.yml b/detections/endpoint/getdomaincomputer_with_powershell.yml index d468863479..996fd3579c 100644 --- a/detections/endpoint/getdomaincomputer_with_powershell.yml +++ b/detections/endpoint/getdomaincomputer_with_powershell.yml @@ -63,3 +63,6 @@ tags: - Processes.parent_process_id risk_score: 24 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/getdomaingroup_with_powershell.yml b/detections/endpoint/getdomaingroup_with_powershell.yml index 9ac798505f..6bf0650d8b 100644 --- a/detections/endpoint/getdomaingroup_with_powershell.yml +++ b/detections/endpoint/getdomaingroup_with_powershell.yml @@ -65,3 +65,6 @@ tags: - Processes.parent_process_id risk_score: 15 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml b/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml index 235c52a3a7..df304cf24a 100644 --- a/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml @@ -64,3 +64,6 @@ tags: - Processes.parent_process_id risk_score: 21 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml index eaa34c8215..54ab0736ba 100644 --- a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml @@ -67,3 +67,6 @@ tags: - Processes.parent_process_id risk_score: 15 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml index 4ccf31d24f..fbe98c8ce3 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -74,5 +74,5 @@ tags: risk_score: 25 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/hide_user_account_from_sign_in_screen.yml b/detections/endpoint/hide_user_account_from_sign_in_screen.yml index bc922181e5..8b93e1bd40 100644 --- a/detections/endpoint/hide_user_account_from_sign_in_screen.yml +++ b/detections/endpoint/hide_user_account_from_sign_in_screen.yml @@ -71,5 +71,5 @@ tags: risk_score: 72 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index 63e66d8e73..f6595b88f0 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -75,6 +75,5 @@ tags: risk_score: 72 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_windows + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/icacls_deny_command.yml b/detections/endpoint/icacls_deny_command.yml index e914117b5a..8246482db2 100644 --- a/detections/endpoint/icacls_deny_command.yml +++ b/detections/endpoint/icacls_deny_command.yml @@ -66,6 +66,5 @@ tags: risk_score: 72 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/icacls_grant_command.yml b/detections/endpoint/icacls_grant_command.yml index 7577f5d5fd..2e5a3a82e8 100644 --- a/detections/endpoint/icacls_grant_command.yml +++ b/detections/endpoint/icacls_grant_command.yml @@ -66,6 +66,5 @@ tags: risk_score: 49 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml index 8f6faa77bf..0cbeb833ad 100644 --- a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml @@ -81,3 +81,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/java_class_file_download_by_java_user_agent.yml b/detections/endpoint/java_class_file_download_by_java_user_agent.yml index 4146d277c7..864c3d03fd 100644 --- a/detections/endpoint/java_class_file_download_by_java_user_agent.yml +++ b/detections/endpoint/java_class_file_download_by_java_user_agent.yml @@ -67,13 +67,3 @@ tags: - Web.http_user_agent risk_score: 40 security_domain: network - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_citrix-netscaler - - Splunk_TA_nginx - - Splunk_TA_microsoft-iis - - Splunk_TA_websense-cg - - Splunk_TA_squid - - Splunk_TA_haproxy - - Splunk_TA_mcafee-wg - - Splunk_TA_cisco-wsa diff --git a/detections/endpoint/jscript_execution_using_cscript_app.yml b/detections/endpoint/jscript_execution_using_cscript_app.yml index 0f2b8f9134..44b797c99a 100644 --- a/detections/endpoint/jscript_execution_using_cscript_app.yml +++ b/detections/endpoint/jscript_execution_using_cscript_app.yml @@ -70,5 +70,5 @@ tags: risk_score: 49 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/linux_add_files_in_known_crontab_directories.yml b/detections/endpoint/linux_add_files_in_known_crontab_directories.yml index e83a0eea80..37bbd7ea38 100644 --- a/detections/endpoint/linux_add_files_in_known_crontab_directories.yml +++ b/detections/endpoint/linux_add_files_in_known_crontab_directories.yml @@ -70,6 +70,3 @@ tags: - Filesystem.file_path risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_at_allow_config_file_creation.yml b/detections/endpoint/linux_at_allow_config_file_creation.yml index 19593a3a33..44c01c5905 100644 --- a/detections/endpoint/linux_at_allow_config_file_creation.yml +++ b/detections/endpoint/linux_at_allow_config_file_creation.yml @@ -69,6 +69,3 @@ tags: - Filesystem.file_path risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_at_application_execution.yml b/detections/endpoint/linux_at_application_execution.yml index 0b05d1a797..07a98f45d8 100644 --- a/detections/endpoint/linux_at_application_execution.yml +++ b/detections/endpoint/linux_at_application_execution.yml @@ -71,7 +71,3 @@ tags: - Processes.parent_process_id risk_score: 9 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_change_file_owner_to_root.yml b/detections/endpoint/linux_change_file_owner_to_root.yml index b0c6002f44..bee64e143f 100644 --- a/detections/endpoint/linux_change_file_owner_to_root.yml +++ b/detections/endpoint/linux_change_file_owner_to_root.yml @@ -72,7 +72,3 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_doas_conf_file_creation.yml b/detections/endpoint/linux_doas_conf_file_creation.yml index ba17e9086a..1a0d7dce2b 100644 --- a/detections/endpoint/linux_doas_conf_file_creation.yml +++ b/detections/endpoint/linux_doas_conf_file_creation.yml @@ -70,6 +70,3 @@ tags: - Filesystem.file_path risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_doas_tool_execution.yml b/detections/endpoint/linux_doas_tool_execution.yml index 937816c218..0997182fa7 100644 --- a/detections/endpoint/linux_doas_tool_execution.yml +++ b/detections/endpoint/linux_doas_tool_execution.yml @@ -73,7 +73,3 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml b/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml index 34093ccfdd..c8e48e229c 100644 --- a/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml +++ b/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml @@ -71,6 +71,3 @@ tags: - Filesystem.file_path risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_file_creation_in_init_boot_directory.yml b/detections/endpoint/linux_file_creation_in_init_boot_directory.yml index d45f4adbb3..28b9fee84d 100644 --- a/detections/endpoint/linux_file_creation_in_init_boot_directory.yml +++ b/detections/endpoint/linux_file_creation_in_init_boot_directory.yml @@ -67,6 +67,3 @@ tags: - Filesystem.file_path risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_file_creation_in_profile_directory.yml b/detections/endpoint/linux_file_creation_in_profile_directory.yml index e39de96166..7ad259ac67 100644 --- a/detections/endpoint/linux_file_creation_in_profile_directory.yml +++ b/detections/endpoint/linux_file_creation_in_profile_directory.yml @@ -69,6 +69,3 @@ tags: - Filesystem.file_path risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml b/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml index d1d9c576eb..9efacdd220 100644 --- a/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml +++ b/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml @@ -71,7 +71,3 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml b/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml index d35b0729b0..9825cd8934 100644 --- a/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml +++ b/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml @@ -72,7 +72,3 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml index ed04f50b91..f3c9be8b15 100644 --- a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml +++ b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml @@ -73,7 +73,3 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml b/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml index 318d61af9f..22818a0ab6 100644 --- a/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml +++ b/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml @@ -72,7 +72,3 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_access_to_credential_files.yml b/detections/endpoint/linux_possible_access_to_credential_files.yml index 086fc87057..3b695cc0f6 100644 --- a/detections/endpoint/linux_possible_access_to_credential_files.yml +++ b/detections/endpoint/linux_possible_access_to_credential_files.yml @@ -73,7 +73,3 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_access_to_sudoers_file.yml b/detections/endpoint/linux_possible_access_to_sudoers_file.yml index 1d3d679792..4d287e68ca 100644 --- a/detections/endpoint/linux_possible_access_to_sudoers_file.yml +++ b/detections/endpoint/linux_possible_access_to_sudoers_file.yml @@ -71,7 +71,3 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml b/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml index bb2dda20cd..4eb48d7d79 100644 --- a/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml +++ b/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml @@ -73,7 +73,3 @@ tags: - Processes.parent_process_id risk_score: 9 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml b/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml index 90dc1a35cb..e3ec58909f 100644 --- a/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml +++ b/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml @@ -73,7 +73,3 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_possible_ssh_key_file_creation.yml b/detections/endpoint/linux_possible_ssh_key_file_creation.yml index 119678e666..6945aed5fc 100644 --- a/detections/endpoint/linux_possible_ssh_key_file_creation.yml +++ b/detections/endpoint/linux_possible_ssh_key_file_creation.yml @@ -68,6 +68,3 @@ tags: - Filesystem.file_path risk_score: 36 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_preload_hijack_library_calls.yml b/detections/endpoint/linux_preload_hijack_library_calls.yml index f6c34e4c35..97c79b0d14 100644 --- a/detections/endpoint/linux_preload_hijack_library_calls.yml +++ b/detections/endpoint/linux_preload_hijack_library_calls.yml @@ -70,7 +70,3 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_service_file_created_in_systemd_directory.yml b/detections/endpoint/linux_service_file_created_in_systemd_directory.yml index 78d8928eaf..999fecc6a8 100644 --- a/detections/endpoint/linux_service_file_created_in_systemd_directory.yml +++ b/detections/endpoint/linux_service_file_created_in_systemd_directory.yml @@ -75,6 +75,3 @@ tags: - Filesystem.file_path risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_service_restarted.yml b/detections/endpoint/linux_service_restarted.yml index 9a3df28e33..f8791b39ec 100644 --- a/detections/endpoint/linux_service_restarted.yml +++ b/detections/endpoint/linux_service_restarted.yml @@ -75,7 +75,3 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_service_started_or_enabled.yml b/detections/endpoint/linux_service_started_or_enabled.yml index d8f31ee12e..f49665180d 100644 --- a/detections/endpoint/linux_service_started_or_enabled.yml +++ b/detections/endpoint/linux_service_started_or_enabled.yml @@ -75,7 +75,3 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_setuid_using_chmod_utility.yml b/detections/endpoint/linux_setuid_using_chmod_utility.yml index a6a0d817d1..9c0993d9d1 100644 --- a/detections/endpoint/linux_setuid_using_chmod_utility.yml +++ b/detections/endpoint/linux_setuid_using_chmod_utility.yml @@ -75,7 +75,3 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_setuid_using_setcap_utility.yml b/detections/endpoint/linux_setuid_using_setcap_utility.yml index 15f935c30b..a9b84716e8 100644 --- a/detections/endpoint/linux_setuid_using_setcap_utility.yml +++ b/detections/endpoint/linux_setuid_using_setcap_utility.yml @@ -76,7 +76,3 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/linux_sudoers_tmp_file_creation.yml b/detections/endpoint/linux_sudoers_tmp_file_creation.yml index 04ffef309c..1df4b0d961 100644 --- a/detections/endpoint/linux_sudoers_tmp_file_creation.yml +++ b/detections/endpoint/linux_sudoers_tmp_file_creation.yml @@ -69,6 +69,3 @@ tags: - Filesystem.file_path risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/linux_visudo_utility_execution.yml b/detections/endpoint/linux_visudo_utility_execution.yml index 14c435443f..4acdf38f55 100644 --- a/detections/endpoint/linux_visudo_utility_execution.yml +++ b/detections/endpoint/linux_visudo_utility_execution.yml @@ -72,7 +72,3 @@ tags: - Processes.parent_process_id risk_score: 16 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR diff --git a/detections/endpoint/logon_script_event_trigger_execution.yml b/detections/endpoint/logon_script_event_trigger_execution.yml index 17c7454063..65f38e8145 100644 --- a/detections/endpoint/logon_script_event_trigger_execution.yml +++ b/detections/endpoint/logon_script_event_trigger_execution.yml @@ -65,5 +65,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml index f984d5eae3..42549ef692 100644 --- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml +++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml @@ -79,3 +79,6 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml index dd40105004..fe4b645d92 100644 --- a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml +++ b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml @@ -77,3 +77,6 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml index b49f8879df..42116b7fcf 100644 --- a/detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml @@ -79,3 +79,6 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/modify_acl_permission_to_files_or_folder.yml b/detections/endpoint/modify_acl_permission_to_files_or_folder.yml index 5f575a26b8..a29a96315d 100644 --- a/detections/endpoint/modify_acl_permission_to_files_or_folder.yml +++ b/detections/endpoint/modify_acl_permission_to_files_or_folder.yml @@ -63,6 +63,5 @@ tags: risk_score: 32 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml index ffe8f6cdf9..9403ebd3ab 100644 --- a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml +++ b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml @@ -69,3 +69,6 @@ tags: - Processes.user risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml index 9dce88003b..2b7e0f2981 100644 --- a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml +++ b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml @@ -72,3 +72,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/msmpeng_application_dll_side_loading.yml b/detections/endpoint/msmpeng_application_dll_side_loading.yml index fdb3cb30d3..34457fed7e 100644 --- a/detections/endpoint/msmpeng_application_dll_side_loading.yml +++ b/detections/endpoint/msmpeng_application_dll_side_loading.yml @@ -48,6 +48,5 @@ tags: - Filesystem.file_path security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/net_profiler_uac_bypass.yml b/detections/endpoint/net_profiler_uac_bypass.yml index b557812d7a..4499d7d39c 100644 --- a/detections/endpoint/net_profiler_uac_bypass.yml +++ b/detections/endpoint/net_profiler_uac_bypass.yml @@ -63,5 +63,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/nishang_powershelltcponeline.yml b/detections/endpoint/nishang_powershelltcponeline.yml index 5c14627938..58b0aec14a 100644 --- a/detections/endpoint/nishang_powershelltcponeline.yml +++ b/detections/endpoint/nishang_powershelltcponeline.yml @@ -72,3 +72,6 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/nltest_domain_trust_discovery.yml b/detections/endpoint/nltest_domain_trust_discovery.yml index 82c1470541..cd02725e6f 100644 --- a/detections/endpoint/nltest_domain_trust_discovery.yml +++ b/detections/endpoint/nltest_domain_trust_discovery.yml @@ -76,5 +76,5 @@ tags: risk_score: 15 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/ntdsutil_export_ntds.yml b/detections/endpoint/ntdsutil_export_ntds.yml index 35929d61ae..6cb6da82e1 100644 --- a/detections/endpoint/ntdsutil_export_ntds.yml +++ b/detections/endpoint/ntdsutil_export_ntds.yml @@ -79,5 +79,5 @@ tags: risk_score: 50 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_application_spawn_regsvr32_process.yml b/detections/endpoint/office_application_spawn_regsvr32_process.yml index 8b21933453..8af912be94 100644 --- a/detections/endpoint/office_application_spawn_regsvr32_process.yml +++ b/detections/endpoint/office_application_spawn_regsvr32_process.yml @@ -67,3 +67,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_application_spawn_rundll32_process.yml b/detections/endpoint/office_application_spawn_rundll32_process.yml index c2d07499f1..bf01bade6d 100644 --- a/detections/endpoint/office_application_spawn_rundll32_process.yml +++ b/detections/endpoint/office_application_spawn_rundll32_process.yml @@ -68,3 +68,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_document_spawned_child_process_to_download.yml b/detections/endpoint/office_document_spawned_child_process_to_download.yml index 79eac14dc6..b4eaba8fd6 100644 --- a/detections/endpoint/office_document_spawned_child_process_to_download.yml +++ b/detections/endpoint/office_document_spawned_child_process_to_download.yml @@ -67,3 +67,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawn_cmd_process.yml b/detections/endpoint/office_product_spawn_cmd_process.yml index 5745a10a4a..5103e3ac08 100644 --- a/detections/endpoint/office_product_spawn_cmd_process.yml +++ b/detections/endpoint/office_product_spawn_cmd_process.yml @@ -73,3 +73,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawning_bitsadmin.yml b/detections/endpoint/office_product_spawning_bitsadmin.yml index dd2294d824..6be37ad6a7 100644 --- a/detections/endpoint/office_product_spawning_bitsadmin.yml +++ b/detections/endpoint/office_product_spawning_bitsadmin.yml @@ -78,3 +78,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawning_certutil.yml b/detections/endpoint/office_product_spawning_certutil.yml index 0e0d0e94fe..239f5a9aba 100644 --- a/detections/endpoint/office_product_spawning_certutil.yml +++ b/detections/endpoint/office_product_spawning_certutil.yml @@ -78,3 +78,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawning_mshta.yml b/detections/endpoint/office_product_spawning_mshta.yml index d838666728..b79ecc5484 100644 --- a/detections/endpoint/office_product_spawning_mshta.yml +++ b/detections/endpoint/office_product_spawning_mshta.yml @@ -78,3 +78,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml b/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml index e2dfd12596..267abd4696 100644 --- a/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml +++ b/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml @@ -81,3 +81,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawning_wmic.yml b/detections/endpoint/office_product_spawning_wmic.yml index efd315eb71..05da4fb63e 100644 --- a/detections/endpoint/office_product_spawning_wmic.yml +++ b/detections/endpoint/office_product_spawning_wmic.yml @@ -80,3 +80,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_spawning_control.yml b/detections/endpoint/office_spawning_control.yml index af3edb56e4..cb9db8f1c2 100644 --- a/detections/endpoint/office_spawning_control.yml +++ b/detections/endpoint/office_spawning_control.yml @@ -85,3 +85,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index 751021d879..1099322ffc 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -70,12 +70,5 @@ tags: risk_score: 72 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_nix - - Splunk_TA_ossec - - Splunk_TA_bit9-carbonblack - - splunk_ta_o365 - - Splunk_TA_sophos - - Splunk_TA_cyberark - - Splunk_TA_windows - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/permission_modification_using_takeown_app.yml b/detections/endpoint/permission_modification_using_takeown_app.yml index 4261e53f6c..7d72e1276e 100644 --- a/detections/endpoint/permission_modification_using_takeown_app.yml +++ b/detections/endpoint/permission_modification_using_takeown_app.yml @@ -66,5 +66,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/ping_sleep_batch_command.yml b/detections/endpoint/ping_sleep_batch_command.yml index 395f97aa89..31e9370fba 100644 --- a/detections/endpoint/ping_sleep_batch_command.yml +++ b/detections/endpoint/ping_sleep_batch_command.yml @@ -79,3 +79,6 @@ tags: - Processes.parent_process_id risk_score: 36 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml index 0d2c0a5cfe..0605b31412 100644 --- a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml +++ b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 45 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/potentially_malicious_code_on_commandline.yml b/detections/endpoint/potentially_malicious_code_on_commandline.yml index 379e346161..c71df93a3c 100644 --- a/detections/endpoint/potentially_malicious_code_on_commandline.yml +++ b/detections/endpoint/potentially_malicious_code_on_commandline.yml @@ -7,36 +7,35 @@ type: Anomaly datamodel: - Endpoint description: The following analytic uses a pretrained machine learning text classifier - to detect potentially malicious commandlines. The model identifies unusual - combinations of keywords found in samples of commandlines where adversaries executed - powershell code, primarily for C2 communication. For example, adversaries will leverage - IO capabilities such as "streamreader" and "webclient", threading capabilties such as - "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic + to detect potentially malicious commandlines. The model identifies unusual combinations + of keywords found in samples of commandlines where adversaries executed powershell + code, primarily for C2 communication. For example, adversaries will leverage IO + capabilities such as "streamreader" and "webclient", threading capabilties such + as "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic operations like "computehash". Although observing one of these keywords in a commandline script is possible, combinations of keywords observed in attack data are not typically - found in normal usage of the commandline. The model will output a score where all values - above zero are suspicious, anything greater than one particularly so. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime - max(_time) as lastTime from datamodel="Endpoint.Processes" by - Processes.parent_process_name Processes.process_name Processes.process - Processes.user Processes.dest | `drop_dm_object_name(Processes)` | where - len(process) > 200 | `potentially_malicious_code_on_cmdline_tokenize_score` | - apply unusual_commandline_detection | eval score=''predicted(unusual_cmdline_logits)'', - process=orig_process | fields - unusual_cmdline* predicted(unusual_cmdline_logits) orig_process | - where score > 0.5 | `security_content_ctime(firstTime)` | - `security_content_ctime(lastTime)` | `potentially_malicious_code_on_commandline_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting logs - with the process name, parent process, and command-line executions from your endpoints. - If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. You - will also need to install the Machine Learning Toolkit version 5.3 or above to apply - the pretrained model. -known_false_positives: This model is an anomaly detector that identifies usage of APIs - and scripting constructs that are correllated with malicious activity. These APIs and - scripting constructs are part of the programming langauge and advanced scripts may - generate false positives. + found in normal usage of the commandline. The model will output a score where all + values above zero are suspicious, anything greater than one particularly so. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel="Endpoint.Processes" by Processes.parent_process_name + Processes.process_name Processes.process Processes.user Processes.dest | `drop_dm_object_name(Processes)` | + where len(process) > 200 | `potentially_malicious_code_on_cmdline_tokenize_score` + | apply unusual_commandline_detection | eval score=''predicted(unusual_cmdline_logits)'', + process=orig_process | fields - unusual_cmdline* predicted(unusual_cmdline_logits) + orig_process | where score > 0.5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `potentially_malicious_code_on_commandline_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. You will also need to install the Machine Learning Toolkit version 5.3 + or above to apply the pretrained model. +known_false_positives: This model is an anomaly detector that identifies usage of + APIs and scripting constructs that are correllated with malicious activity. These + APIs and scripting constructs are part of the programming langauge and advanced + scripts may generate false positives. references: - - https://attack.mitre.org/techniques/T1059/003/ - - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md +- https://attack.mitre.org/techniques/T1059/003/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md tags: analytic_story: - Suspicious Command-Line Executions @@ -63,15 +62,19 @@ tags: confidence: 20 risk_score: 12 context: - - source:endpoint - - stage:Execution - message: Unusual command-line execution with hallmarks of malicious activity run by $user$ found on $dest$ with commandline $process$ + - source:endpoint + - stage:Execution + message: Unusual command-line execution with hallmarks of malicious activity run + by $user$ found on $dest$ with commandline $process$ observable: - - name: dest - type: Hostname - role: - - Victim - - name: user - type: User - role: - - Victim \ No newline at end of file + - name: dest + type: Hostname + role: + - Victim + - name: user + type: User + role: + - Victim + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/powershell_disable_security_monitoring.yml b/detections/endpoint/powershell_disable_security_monitoring.yml index 407a386845..ebcae8148a 100644 --- a/detections/endpoint/powershell_disable_security_monitoring.yml +++ b/detections/endpoint/powershell_disable_security_monitoring.yml @@ -55,3 +55,6 @@ tags: - Processes.process_path - Processes.parent_process_id security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/powershell_start_bitstransfer.yml b/detections/endpoint/powershell_start_bitstransfer.yml index cc0796f0d5..da8e09ed4e 100644 --- a/detections/endpoint/powershell_start_bitstransfer.yml +++ b/detections/endpoint/powershell_start_bitstransfer.yml @@ -76,3 +76,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml index f69506cda0..614e344e72 100644 --- a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml +++ b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml @@ -67,5 +67,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml index 83da35da82..dc64f62336 100644 --- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml +++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml @@ -81,6 +81,5 @@ tags: risk_score: 63 security_domain: network cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/process_execution_via_wmi.yml b/detections/endpoint/process_execution_via_wmi.yml index d75597a1ca..03fa648f65 100644 --- a/detections/endpoint/process_execution_via_wmi.yml +++ b/detections/endpoint/process_execution_via_wmi.yml @@ -72,6 +72,5 @@ tags: risk_score: 49 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/process_kill_base_on_file_path.yml b/detections/endpoint/process_kill_base_on_file_path.yml index 1f31e2837d..acbe92e60c 100644 --- a/detections/endpoint/process_kill_base_on_file_path.yml +++ b/detections/endpoint/process_kill_base_on_file_path.yml @@ -70,3 +70,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index 2d5181b2a0..a64175a7ab 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -77,5 +77,5 @@ tags: risk_score: 42 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml index 9d4d46991d..7092068f7c 100644 --- a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml +++ b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml @@ -54,3 +54,6 @@ tags: - Processes.process_path - Processes.parent_process_id security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml index 03417bcd68..cd11cae2a9 100644 --- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml +++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml @@ -80,6 +80,5 @@ tags: risk_score: 45 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 1d0db92fda..d9605fc44a 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -90,5 +90,5 @@ tags: risk_score: 76 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml index deda9cfcc4..e84f0b5acd 100644 --- a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml +++ b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 36 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml index 8b71b94ee8..96faeb15ae 100644 --- a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml +++ b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml @@ -86,3 +86,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remcos_client_registry_install_entry.yml b/detections/endpoint/remcos_client_registry_install_entry.yml index 9e3d861d01..66bb43f8e3 100644 --- a/detections/endpoint/remcos_client_registry_install_entry.yml +++ b/detections/endpoint/remcos_client_registry_install_entry.yml @@ -54,3 +54,6 @@ tags: - Registry.user risk_score: 90 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml index 4732042e6b..61725b63c9 100644 --- a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml @@ -67,3 +67,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml index b26ed0eae8..02db0a3567 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml @@ -68,3 +68,6 @@ tags: - Processes.parent_process_id risk_score: 45 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml index 0cf0e762c5..bc7fe55d99 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml @@ -66,3 +66,6 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_process_instantiation_via_wmi.yml b/detections/endpoint/remote_process_instantiation_via_wmi.yml index ea0ab2981e..580c9a8749 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi.yml @@ -82,3 +82,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml index aa04af220f..f1b824cd55 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml @@ -66,3 +66,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_system_discovery_with_wmic.yml b/detections/endpoint/remote_system_discovery_with_wmic.yml index 04ca65e585..0cffce5faf 100644 --- a/detections/endpoint/remote_system_discovery_with_wmic.yml +++ b/detections/endpoint/remote_system_discovery_with_wmic.yml @@ -65,3 +65,6 @@ tags: - Processes.parent_process_id risk_score: 15 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_wmi_command_attempt.yml b/detections/endpoint/remote_wmi_command_attempt.yml index 6322b3fe5e..e330bed723 100644 --- a/detections/endpoint/remote_wmi_command_attempt.yml +++ b/detections/endpoint/remote_wmi_command_attempt.yml @@ -77,5 +77,5 @@ tags: risk_score: 36 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/resize_shadowstorage_volume.yml b/detections/endpoint/resize_shadowstorage_volume.yml index f9a4e86e63..314d10d510 100644 --- a/detections/endpoint/resize_shadowstorage_volume.yml +++ b/detections/endpoint/resize_shadowstorage_volume.yml @@ -74,6 +74,5 @@ tags: risk_score: 72 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/revil_common_exec_parameter.yml b/detections/endpoint/revil_common_exec_parameter.yml index 34ca80dd8f..a197e5c84e 100644 --- a/detections/endpoint/revil_common_exec_parameter.yml +++ b/detections/endpoint/revil_common_exec_parameter.yml @@ -68,5 +68,5 @@ tags: risk_score: 54 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/revil_registry_entry.yml b/detections/endpoint/revil_registry_entry.yml index 5bd711e5d0..11ee8ad99f 100644 --- a/detections/endpoint/revil_registry_entry.yml +++ b/detections/endpoint/revil_registry_entry.yml @@ -66,5 +66,5 @@ tags: risk_score: 60 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml index f8acc400d0..f763971249 100644 --- a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml +++ b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml @@ -91,3 +91,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/rundll32_shimcache_flush.yml b/detections/endpoint/rundll32_shimcache_flush.yml index f299c462a3..1ea2ca7251 100644 --- a/detections/endpoint/rundll32_shimcache_flush.yml +++ b/detections/endpoint/rundll32_shimcache_flush.yml @@ -69,3 +69,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml index 2027ca3881..217638d28c 100644 --- a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml @@ -86,3 +86,6 @@ tags: - Processes.parent_process_id risk_score: 70 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/endpoint/rundll_loading_dll_by_ordinal.yml index 1a42db412b..92a26b1d19 100644 --- a/detections/endpoint/rundll_loading_dll_by_ordinal.yml +++ b/detections/endpoint/rundll_loading_dll_by_ordinal.yml @@ -76,3 +76,6 @@ tags: - Processes.parent_process_id risk_score: 70 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/ryuk_wake_on_lan_command.yml b/detections/endpoint/ryuk_wake_on_lan_command.yml index c0c1b085f8..296a40030e 100644 --- a/detections/endpoint/ryuk_wake_on_lan_command.yml +++ b/detections/endpoint/ryuk_wake_on_lan_command.yml @@ -74,5 +74,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/samsam_test_file_write.yml b/detections/endpoint/samsam_test_file_write.yml index d28121eff5..99697d458f 100644 --- a/detections/endpoint/samsam_test_file_write.yml +++ b/detections/endpoint/samsam_test_file_write.yml @@ -63,11 +63,5 @@ tags: risk_score: 12 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_nix - - Splunk_TA_bit9-carbonblack - - splunk_ta_o365 - - Splunk_TA_sophos - - Splunk_TA_cyberark - - Splunk_TA_windows - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index f13355af48..3fb235bf4d 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -79,6 +79,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml index dc1b4e2e5c..b2c0f51639 100644 --- a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml +++ b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml @@ -68,3 +68,6 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index 426e2d0265..d22c63effc 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -72,5 +72,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml index 534990ea49..fdd2584d25 100644 --- a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml +++ b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml @@ -65,3 +65,6 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/schtasks_run_task_on_demand.yml b/detections/endpoint/schtasks_run_task_on_demand.yml index 0edf0ce49f..4ee325ba44 100644 --- a/detections/endpoint/schtasks_run_task_on_demand.yml +++ b/detections/endpoint/schtasks_run_task_on_demand.yml @@ -67,6 +67,5 @@ tags: risk_score: 48 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index 9953a4056f..ccf5e0e562 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -74,6 +74,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index 3fc0c0b660..5d1d6016f5 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -71,6 +71,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml index 1954c0955e..e2aaa3e2c0 100644 --- a/detections/endpoint/screensaver_event_trigger_execution.yml +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -68,5 +68,5 @@ tags: risk_score: 72 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/script_execution_via_wmi.yml b/detections/endpoint/script_execution_via_wmi.yml index 9fdb3c319d..f3b88b6a4c 100644 --- a/detections/endpoint/script_execution_via_wmi.yml +++ b/detections/endpoint/script_execution_via_wmi.yml @@ -66,9 +66,5 @@ tags: risk_score: 36 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_nix - - Splunk_TA_bit9-carbonblack - - Splunk_TA_windows - - Splunk_TA_CrowdStrike_FDR - - Splunk_TA_cyberark_epm + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/sdclt_uac_bypass.yml b/detections/endpoint/sdclt_uac_bypass.yml index 2c07e09f51..ce90d93ae7 100644 --- a/detections/endpoint/sdclt_uac_bypass.yml +++ b/detections/endpoint/sdclt_uac_bypass.yml @@ -63,5 +63,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/sdelete_application_execution.yml b/detections/endpoint/sdelete_application_execution.yml index 1d8219f0c5..e6d69bc6db 100644 --- a/detections/endpoint/sdelete_application_execution.yml +++ b/detections/endpoint/sdelete_application_execution.yml @@ -73,3 +73,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index 005f3fb6f4..1b46174d18 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -69,5 +69,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml index 2f456df538..1695b3c2d7 100644 --- a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml +++ b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml @@ -106,3 +106,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/services_escalate_exe.yml b/detections/endpoint/services_escalate_exe.yml index d498e06881..67a821a3cc 100644 --- a/detections/endpoint/services_escalate_exe.yml +++ b/detections/endpoint/services_escalate_exe.yml @@ -76,5 +76,5 @@ tags: risk_score: 76 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml index 3761b132b9..410184734c 100644 --- a/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml @@ -79,3 +79,6 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index ab3d4acfd4..f0a0397da4 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -72,5 +72,5 @@ tags: risk_score: 48 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index 222f9046cc..c2b6652199 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -69,6 +69,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index 1a792d52c7..41eaafaaab 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -63,9 +63,3 @@ tags: - All_Changes.dest risk_score: 63 security_domain: access - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_microsoft-cloudservices - - Splunk_TA_rsa-securid - - Splunk_TA_aws-kinesis-firehose - - Splunk_TA_cyberark diff --git a/detections/endpoint/silentcleanup_uac_bypass.yml b/detections/endpoint/silentcleanup_uac_bypass.yml index d486a01bb7..1f0a4a2a8f 100644 --- a/detections/endpoint/silentcleanup_uac_bypass.yml +++ b/detections/endpoint/silentcleanup_uac_bypass.yml @@ -61,5 +61,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index a7bcd3d9c5..91a8047c4b 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -67,9 +67,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_nix - - Splunk_TA_bit9-carbonblack - - Splunk_TA_windows - - Splunk_TA_CrowdStrike_FDR - - Splunk_TA_cyberark_epm + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/slui_runas_elevated.yml b/detections/endpoint/slui_runas_elevated.yml index d966f6345d..5d132649be 100644 --- a/detections/endpoint/slui_runas_elevated.yml +++ b/detections/endpoint/slui_runas_elevated.yml @@ -73,5 +73,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/slui_spawning_a_process.yml b/detections/endpoint/slui_spawning_a_process.yml index 74ea2763af..2da907b586 100644 --- a/detections/endpoint/slui_spawning_a_process.yml +++ b/detections/endpoint/slui_spawning_a_process.yml @@ -71,5 +71,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/spoolsv_spawning_rundll32.yml b/detections/endpoint/spoolsv_spawning_rundll32.yml index 75048de2bf..103f405eab 100644 --- a/detections/endpoint/spoolsv_spawning_rundll32.yml +++ b/detections/endpoint/spoolsv_spawning_rundll32.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 72 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml index 630db87662..fb8f31dbf1 100644 --- a/detections/endpoint/spoolsv_writing_a_dll.yml +++ b/detections/endpoint/spoolsv_writing_a_dll.yml @@ -82,8 +82,5 @@ tags: risk_score: 72 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_nix - - Splunk_TA_bit9-carbonblack - - Splunk_TA_windows - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/start_up_during_safe_mode_boot.yml b/detections/endpoint/start_up_during_safe_mode_boot.yml index 207d1b46df..cb9cdf47cb 100644 --- a/detections/endpoint/start_up_during_safe_mode_boot.yml +++ b/detections/endpoint/start_up_during_safe_mode_boot.yml @@ -60,5 +60,5 @@ tags: risk_score: 42 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_copy_on_system32.yml b/detections/endpoint/suspicious_copy_on_system32.yml index 3e695150a0..ff152f7d63 100644 --- a/detections/endpoint/suspicious_copy_on_system32.yml +++ b/detections/endpoint/suspicious_copy_on_system32.yml @@ -72,3 +72,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml b/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml index 03ad024c6e..7abaea2239 100644 --- a/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml @@ -74,3 +74,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml b/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml index b52fb89260..42dd64b120 100644 --- a/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml @@ -73,3 +73,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml index 2c5ba047e9..34c55dba23 100644 --- a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml +++ b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml @@ -69,3 +69,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml index be0e067ced..4731d99a13 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml @@ -75,3 +75,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml index 54626c3ca3..f444c4817f 100644 --- a/detections/endpoint/suspicious_msbuild_path.yml +++ b/detections/endpoint/suspicious_msbuild_path.yml @@ -86,3 +86,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml index b95320d0c2..a19660278e 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/endpoint/suspicious_msbuild_rename.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_msbuild_spawn.yml b/detections/endpoint/suspicious_msbuild_spawn.yml index 5446e67271..34350db21f 100644 --- a/detections/endpoint/suspicious_msbuild_spawn.yml +++ b/detections/endpoint/suspicious_msbuild_spawn.yml @@ -81,3 +81,6 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index 40514b30ee..aa81646a00 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -80,5 +80,5 @@ tags: risk_score: 40 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_mshta_spawn.yml b/detections/endpoint/suspicious_mshta_spawn.yml index c90b293976..ab2369d2d8 100644 --- a/detections/endpoint/suspicious_mshta_spawn.yml +++ b/detections/endpoint/suspicious_mshta_spawn.yml @@ -75,3 +75,6 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index b87fadbac2..3e6a501fb7 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -75,5 +75,5 @@ tags: risk_score: 35 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index 31e7dff7ff..be3bd9b497 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -79,6 +79,5 @@ tags: risk_score: 35 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml index 6884c73b1f..c991ace093 100644 --- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml +++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml @@ -88,3 +88,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml index 25aadbe349..4a997aa0da 100644 --- a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml +++ b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml @@ -88,3 +88,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_rundll32_plugininit.yml b/detections/endpoint/suspicious_rundll32_plugininit.yml index 838bd7e76f..32dfa13f81 100644 --- a/detections/endpoint/suspicious_rundll32_plugininit.yml +++ b/detections/endpoint/suspicious_rundll32_plugininit.yml @@ -69,3 +69,6 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_rundll32_startw.yml b/detections/endpoint/suspicious_rundll32_startw.yml index 222729300e..4c1913d7e7 100644 --- a/detections/endpoint/suspicious_rundll32_startw.yml +++ b/detections/endpoint/suspicious_rundll32_startw.yml @@ -89,3 +89,6 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml b/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml index decaa12b61..d52144e124 100644 --- a/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml @@ -87,3 +87,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index 6e5616636d..5c7a49bbf8 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -74,5 +74,5 @@ tags: risk_score: 35 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml b/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml index 6b9c3a6cd7..c208bf6831 100644 --- a/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml @@ -74,3 +74,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index 1b00a621a3..a5acbabdb0 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -78,6 +78,5 @@ tags: risk_score: 28 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/system_information_discovery_detection.yml b/detections/endpoint/system_information_discovery_detection.yml index f098533737..edc8e672bf 100644 --- a/detections/endpoint/system_information_discovery_detection.yml +++ b/detections/endpoint/system_information_discovery_detection.yml @@ -67,9 +67,5 @@ tags: risk_score: 15 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_nix - - Splunk_TA_bit9-carbonblack - - Splunk_TA_windows - - Splunk_TA_CrowdStrike_FDR - - Splunk_TA_cyberark_epm + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index 0bf3f0e869..517748d29e 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -83,6 +83,5 @@ tags: risk_score: 49 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml index 5e305337a5..ce45d2aeb6 100644 --- a/detections/endpoint/time_provider_persistence_registry.yml +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -68,5 +68,5 @@ tags: risk_score: 80 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/unified_messaging_service_spawning_a_process.yml b/detections/endpoint/unified_messaging_service_spawning_a_process.yml index 875bb25a4e..b181f06201 100644 --- a/detections/endpoint/unified_messaging_service_spawning_a_process.yml +++ b/detections/endpoint/unified_messaging_service_spawning_a_process.yml @@ -72,5 +72,5 @@ tags: risk_score: 56 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/uninstall_app_using_msiexec.yml b/detections/endpoint/uninstall_app_using_msiexec.yml index c554e89da5..a1c12f056e 100644 --- a/detections/endpoint/uninstall_app_using_msiexec.yml +++ b/detections/endpoint/uninstall_app_using_msiexec.yml @@ -66,5 +66,5 @@ tags: risk_score: 30 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index 35dc22a6ea..e9e40dac75 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -66,6 +66,5 @@ tags: risk_score: 45 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/usn_journal_deletion.yml b/detections/endpoint/usn_journal_deletion.yml index 24034384ed..7dc9caaf7c 100644 --- a/detections/endpoint/usn_journal_deletion.yml +++ b/detections/endpoint/usn_journal_deletion.yml @@ -71,5 +71,5 @@ tags: risk_score: 45 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/vbscript_execution_using_wscript_app.yml b/detections/endpoint/vbscript_execution_using_wscript_app.yml index 0f6d7fd64c..02077abbf5 100644 --- a/detections/endpoint/vbscript_execution_using_wscript_app.yml +++ b/detections/endpoint/vbscript_execution_using_wscript_app.yml @@ -72,3 +72,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml index bc62aa7a0f..ba04b3a96f 100644 --- a/detections/endpoint/w3wp_spawning_shell.yml +++ b/detections/endpoint/w3wp_spawning_shell.yml @@ -80,3 +80,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wbadmin_delete_system_backups.yml b/detections/endpoint/wbadmin_delete_system_backups.yml index 56af59a5e7..c915ee1e6e 100644 --- a/detections/endpoint/wbadmin_delete_system_backups.yml +++ b/detections/endpoint/wbadmin_delete_system_backups.yml @@ -65,6 +65,5 @@ tags: risk_score: 15 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml b/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml index a11923aa97..87a1b9cf50 100644 --- a/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml +++ b/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml @@ -66,3 +66,6 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wget_download_and_bash_execution.yml b/detections/endpoint/wget_download_and_bash_execution.yml index 41141ae6e7..4d1a88f5dc 100644 --- a/detections/endpoint/wget_download_and_bash_execution.yml +++ b/detections/endpoint/wget_download_and_bash_execution.yml @@ -78,6 +78,3 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/endpoint/windows_adfind_exe.yml b/detections/endpoint/windows_adfind_exe.yml index e16c0d6e7b..6eafa71e1e 100644 --- a/detections/endpoint/windows_adfind_exe.yml +++ b/detections/endpoint/windows_adfind_exe.yml @@ -59,5 +59,5 @@ tags: - Processes.parent_process_id security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index f8c22e9a38..31e9590167 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -86,3 +86,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_curl_upload_to_remote_destination.yml b/detections/endpoint/windows_curl_upload_to_remote_destination.yml index 29a94ae877..f07fd2ef2e 100644 --- a/detections/endpoint/windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/windows_curl_upload_to_remote_destination.yml @@ -94,3 +94,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_defender_exclusion_registry_entry.yml b/detections/endpoint/windows_defender_exclusion_registry_entry.yml index 6e8dfa528a..f5cba30004 100644 --- a/detections/endpoint/windows_defender_exclusion_registry_entry.yml +++ b/detections/endpoint/windows_defender_exclusion_registry_entry.yml @@ -75,3 +75,6 @@ tags: - Registry.registry_value_data risk_score: 64 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_disableantispyware_reg.yml b/detections/endpoint/windows_disableantispyware_reg.yml index 0bf3326238..59eff047c9 100644 --- a/detections/endpoint/windows_disableantispyware_reg.yml +++ b/detections/endpoint/windows_disableantispyware_reg.yml @@ -69,5 +69,5 @@ tags: risk_score: 24 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_dism_remove_defender.yml b/detections/endpoint/windows_dism_remove_defender.yml index d30b7eb169..a1d607addc 100644 --- a/detections/endpoint/windows_dism_remove_defender.yml +++ b/detections/endpoint/windows_dism_remove_defender.yml @@ -79,3 +79,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: access + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml index dcedbd87eb..e83ae62983 100644 --- a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml +++ b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml @@ -95,3 +95,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_installutil_credential_theft.yml b/detections/endpoint/windows_installutil_credential_theft.yml index 11b50baa38..ed812e47c8 100644 --- a/detections/endpoint/windows_installutil_credential_theft.yml +++ b/detections/endpoint/windows_installutil_credential_theft.yml @@ -89,3 +89,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_installutil_in_non_standard_path.yml b/detections/endpoint/windows_installutil_in_non_standard_path.yml index 1388db4a62..e353d99ecb 100644 --- a/detections/endpoint/windows_installutil_in_non_standard_path.yml +++ b/detections/endpoint/windows_installutil_in_non_standard_path.yml @@ -90,3 +90,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_installutil_uninstall_option.yml b/detections/endpoint/windows_installutil_uninstall_option.yml index 804cb45e00..800e5e9634 100644 --- a/detections/endpoint/windows_installutil_uninstall_option.yml +++ b/detections/endpoint/windows_installutil_uninstall_option.yml @@ -96,3 +96,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_installutil_url_in_command_line.yml b/detections/endpoint/windows_installutil_url_in_command_line.yml index 6e9e84ed39..0da38ed8f5 100644 --- a/detections/endpoint/windows_installutil_url_in_command_line.yml +++ b/detections/endpoint/windows_installutil_url_in_command_line.yml @@ -92,3 +92,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_nirsoft_advancedrun.yml b/detections/endpoint/windows_nirsoft_advancedrun.yml index 9e8d2015e3..e1497a56d8 100644 --- a/detections/endpoint/windows_nirsoft_advancedrun.yml +++ b/detections/endpoint/windows_nirsoft_advancedrun.yml @@ -83,3 +83,6 @@ tags: - Processes.parent_process_id risk_score: 60 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml index d94b7011e3..3dff4b9d7a 100644 --- a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml +++ b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml @@ -79,3 +79,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml index ee54cbec60..6ccd7f379c 100644 --- a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml +++ b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml @@ -67,3 +67,6 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml index bf0a3f099e..bdf5d5a363 100644 --- a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml +++ b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml @@ -65,3 +65,6 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/winhlp32_spawning_a_process.yml b/detections/endpoint/winhlp32_spawning_a_process.yml index 26f1b008ed..776550da9f 100644 --- a/detections/endpoint/winhlp32_spawning_a_process.yml +++ b/detections/endpoint/winhlp32_spawning_a_process.yml @@ -86,3 +86,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/winword_spawning_cmd.yml b/detections/endpoint/winword_spawning_cmd.yml index 79ab9fdff3..a53d2a37cd 100644 --- a/detections/endpoint/winword_spawning_cmd.yml +++ b/detections/endpoint/winword_spawning_cmd.yml @@ -79,3 +79,6 @@ tags: - Processes.parent_process_id risk_score: 70 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/winword_spawning_powershell.yml b/detections/endpoint/winword_spawning_powershell.yml index 27bf1fe98d..e1b7ef5f9e 100644 --- a/detections/endpoint/winword_spawning_powershell.yml +++ b/detections/endpoint/winword_spawning_powershell.yml @@ -81,3 +81,6 @@ tags: - Processes.parent_process_id risk_score: 70 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wmic_xsl_execution_via_url.yml b/detections/endpoint/wmic_xsl_execution_via_url.yml index 083857a0c6..9d24ed93dc 100644 --- a/detections/endpoint/wmic_xsl_execution_via_url.yml +++ b/detections/endpoint/wmic_xsl_execution_via_url.yml @@ -84,3 +84,6 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml index e97f6960b8..6c10241917 100644 --- a/detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml @@ -78,3 +78,6 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml index 71b9b9c4e9..87aece9016 100644 --- a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml +++ b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml @@ -78,3 +78,6 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml index f7a2261b11..48049758dc 100644 --- a/detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml @@ -79,3 +79,6 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wsreset_uac_bypass.yml b/detections/endpoint/wsreset_uac_bypass.yml index 75b25a90d1..f9f88abf71 100644 --- a/detections/endpoint/wsreset_uac_bypass.yml +++ b/detections/endpoint/wsreset_uac_bypass.yml @@ -62,5 +62,5 @@ tags: risk_score: 63 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/xsl_script_execution_with_wmic.yml b/detections/endpoint/xsl_script_execution_with_wmic.yml index 4c96db18e3..faab307475 100644 --- a/detections/endpoint/xsl_script_execution_with_wmic.yml +++ b/detections/endpoint/xsl_script_execution_with_wmic.yml @@ -78,5 +78,5 @@ tags: risk_score: 49 security_domain: endpoint cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/experimental/endpoint/print_processor_registry_autostart.yml b/detections/experimental/endpoint/print_processor_registry_autostart.yml index 48e2c132e1..bb3b2100fd 100644 --- a/detections/experimental/endpoint/print_processor_registry_autostart.yml +++ b/detections/experimental/endpoint/print_processor_registry_autostart.yml @@ -67,6 +67,3 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack diff --git a/detections/network/dns_query_length_with_high_standard_deviation.yml b/detections/network/dns_query_length_with_high_standard_deviation.yml index 151e3d36c3..a0505fe1c8 100644 --- a/detections/network/dns_query_length_with_high_standard_deviation.yml +++ b/detections/network/dns_query_length_with_high_standard_deviation.yml @@ -67,7 +67,5 @@ tags: risk_score: 56 security_domain: network cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_isc-bind - - Splunk_TA_CrowdStrike_FDR - - Splunk_TA_infoblox + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/security_content_automation/detection_ta_mapping.yml b/security_content_automation/detection_ta_mapping.yml index 33ee099a45..cdfe79fcac 100644 --- a/security_content_automation/detection_ta_mapping.yml +++ b/security_content_automation/detection_ta_mapping.yml @@ -34,67 +34,205 @@ abnormally_high_number_of_cloud_security_group_api_calls: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce +account_discovery_with_net_app: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon active_setup_registry_autostart: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -add_defaultuser_and_password_in_registr: + - Splunk_TA_microsoft_sysmon +add_defaultuser_and_password_in_registry: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -allow_inbound_traffic_by_firewall_rule_registr: + - Splunk_TA_microsoft_sysmon +add_or_set_windows_defender_exclusion: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +allow_file_and_printing_sharing_in_firewall: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +allow_inbound_traffic_by_firewall_rule_registry: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +allow_network_discovery_in_firewall: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon allow_operation_with_consent_admin: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon anomalous_usage_of_7zip: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +any_powershell_downloadfile: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +any_powershell_downloadstring: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon attacker_tools_on_endpoint: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_windows attempt_to_add_certificate_to_untrusted_store: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -auto_admin_logon_registry_entr: + - Splunk_TA_microsoft_sysmon +attempt_to_stop_security_service: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +attempted_credential_dump_from_registry_via_reg_exe: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +auto_admin_logon_registry_entry: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon batch_file_write_to_system32: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR bcdedit_command_back_to_normal_mode_boot: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon bcdedit_failure_recovery_modification: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR +bits_job_persistence: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +bitsadmin_download_file: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +certutil_download_with_urlcache_and_split_arguments: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +certutil_download_with_verifyctl_and_split_arguments: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +certutil_exe_certificate_extraction: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +certutil_with_decode_argument: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon change_default_file_association: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon change_to_safe_mode_with_network_config: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon check_elevated_cmd_using_whoami: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +clear_unallocated_sector_using_cipher_app: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +clop_common_exec_parameter: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon cloud_api_calls_from_previously_unseen_user_roles: cim_version: 5.0.0 supported_tas: @@ -146,7 +284,7 @@ cloud_instance_modified_with_previously_unseen_user: - Splunk_TA_cyberark - Splunk_TA_box - Splunk_TA_salesforce -cloud_provisioning_from_previously_unseen_cit: +cloud_provisioning_from_previously_unseen_city: cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose @@ -162,7 +300,7 @@ cloud_provisioning_from_previously_unseen_cit: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce -cloud_provisioning_from_previously_unseen_countr: +cloud_provisioning_from_previously_unseen_country: cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose @@ -208,120 +346,491 @@ cloud_provisioning_from_previously_unseen_region: - Splunk_TA_cisco-asa - Splunk_TA_infoblox - Splunk_TA_salesforce +cmd_echo_pipe___escalation: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +cmdline_tool_not_executed_in_cmd_shell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +conti_common_exec_parameter: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +control_loading_from_world_writable_directory: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +create_local_admin_accounts_using_net_exe: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +create_or_delete_windows_shares_using_net_exe: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +creation_of_shadow_copy: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +creation_of_shadow_copy_with_wmic_and_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +credential_dumping_via_copy_command_from_shadow_copy: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +credential_dumping_via_symlink_to_shadow_copy: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon curl_download_and_bash_execution: cim_version: 5.0.0 tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -detect_exchange_web_she: + - Splunk_TA_microsoft_sysmon +deleting_of_net_users: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +deleting_shadow_copies: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_azurehound_command_line_arguments: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_exchange_web_shell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR +detect_html_help_spawn_child_process: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_html_help_url_in_command_line: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_html_help_using_infotech_storage_handlers: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_mshta_inline_hta_execution: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_mshta_url_in_command_line: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_path_interception_by_creation_of_program_exe: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_processes_used_for_system_network_configuration_discovery: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_psexec_with_accepteula_flag: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_rclone_command_line_usage: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon detect_regasm_spawning_a_process: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +detect_regasm_with_no_command_line_arguments: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon detect_regsvcs_spawning_a_process: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +detect_regsvcs_with_no_command_line_arguments: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_regsvr32_application_control_bypass: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_rundll32_application_control_bypass___advpack: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_rundll32_application_control_bypass___setupapi: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_rundll32_application_control_bypass___syssetup: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +detect_rundll32_inline_hta_execution: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon detect_sharphound_command_line_arguments: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +detect_sharphound_usage: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon detect_use_of_cmd_exe_to_launch_script_interpreters: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -disable_amsi_through_registr: + - Splunk_TA_microsoft_sysmon +disable_amsi_through_registry: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -disable_etw_through_registr: + - Splunk_TA_microsoft_sysmon +disable_defender_antivirus_registry: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -disable_logs_using_wevtuti: + - Splunk_TA_microsoft_sysmon +disable_defender_blockatfirstseen_feature: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -disable_registry_too: + - Splunk_TA_microsoft_sysmon +disable_defender_enhanced_notification: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +disable_defender_mpengine_registry: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +disable_defender_spynet_reporting: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +disable_defender_submit_samples_consent_feature: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +disable_etw_through_registry: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +disable_logs_using_wevtutil: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +disable_registry_tool: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon disable_schedule_task: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR +disable_security_logs_using_minint_registry: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +disable_uac_remote_restriction: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon disable_windows_app_hotkeys: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon disable_windows_behavior_monitoring: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon disabling_cmd_application: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -disabling_controlpane: + - Splunk_TA_microsoft_sysmon +disabling_controlpanel: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +disabling_defender_services: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +disabling_firewall_with_netsh: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon disabling_folderoptions_windows_feature: cim_version: 5.0.0 tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +disabling_net_user_account: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon disabling_norun_windows_app: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -disabling_systemrestore_in_registr: + - Splunk_TA_microsoft_sysmon +disabling_systemrestore_in_registry: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon disabling_task_manager: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +dns_exfiltration_using_nslookup_app: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon dns_query_length_with_high_standard_deviation: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_isc-bind + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR - Splunk_TA_infoblox domain_account_discovery_with_net_app: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon domain_account_discovery_with_wmic: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -dsquery_domain_discover: + - Splunk_TA_microsoft_sysmon +domain_controller_discovery_with_nltest: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +dsquery_domain_discovery: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR +dump_lsass_via_comsvcs_dll: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon dump_lsass_via_procdump: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR +elevated_group_discovery_with_net: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +elevated_group_discovery_with_wmic: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon enable_rdp_in_other_port_number: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +enable_wdigest_uselogoncredential_registry: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +etw_registry_disabled: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon eventvwr_uac_bypass: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +excel_spawning_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon excessive_attempt_to_disable_services: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR excessive_number_of_distinct_processes_created_in_windows_temp_folder: cim_version: 5.0.0 @@ -330,13 +839,17 @@ excessive_number_of_distinct_processes_created_in_windows_temp_folder: tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm excessive_number_of_service_control_start_as_disabled: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon excessive_number_of_taskhost_processes: cim_version: 5.0.0 supported_tas: @@ -344,37 +857,74 @@ excessive_number_of_taskhost_processes: tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR +excessive_service_stop_attempt: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon excessive_usage_of_cacls_app: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR -excessive_usage_of_taskki: +excessive_usage_of_net_app: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +excessive_usage_of_taskkill: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR executables_or_script_creation_in_suspicious_path: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR execute_javascript_with_jscript_com_clsid: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon execution_of_file_with_multiple_extensions: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_windows +extraction_of_registry_hives: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon file_with_samsam_extension: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - splunk_ta_o365 - Splunk_TA_sophos - Splunk_TA_cyberark @@ -382,172 +932,126 @@ file_with_samsam_extension: - Splunk_TA_CrowdStrike_FDR firewall_allowed_program_enable: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon fodhelper_uac_bypass: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon fsutil_zeroing_file: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -get_aduserresultantpasswordpolicy_with_powershe: + - Splunk_TA_microsoft_sysmon +get_aduserresultantpasswordpolicy_with_powershell: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -get_domainpolicy_with_powershe: + - Splunk_TA_microsoft_sysmon +get_domainpolicy_with_powershell: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -get_domainuser_with_powershe: + - Splunk_TA_microsoft_sysmon +get_domaintrust_with_powershell: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -getwmiobject_ds_user_with_powershe: + - Splunk_TA_microsoft_sysmon +get_domainuser_with_powershell: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +get_foresttrust_with_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +getdomaincomputer_with_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +getdomaingroup_with_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +getwmiobject_ds_computer_with_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +getwmiobject_ds_group_with_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +getwmiobject_ds_user_with_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon hide_user_account_from_sign_in_screen: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon hiding_files_and_directories_with_attrib_exe: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_windows icacls_deny_command: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR icacls_grant_command: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR -inux_add_files_in_known_crontab_directories: +impacket_lateral_movement_commandline_parameters: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -inux_at_allow_config_file_creation: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -inux_at_application_execution: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_change_file_owner_to_root: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_doas_conf_file_creation: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -inux_doas_tool_execution: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_file_created_in_kernel_driver_director: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -inux_file_creation_in_init_boot_director: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -inux_file_creation_in_profile_director: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -inux_insert_kernel_module_using_insmod_utilit: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_install_kernel_module_using_modprobe_utilit: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_nopasswd_entry_in_sudoers_file: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_possible_access_or_modification_of_sshd_config_file: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_possible_access_to_credential_files: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_possible_access_to_sudoers_file: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_possible_append_command_to_at_allow_config_file: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_possible_append_command_to_profile_config_file: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_possible_ssh_key_file_creation: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -inux_preload_hijack_library_calls: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_service_file_created_in_systemd_director: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -inux_service_restarted: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_service_started_or_enabled: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_setuid_using_chmod_utilit: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_setuid_using_setcap_utilit: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -inux_sudoers_tmp_file_creation: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack -inux_visudo_utility_execution: - cim_version: 5.0.0 - tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_microsoft_sysmon java_class_file_download_by_java_user_agent: cim_version: 5.0.0 tas_with_cim_mapping: @@ -561,35 +1065,311 @@ java_class_file_download_by_java_user_agent: - Splunk_TA_cisco-wsa jscript_execution_using_cscript_app: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +linux_add_files_in_known_crontab_directories: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +linux_at_allow_config_file_creation: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +linux_at_application_execution: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_change_file_owner_to_root: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_doas_conf_file_creation: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +linux_doas_tool_execution: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_file_created_in_kernel_driver_directory: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +linux_file_creation_in_init_boot_directory: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +linux_file_creation_in_profile_directory: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +linux_insert_kernel_module_using_insmod_utility: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_install_kernel_module_using_modprobe_utility: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_java_spawning_shell: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +linux_nopasswd_entry_in_sudoers_file: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_possible_access_or_modification_of_sshd_config_file: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_possible_access_to_credential_files: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_possible_access_to_sudoers_file: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_possible_append_command_to_at_allow_config_file: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_possible_append_command_to_profile_config_file: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_possible_ssh_key_file_creation: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +linux_preload_hijack_library_calls: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_service_file_created_in_systemd_directory: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +linux_service_restarted: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_service_started_or_enabled: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_setuid_using_chmod_utility: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_setuid_using_setcap_utility: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +linux_sudoers_tmp_file_creation: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +linux_visudo_utility_execution: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +logon_script_event_trigger_execution: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +malicious_powershell_process___execution_policy_bypass: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +malicious_powershell_process_with_obfuscation_techniques: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +mmc_exe_lolbas_execution_process_spawn: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +modify_acl_permission_to_files_or_folder: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR +msbuild_suspicious_spawned_by_script_process: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +mshta_spawning_rundll32_or_regsvr32_process: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +msmpeng_application_dll_side_loading: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon + - Splunk_TA_CrowdStrike_FDR net_profiler_uac_bypass: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -nltest_domain_trust_discover: + - Splunk_TA_microsoft_sysmon +nishang_powershelltcponeline: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +nltest_domain_trust_discovery: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon ntdsutil_export_ntds: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -odify_acl_permission_to_files_or_folder: + - Splunk_TA_microsoft_sysmon +office_application_spawn_regsvr32_process: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -ogon_script_event_trigger_execution: + - Splunk_TA_microsoft_sysmon +office_application_spawn_rundll32_process: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +office_document_spawned_child_process_to_download: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +office_product_spawn_cmd_process: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +office_product_spawning_bitsadmin: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +office_product_spawning_certutil: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +office_product_spawning_mshta: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +office_product_spawning_rundll32_with_no_dll: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +office_product_spawning_wmic: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +office_spawning_control: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon overwriting_accessibility_binaries: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_ossec - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - splunk_ta_o365 - Splunk_TA_sophos - Splunk_TA_cyberark @@ -597,65 +1377,225 @@ overwriting_accessibility_binaries: - Splunk_TA_CrowdStrike_FDR permission_modification_using_takeown_app: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +ping_sleep_batch_command: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +possible_lateral_movement_powershell_spawn: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +potentially_malicious_code_on_commandline: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +powershell_disable_security_monitoring: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +powershell_start_bitstransfer: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon prevent_automatic_repair_mode_using_bcdedit: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon print_processor_registry_autostart: cim_version: 5.0.0 tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon process_creating_lnk_file_in_suspicious_location: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR process_execution_via_wmi: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR +process_kill_base_on_file_path: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon processes_launching_netsh: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +recursive_delete_of_directory_in_batch_cmd: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon reg_exe_manipulating_windows_services_registry_keys: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR registry_keys_used_for_persistence: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +regsvr32_silent_and_install_param_dll_loading: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +regsvr32_with_known_silent_switch_cmdline: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +remcos_client_registry_install_entry: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +remote_process_instantiation_via_dcom_and_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +remote_process_instantiation_via_winrm_and_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +remote_process_instantiation_via_winrm_and_winrs: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +remote_process_instantiation_via_wmi: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +remote_process_instantiation_via_wmi_and_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +remote_system_discovery_with_wmic: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon remote_wmi_command_attempt: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon resize_shadowstorage_volume: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR + - Splunk_TA_microsoft_sysmon revil_common_exec_parameter: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -revil_registry_entr: + - Splunk_TA_microsoft_sysmon +revil_registry_entry: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +rundll32_control_rundll_world_writable_directory: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +rundll32_shimcache_flush: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +rundll32_with_no_command_line_arguments_with_network: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +rundll_loading_dll_by_ordinal: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon ryuk_wake_on_lan_command: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon samsam_test_file_write: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - splunk_ta_o365 - Splunk_TA_sophos - Splunk_TA_cyberark @@ -663,60 +1603,126 @@ samsam_test_file_write: - Splunk_TA_CrowdStrike_FDR sc_exe_manipulating_windows_services: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR +scheduled_task_creation_on_remote_endpoint_using_at: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon scheduled_task_deleted_or_created_via_cmd: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +scheduled_task_initiation_on_remote_endpoint: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon schtasks_run_task_on_demand: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR -schtasks_scheduling_job_on_remote_syste: +schtasks_scheduling_job_on_remote_system: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR schtasks_used_for_forcing_a_reboot: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR screensaver_event_trigger_execution: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon script_execution_via_wmi: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm sdclt_uac_bypass: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -secretdumps_offline_ntds_dumping_too: + - Splunk_TA_microsoft_sysmon +sdelete_application_execution: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +secretdumps_offline_ntds_dumping_tool: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +serviceprincipalnames_discovery_with_setspn: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon services_escalate_exe: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +services_exe_lolbas_execution_process_spawn: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon set_default_powershell_execution_policy_to_unrestricted_or_bypass: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon shim_database_installation_with_suspicious_parameters: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR short_lived_windows_accounts: cim_version: 5.0.0 @@ -727,118 +1733,420 @@ short_lived_windows_accounts: - Splunk_TA_cyberark silentcleanup_uac_bypass: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon single_letter_process_on_endpoint: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm slui_runas_elevated: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon slui_spawning_a_process: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack -smpeng_application_dll_side_loading: + - Splunk_TA_microsoft_sysmon +spoolsv_spawning_rundll32: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - - Splunk_TA_bit9-carbonblack - - Splunk_TA_CrowdStrike_FDR -spoolsv_writing_a_d: + - Splunk_TA_microsoft_sysmon +spoolsv_writing_a_dll: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack - - Splunk_TA_windows + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR start_up_during_safe_mode_boot: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +suspicious_copy_on_system32: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_dllhost_no_command_line_arguments: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_gpupdate_no_command_line_arguments: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_icedid_rundll32_cmdline: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_microsoft_workflow_compiler_usage: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_msbuild_path: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_msbuild_rename: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_msbuild_spawn: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon suspicious_mshta_child_process: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +suspicious_mshta_spawn: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon suspicious_process_file_path: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon suspicious_reg_exe_process: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR -suspicious_scheduled_task_from_public_director: +suspicious_regsvr32_register_suspicious_path: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_rundll32_dllregisterserver: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_rundll32_plugininit: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_rundll32_startw: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_rundll32_with_no_command_line_arguments: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +suspicious_scheduled_task_from_public_directory: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +suspicious_searchprotocolhost_no_command_line_arguments: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon suspicious_wevtutil_usage: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR +svchost_exe_lolbas_execution_process_spawn: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon system_information_discovery_detection: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_nix - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_windows - Splunk_TA_CrowdStrike_FDR - Splunk_TA_cyberark_epm system_processes_run_from_unexpected_locations: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR -time_provider_persistence_registr: +time_provider_persistence_registry: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon unified_messaging_service_spawning_a_process: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon uninstall_app_using_msiexec: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon unload_sysmon_filter_driver: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR usn_journal_deletion: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +vbscript_execution_using_wscript_app: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +w3wp_spawning_shell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon wbadmin_delete_system_backups: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR +wermgr_process_spawned_cmd_or_powershell_process: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon wget_download_and_bash_execution: cim_version: 5.0.0 tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon windows_adfind_exe: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +windows_curl_download_to_suspicious_path: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +windows_curl_upload_to_remote_destination: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +windows_defender_exclusion_registry_entry: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon windows_disableantispyware_reg: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon +windows_dism_remove_defender: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +windows_dotnet_binary_in_non_standard_path: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +windows_installutil_credential_theft: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +windows_installutil_in_non_standard_path: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +windows_installutil_uninstall_option: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +windows_installutil_url_in_command_line: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +windows_nirsoft_advancedrun: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +windows_raccine_scheduled_task_deletion: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +windows_service_creation_on_remote_endpoint: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +windows_service_initiation_on_remote_endpoint: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +winhlp32_spawning_a_process: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +winword_spawning_cmd: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +winword_spawning_powershell: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +wmic_xsl_execution_via_url: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +wmiprsve_exe_lolbas_execution_process_spawn: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +wscript_or_cscript_suspicious_child_process: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon +wsmprovhost_exe_lolbas_execution_process_spawn: + cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon wsreset_uac_bypass: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon xsl_script_execution_with_wmic: cim_version: 5.0.0 + supported_tas: + - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_bit9-carbonblack + - Splunk_TA_microsoft_sysmon diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index 9bb21fa6e8..f459bb015c 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -7,6 +7,7 @@ import re import shutil import sys import time +from pathlib import Path import git import yaml @@ -65,11 +66,13 @@ def map_required_fields(cim_summary, datamodel, required_fields): cim_fields = e_type.get("fields", []) if set(datasets_fields[dataset]).issubset(set(cim_fields)): add_addon = True + if add_addon == False: + return add_addon return add_addon -def is_valid_detection_file(filepath) -> bool: +def is_valid_detection_file(filepath): detection_analytic_type = ["ttp", "anomaly"] detection_with_valid_analytic_type = False @@ -147,12 +150,12 @@ def main(): for data in detection_obj.get("tests")[0].get("attack_data"): source_types.append(data.get("sourcetype")) - detection_file_name = ( + detection_file_name_path = ( detection_obj.get("tests")[0] .get("file") .rsplit("/", 1)[1] - .strip(".yml") ) + detection_file_name = Path(detection_file_name_path).stem filepath = "security_content/detections/" + detection_obj.get("tests")[ 0 ].get("file") @@ -195,8 +198,6 @@ def main(): if recommended_ta_list: keyname = "tas_with_cim_mapping" - enrich_detection_file(filepath, cim_version, "cim_version") - enrich_detection_file(filepath, recommended_ta_list, keyname) detection_ta_mapping[detection_file_name][ "cim_version" ] = cim_version @@ -206,6 +207,7 @@ def main(): if tas_with_data_list: keyname = "supported_tas" + enrich_detection_file(filepath, cim_version, "cim_version") enrich_detection_file(filepath, tas_with_data_list, keyname) detection_ta_mapping[detection_file_name][ keyname @@ -236,19 +238,19 @@ def main(): security_content_repo_obj.git.push("--set-upstream", "origin", branch_name) repo = g.get_repo("splunk/security_content") - pr = repo.create_pull( - title="Enrich Detection PR " + branch_name, - body="Enriched the detections with recommended TAs", - head=branch_name, - base="develop", - ) + # pr = repo.create_pull( + # title="Enrich Detection PR " + branch_name, + # body="Enriched the detections with recommended TAs", + # head=branch_name, + # base="develop", + # ) - try: - shutil.rmtree("./security_content") - shutil.rmtree("./ta_cim_mapping_reports") - except OSError as e: - error_message = "Unexpected error occurred while deleting files." - logging.error(error_message) + # try: + # shutil.rmtree("./security_content") + # shutil.rmtree("./ta_cim_mapping_reports") + # except OSError as e: + # error_message = "Unexpected error occurred while deleting files." + # logging.error(error_message) if __name__ == "__main__": From 4090593f408d58378600441eadbee6ffb3f4326d Mon Sep 17 00:00:00 2001 From: mjobanputra Date: Tue, 1 Feb 2022 14:59:49 +0530 Subject: [PATCH 22/25] Add detection_ta_mapping CSV file --- .../detection_ta_mapping.csv | 317 ++++++++++++++++++ 1 file changed, 317 insertions(+) create mode 100644 security_content_automation/detection_ta_mapping.csv diff --git a/security_content_automation/detection_ta_mapping.csv b/security_content_automation/detection_ta_mapping.csv new file mode 100644 index 0000000000..1d0823e99c --- /dev/null +++ b/security_content_automation/detection_ta_mapping.csv @@ -0,0 +1,317 @@ +detection_name,cim_version,supported_tas,tas_with_cim_mapping +abnormally_high_number_of_cloud_security_group_api_calls,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce" +cloud_api_calls_from_previously_unseen_user_roles,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, splunk_ta_o365, Splunk_TA_box, Splunk_TA_infoblox, Splunk_TA_salesforce" +cloud_compute_instance_created_in_previously_unused_region,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose +cloud_provisioning_from_previously_unseen_country,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce" +cloud_compute_instance_created_with_previously_unseen_instance_type,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose +cloud_compute_instance_created_by_previously_unseen_user,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose +cloud_provisioning_from_previously_unseen_region,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce" +abnormally_high_number_of_cloud_infrastructure_api_calls,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce" +cloud_compute_instance_created_with_previously_unseen_image,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose +cloud_provisioning_from_previously_unseen_city,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce" +cloud_provisioning_from_previously_unseen_ip_address,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_salesforce" +cloud_instance_modified_with_previously_unseen_user,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_salesforce" +linux_setuid_using_chmod_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +disabling_folderoptions_windows_feature,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +anomalous_usage_of_7zip,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +enable_rdp_in_other_port_number,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +excessive_number_of_taskhost_processes,5.0.0,Splunk_TA_windows,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR" +xsl_script_execution_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +rundll32_control_rundll_world_writable_directory,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +disable_schedule_task,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +serviceprincipalnames_discovery_with_setspn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +allow_operation_with_consent_admin,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +windows_service_initiation_on_remote_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +spoolsv_writing_a_dll,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +dsquery_domain_discovery,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +linux_possible_access_or_modification_of_sshd_config_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +secretdumps_offline_ntds_dumping_tool,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +attacker_tools_on_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows" +domain_account_discovery_with_net_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +certutil_exe_certificate_extraction,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_html_help_url_in_command_line,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +prevent_automatic_repair_mode_using_bcdedit,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +linux_possible_access_to_sudoers_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +get_domainpolicy_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +excessive_number_of_distinct_processes_created_in_windows_temp_folder,5.0.0,Splunk_TA_windows,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm" +disable_registry_tool,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +powershell_disable_security_monitoring,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +svchost_exe_lolbas_execution_process_spawn,5.0.0,,Splunk_TA_microsoft_sysmon +disable_defender_spynet_reporting,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +certutil_download_with_verifyctl_and_split_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +windows_nirsoft_advancedrun,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +cmd_echo_pipe___escalation,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +excessive_number_of_service_control_start_as_disabled,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +windows_installutil_url_in_command_line,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_use_of_cmd_exe_to_launch_script_interpreters,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +suspicious_icedid_rundll32_cmdline,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +excessive_service_stop_attempt,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_copy_on_system32,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +credential_dumping_via_symlink_to_shadow_copy,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_searchprotocolhost_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +excessive_usage_of_net_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +permission_modification_using_takeown_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +linux_at_application_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +reg_exe_manipulating_windows_services_registry_keys,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +logon_script_event_trigger_execution,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +linux_possible_ssh_key_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +dump_lsass_via_procdump,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +getwmiobject_ds_computer_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +sdclt_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +hide_user_account_from_sign_in_screen,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +deleting_of_net_users,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +revil_registry_entry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +detect_psexec_with_accepteula_flag,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +remote_process_instantiation_via_dcom_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +auto_admin_logon_registry_entry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +linux_doas_tool_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +modify_acl_permission_to_files_or_folder,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +getdomaingroup_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +disable_amsi_through_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +wermgr_process_spawned_cmd_or_powershell_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_azurehound_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +office_product_spawning_rundll32_with_no_dll,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_exchange_web_shell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +time_provider_persistence_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +system_processes_run_from_unexpected_locations,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +scheduled_task_initiation_on_remote_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +sc_exe_manipulating_windows_services,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +disable_defender_submit_samples_consent_feature,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +ryuk_wake_on_lan_command,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +suspicious_msbuild_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_possible_access_to_credential_files,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +suspicious_wevtutil_usage,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +excessive_usage_of_cacls_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +disabling_task_manager,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +office_document_spawned_child_process_to_download,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +processes_launching_netsh,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +linux_possible_append_command_to_at_allow_config_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +single_letter_process_on_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm" +check_elevated_cmd_using_whoami,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +short_lived_windows_accounts,5.0.0,,"Splunk_TA_microsoft-cloudservices, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_cyberark" +possible_lateral_movement_powershell_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +schtasks_scheduling_job_on_remote_system,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +executables_or_script_creation_in_suspicious_path,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +active_setup_registry_autostart,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +suspicious_rundll32_with_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +winword_spawning_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_regsvr32_register_suspicious_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_install_kernel_module_using_modprobe_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +scheduled_task_creation_on_remote_endpoint_using_at,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_possible_append_command_to_profile_config_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +nishang_powershelltcponeline,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_mshta_url_in_command_line,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_sudoers_tmp_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +linux_service_restarted,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +disabling_defender_services,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +getwmiobject_ds_group_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +firewall_allowed_program_enable,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +office_application_spawn_regsvr32_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_rundll32_inline_hta_execution,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_gpupdate_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +extraction_of_registry_hives,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +powershell_start_bitstransfer,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_mshta_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_rundll32_application_control_bypass___setupapi,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +recursive_delete_of_directory_in_batch_cmd,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +get_aduserresultantpasswordpolicy_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +windows_dotnet_binary_in_non_standard_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +net_profiler_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +disable_etw_through_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +remote_process_instantiation_via_winrm_and_winrs,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +office_product_spawning_wmic,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +execution_of_file_with_multiple_extensions,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows" +remote_process_instantiation_via_winrm_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_process_file_path,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +any_powershell_downloadstring,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_change_file_owner_to_root,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +process_creating_lnk_file_in_suspicious_location,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +wbadmin_delete_system_backups,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +disabling_controlpanel,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +attempt_to_stop_security_service,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +excel_spawning_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +allow_inbound_traffic_by_firewall_rule_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +getdomaincomputer_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +malicious_powershell_process___execution_policy_bypass,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +disable_defender_enhanced_notification,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +fodhelper_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +detect_regsvr32_application_control_bypass,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +windows_curl_download_to_suspicious_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +remcos_client_registry_install_entry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_microsoft_workflow_compiler_usage,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +bcdedit_failure_recovery_modification,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +linux_service_file_created_in_systemd_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +slui_runas_elevated,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +batch_file_write_to_system32,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR" +windows_dism_remove_defender,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +excessive_usage_of_taskkill,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +nltest_domain_trust_discovery,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +fsutil_zeroing_file,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +office_application_spawn_rundll32_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +add_or_set_windows_defender_exclusion,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +bitsadmin_download_file,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +print_processor_registry_autostart,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +detect_path_interception_by_creation_of_program_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +cmdline_tool_not_executed_in_cmd_shell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_mshta_inline_hta_execution,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_rundll32_startw,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +script_execution_via_wmi,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm" +slui_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +scheduled_task_deleted_or_created_via_cmd,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +allow_network_discovery_in_firewall,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_file_created_in_kernel_driver_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +disable_logs_using_wevtutil,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +revil_common_exec_parameter,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +detect_sharphound_usage,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +wmiprsve_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_file_creation_in_profile_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +services_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +regsvr32_with_known_silent_switch_cmdline,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +windows_installutil_uninstall_option,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +deleting_shadow_copies,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +winhlp32_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +disabling_firewall_with_netsh,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +elevated_group_discovery_with_net,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_setuid_using_setcap_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +linux_preload_hijack_library_calls,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +windows_installutil_in_non_standard_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +get_foresttrust_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +windows_defender_exclusion_registry_entry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +windows_adfind_exe,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +disabling_cmd_application,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +msmpeng_application_dll_side_loading,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +account_discovery_with_net_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_insert_kernel_module_using_insmod_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +certutil_download_with_urlcache_and_split_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_msbuild_rename,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_mshta_child_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +set_default_powershell_execution_policy_to_unrestricted_or_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +uninstall_app_using_msiexec,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +execute_javascript_with_jscript_com_clsid,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +create_local_admin_accounts_using_net_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +disable_uac_remote_restriction,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_doas_conf_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +creation_of_shadow_copy,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_file_creation_in_init_boot_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +windows_disableantispyware_reg,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +disable_defender_mpengine_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +getwmiobject_ds_user_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +disable_windows_app_hotkeys,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +dns_exfiltration_using_nslookup_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +clear_unallocated_sector_using_cipher_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_java_spawning_shell,5.0.0,,Splunk_TA_microsoft_sysmon +disable_defender_blockatfirstseen_feature,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +remote_process_instantiation_via_wmi_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_regsvcs_with_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +get_domaintrust_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +windows_installutil_credential_theft,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +elevated_group_discovery_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +registry_keys_used_for_persistence,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +detect_rundll32_application_control_bypass___syssetup,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +ping_sleep_batch_command,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_processes_used_for_system_network_configuration_discovery,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +clop_common_exec_parameter,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +office_product_spawning_certutil,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +regsvr32_silent_and_install_param_dll_loading,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +msbuild_suspicious_spawned_by_script_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +hiding_files_and_directories_with_attrib_exe,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows" +office_product_spawn_cmd_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +wsreset_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +certutil_with_decode_argument,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +allow_file_and_printing_sharing_in_firewall,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +system_information_discovery_detection,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm" +malicious_powershell_process_with_obfuscation_techniques,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_add_files_in_known_crontab_directories,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +eventvwr_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +icacls_deny_command,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +usn_journal_deletion,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +remote_system_discovery_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_html_help_using_infotech_storage_handlers,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +disable_security_logs_using_minint_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +sdelete_application_execution,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +curl_download_and_bash_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +icacls_grant_command,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +rundll_loading_dll_by_ordinal,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +winword_spawning_cmd,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +credential_dumping_via_copy_command_from_shadow_copy,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_regasm_with_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +enable_wdigest_uselogoncredential_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +control_loading_from_world_writable_directory,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +remote_process_instantiation_via_wmi,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_dllhost_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +spoolsv_spawning_rundll32,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +conti_common_exec_parameter,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +attempted_credential_dump_from_registry_via_reg_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +jscript_execution_using_cscript_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +bcdedit_command_back_to_normal_mode_boot,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +rundll32_shimcache_flush,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +screensaver_event_trigger_execution,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +office_product_spawning_bitsadmin,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +change_default_file_association,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +wscript_or_cscript_suspicious_child_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +domain_controller_discovery_with_nltest,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +disable_windows_behavior_monitoring,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +windows_curl_upload_to_remote_destination,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +unified_messaging_service_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +detect_html_help_spawn_child_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_regsvcs_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +linux_service_started_or_enabled,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +java_class_file_download_by_java_user_agent,5.0.0,,"Splunk_TA_citrix-netscaler, Splunk_TA_nginx, Splunk_TA_microsoft-iis, Splunk_TA_websense-cg, Splunk_TA_squid, Splunk_TA_haproxy, Splunk_TA_mcafee-wg, Splunk_TA_cisco-wsa" +linux_at_allow_config_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +disable_defender_antivirus_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_visudo_utility_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +schtasks_run_task_on_demand,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +schtasks_used_for_forcing_a_reboot,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +windows_raccine_scheduled_task_deletion,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +mshta_spawning_rundll32_or_regsvr32_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +excessive_attempt_to_disable_services,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +get_domainuser_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +suspicious_scheduled_task_from_public_directory,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +rundll32_with_no_command_line_arguments_with_network,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +windows_service_creation_on_remote_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +linux_nopasswd_entry_in_sudoers_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +attempt_to_add_certificate_to_untrusted_store,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +process_kill_base_on_file_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +wsmprovhost_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +domain_account_discovery_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +disabling_norun_windows_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +suspicious_rundll32_plugininit,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +file_with_samsam_extension,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR" +silentcleanup_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +ntdsutil_export_ntds,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +disabling_systemrestore_in_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +vbscript_execution_using_wscript_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +office_spawning_control,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_regasm_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +start_up_during_safe_mode_boot,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +office_product_spawning_mshta,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +change_to_safe_mode_with_network_config,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +potentially_malicious_code_on_commandline,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +detect_rundll32_application_control_bypass___advpack,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +services_escalate_exe,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +wget_download_and_bash_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +remote_wmi_command_attempt,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +create_or_delete_windows_shares_using_net_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +unload_sysmon_filter_driver,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +resize_shadowstorage_volume,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +wmic_xsl_execution_via_url,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_reg_exe_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +etw_registry_disabled,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +process_execution_via_wmi,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +samsam_test_file_write,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR" +impacket_lateral_movement_commandline_parameters,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +dump_lsass_via_comsvcs_dll,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +creation_of_shadow_copy_with_wmic_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +overwriting_accessibility_binaries,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_ossec, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR" +add_defaultuser_and_password_in_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +bits_job_persistence,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_rundll32_dllregisterserver,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +any_powershell_downloadfile,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +mmc_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +w3wp_spawning_shell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +detect_sharphound_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" +detect_rclone_command_line_usage,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +suspicious_msbuild_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +disabling_net_user_account,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon +shim_database_installation_with_suspicious_parameters,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +dns_query_length_with_high_standard_deviation,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_isc-bind, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR, Splunk_TA_infoblox" From 1822bac96864ed57481dd59cb85b4426bf7452c6 Mon Sep 17 00:00:00 2001 From: truptilangalia-crest Date: Thu, 3 Feb 2022 09:20:06 +0530 Subject: [PATCH 23/25] test: added loggers --- .../enrich_detections.py | 166 +++++++++++------- 1 file changed, 107 insertions(+), 59 deletions(-) diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index 430287d207..1a0afa2b27 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -15,13 +15,15 @@ import yaml from github import Github +TIMESTAMP_FORMAT = '%(asctime)s %(levelname)s - %(message)s' + def fetch_ta_cim_mapping_report(file_name): try: with open(file_name) as file_content: cim_field_report = json.load(file_content) return cim_field_report except Exception as error: - error_message = "Unexpected error occurred while reading file." + error_message = f"Unexpected error occurred while reading file. {error}" logging.error(error_message) @@ -110,42 +112,58 @@ def main(): git_token_bytes = base64.b64decode(git_token_base64_bytes) github_token = git_token_bytes.decode('ascii') - g = Github(github_token) + git_token = Github(github_token) detection_types = ["cloud", "endpoint", "network"] cim_report_path = ( "ta_cim_mapping_reports/ta_cim_mapping/cim_mapping_reports/latest/" ) detection_ta_mapping = {} - # clone security content repository - security_content_repo_obj = git.Repo.clone_from( - "https://" - + github_token - + ":x-oauth-basic@github.com/" - + security_content_repo, - "security_content", - branch=security_content_branch, - ) + + try: + # clone security content repository + security_content_repo_obj = git.Repo.clone_from( + "https://" + + github_token + + ":x-oauth-basic@github.com/" + + security_content_repo, + "security_content", + branch=security_content_branch, + ) + message = "Successfully cloned security_content." + logging.info(message) + except Exception as error: + error_message = f"Unexpected error occurred while Cloning security_content, {error}" + logging.error(error_message) + + try: + # clone ta cim field reports repository + ta_cim_field_reports_obj = git.Repo.clone_from( + "https://" + + github_token + + ":x-oauth-basic@github.com/" + + ta_cim_field_reports_repo, + "ta_cim_mapping_reports", + branch=ta_cim_field_reports_branch, + ) + message = "Successfully cloned ta_cim_mapping_reports." + logging.info(message) + except Exception as error: + error_message = f"Unexpected error occurred while Cloning ta-cim-field-reports repo, {error}" + logging.error(error_message) - # clone ta cim field reports repository - ta_cim_field_reports_obj = git.Repo.clone_from( - "https://" - + github_token - + ":x-oauth-basic@github.com/" - + ta_cim_field_reports_repo, - "ta_cim_mapping_reports", - branch=ta_cim_field_reports_branch, - ) # iterate for every detection types + + for detection_type in detection_types: for subdir, _, files in os.walk(f"security_content/tests/{detection_type}"): for file in files: filepath = subdir + os.sep + file - recommended_ta_list = [] - tas_with_data_list = [] + tas_with_cim_mapping_list = [] + supported_tas_list = [] detection_obj = load_file(filepath) source_types = [] for data in detection_obj.get("tests")[0].get("attack_data"): @@ -165,7 +183,6 @@ def main(): if is_valid_detection_file(filepath): for ta_cim_mapping_file in os.listdir(cim_report_path): - ta_cim_map = fetch_ta_cim_mapping_report( cim_report_path + ta_cim_mapping_file ) @@ -181,7 +198,7 @@ def main(): cim_version = ta_cim_map["cim_version"] if result: - recommended_ta_list.append( + tas_with_cim_mapping_list.append( ta_cim_map.get("ta_name").get("name") ) ta_sourcetype = ta_cim_map["sourcetypes"] @@ -190,33 +207,37 @@ def main(): if ( source_type in ta_sourcetype and ta_cim_map.get("ta_name").get("name") - not in tas_with_data_list + not in supported_tas_list ): - tas_with_data_list.append( + supported_tas_list.append( ta_cim_map.get("ta_name").get("name") ) detection_ta_mapping[detection_file_name] = {} - if recommended_ta_list: + if tas_with_cim_mapping_list: keyname = "tas_with_cim_mapping" detection_ta_mapping[detection_file_name][ "cim_version" ] = cim_version detection_ta_mapping[detection_file_name][ keyname - ] = recommended_ta_list + ] = tas_with_cim_mapping_list - if tas_with_data_list: + if supported_tas_list: keyname = "supported_tas" enrich_detection_file(filepath, cim_version, "cim_version") - enrich_detection_file(filepath, tas_with_data_list, keyname) + enrich_detection_file(filepath, supported_tas_list, keyname) detection_ta_mapping[detection_file_name][ keyname - ] = tas_with_data_list + ] = supported_tas_list + + logging.info(f"Enriched {detection_file_name} with supported TAs : {supported_tas_list}") security_content_repo_obj.index.add( [filepath.strip("security_content/")] ) + + # Generating detection_ta_mapping CSV report try: with open(r"./security_content/security_content_automation/detection_ta_mapping.csv", 'w+', newline='') as csv_file: @@ -232,48 +253,75 @@ def main(): 'detection_name': detection_name }) writer.writerow(detection_content) + security_content_repo_obj.index.add( + ["security_content_automation/detection_ta_mapping.csv"] + ) + message = "Created detection_ta_mapping.csv file" + logging.info(message) + except Exception as error: error_message = f"Unexpected error occurred while generating detection_ta_mapping CSV report, {error}" logging.error(error_message) - security_content_repo_obj.index.add( - ["security_content_automation/detection_ta_mapping.csv"] - ) + - with io.open( - r"./security_content/security_content_automation/detection_ta_mapping.yml", - "w", - encoding="utf8", - ) as outfile: - yaml.safe_dump( - detection_ta_mapping, outfile, default_flow_style=False, allow_unicode=True + # Generating detection_ta_mapping yml file + try: + with io.open( + r"./security_content/security_content_automation/detection_ta_mapping.yml", + "w", + encoding="utf8", + ) as outfile: + yaml.safe_dump( + detection_ta_mapping, outfile, default_flow_style=False, allow_unicode=True + ) + + security_content_repo_obj.index.add( + ["security_content_automation/detection_ta_mapping.yml"] ) - security_content_repo_obj.index.add( - ["security_content_automation/detection_ta_mapping.yml"] - ) - security_content_repo_obj.index.commit( - "Updated detection files with recommended TA list." - ) + message = "Created detection_ta_mapping.yml file" + logging.info(message) - epoch_time = str(int(time.time())) - branch_name = "security_content_automation_" + epoch_time - security_content_repo_obj.git.checkout("-b", branch_name) - security_content_repo_obj.git.push("--set-upstream", "origin", branch_name) - repo = g.get_repo("splunk/security_content") + except Exception as error: + error_message = f"Unexpected error occurred while generating detection_ta_mapping.yml file, {error}" + logging.error(error_message) + + + try: + security_content_repo_obj.index.commit( + "Updated detection files with recommended TA list." + ) + + epoch_time = str(int(time.time())) + branch_name = "security_content_automation_" + epoch_time + security_content_repo_obj.git.checkout("-b", branch_name) + security_content_repo_obj.git.push("--set-upstream", "origin", branch_name) + repo = git_token.get_repo("splunk/security_content") + + pr = repo.create_pull( + title="Enrich Detection PR " + branch_name, + body="Enriched the detections with supported TAs", + head=branch_name, + base="develop", + ) + message = "Created pull request" + logging.info(message) + except Exception as error: + error_message = f"Unexpected error occurred while creating pull request, {error}" + logging.error(error_message) - pr = repo.create_pull( - title="Enrich Detection PR " + branch_name, - body="Enriched the detections with recommended TAs", - head=branch_name, - base="develop", - ) try: shutil.rmtree("./security_content") shutil.rmtree("./ta_cim_mapping_reports") + message = "Cleaned up the environment" + logging.info(message) except OSError as e: - error_message = "Unexpected error occurred while deleting files." + error_message = f"Unexpected error occurred while deleting files, {error}" logging.error(error_message) if __name__ == "__main__": + log_level=logging.INFO + handlers = [logging.StreamHandler()] + logging.basicConfig(level=log_level, format=TIMESTAMP_FORMAT, handlers=handlers) main() From 179134e8eff49dcd9cf5e4c304a4b2ff7c0a4d59 Mon Sep 17 00:00:00 2001 From: truptilangalia-crest Date: Tue, 8 Feb 2022 12:05:05 +0530 Subject: [PATCH 24/25] test:removed cim version --- ...mber_of_cloud_infrastructure_api_calls.yml | 1 - ...mber_of_cloud_security_group_api_calls.yml | 1 - ...alls_from_previously_unseen_user_roles.yml | 1 - ...ance_created_by_previously_unseen_user.yml | 1 - ...ce_created_in_previously_unused_region.yml | 1 - ...e_created_with_previously_unseen_image.yml | 1 - ...d_with_previously_unseen_instance_type.yml | 1 - ...e_modified_with_previously_unseen_user.yml | 1 - ...ovisioning_from_previously_unseen_city.yml | 1 - ...sioning_from_previously_unseen_country.yml | 1 - ...ning_from_previously_unseen_ip_address.yml | 1 - ...isioning_from_previously_unseen_region.yml | 1 - .../cloud/o365_added_service_principal.yml | 6 +- .../cloud/o365_bypass_mfa_via_trusted_ip.yml | 6 +- detections/cloud/o365_disable_mfa.yml | 4 +- .../rundll_loading_dll_by_ordinal.yml | 3 - .../suspicious_rundll32_rename.yml | 14 +-- .../account_discovery_with_net_app.yml | 1 - .../active_setup_registry_autostart.yml | 1 - ...d_defaultuser_and_password_in_registry.yml | 1 - .../add_or_set_windows_defender_exclusion.yml | 1 - ..._file_and_printing_sharing_in_firewall.yml | 1 - ...ound_traffic_by_firewall_rule_registry.yml | 1 - .../allow_network_discovery_in_firewall.yml | 1 - .../allow_operation_with_consent_admin.yml | 1 - .../endpoint/anomalous_usage_of_7zip.yml | 1 - .../endpoint/any_powershell_downloadfile.yml | 1 - .../any_powershell_downloadstring.yml | 1 - .../endpoint/attacker_tools_on_endpoint.yml | 1 - ..._to_add_certificate_to_untrusted_store.yml | 1 - .../attempt_to_stop_security_service.yml | 1 - ...dential_dump_from_registry_via_reg_exe.yml | 1 - .../auto_admin_logon_registry_entry.yml | 22 +++-- .../endpoint/batch_file_write_to_system32.yml | 1 - ...dedit_command_back_to_normal_mode_boot.yml | 1 - .../bcdedit_failure_recovery_modification.yml | 1 - detections/endpoint/bits_job_persistence.yml | 1 - .../endpoint/bitsadmin_download_file.yml | 1 - ...load_with_urlcache_and_split_arguments.yml | 1 - ...oad_with_verifyctl_and_split_arguments.yml | 1 - .../certutil_exe_certificate_extraction.yml | 1 - .../certutil_with_decode_argument.yml | 1 - .../change_default_file_association.yml | 1 - ...hange_to_safe_mode_with_network_config.yml | 1 - .../check_elevated_cmd_using_whoami.yml | 1 - ...ar_unallocated_sector_using_cipher_app.yml | 1 - .../endpoint/clop_common_exec_parameter.yml | 1 - .../endpoint/cmd_echo_pipe___escalation.yml | 1 - ...cmdline_tool_not_executed_in_cmd_shell.yml | 1 - .../endpoint/conti_common_exec_parameter.yml | 1 - ..._loading_from_world_writable_directory.yml | 1 - ...ate_local_admin_accounts_using_net_exe.yml | 1 - ...or_delete_windows_shares_using_net_exe.yml | 1 - .../endpoint/creation_of_shadow_copy.yml | 1 - ...f_shadow_copy_with_wmic_and_powershell.yml | 1 - ...ping_via_copy_command_from_shadow_copy.yml | 1 - ...ial_dumping_via_symlink_to_shadow_copy.yml | 1 - detections/endpoint/deleting_of_net_users.yml | 1 - .../endpoint/deleting_shadow_copies.yml | 1 - ...tect_azurehound_command_line_arguments.yml | 1 - .../endpoint/detect_exchange_web_shell.yml | 1 - .../detect_html_help_spawn_child_process.yml | 1 - .../detect_html_help_url_in_command_line.yml | 1 - ...l_help_using_infotech_storage_handlers.yml | 1 - .../detect_mshta_inline_hta_execution.yml | 1 - .../detect_mshta_url_in_command_line.yml | 1 - ...nterception_by_creation_of_program_exe.yml | 1 - ...system_network_configuration_discovery.yml | 1 - .../detect_psexec_with_accepteula_flag.yml | 1 - .../detect_rclone_command_line_usage.yml | 1 - .../detect_regasm_spawning_a_process.yml | 1 - ..._regasm_with_no_command_line_arguments.yml | 1 - .../detect_regsvcs_spawning_a_process.yml | 1 - ...regsvcs_with_no_command_line_arguments.yml | 1 - ...ct_regsvr32_application_control_bypass.yml | 1 - ...2_application_control_bypass___advpack.yml | 1 - ..._application_control_bypass___setupapi.yml | 1 - ..._application_control_bypass___syssetup.yml | 1 - .../detect_rundll32_inline_hta_execution.yml | 1 - ...tect_sharphound_command_line_arguments.yml | 1 - .../endpoint/detect_sharphound_usage.yml | 1 - ..._cmd_exe_to_launch_script_interpreters.yml | 1 - .../disable_amsi_through_registry.yml | 1 - .../disable_defender_antivirus_registry.yml | 1 - ...able_defender_blockatfirstseen_feature.yml | 1 - ...disable_defender_enhanced_notification.yml | 1 - .../disable_defender_mpengine_registry.yml | 1 - .../disable_defender_spynet_reporting.yml | 1 - ...efender_submit_samples_consent_feature.yml | 1 - .../endpoint/disable_etw_through_registry.yml | 1 - .../endpoint/disable_logs_using_wevtutil.yml | 1 - detections/endpoint/disable_registry_tool.yml | 1 - detections/endpoint/disable_schedule_task.yml | 1 - ...le_security_logs_using_minint_registry.yml | 1 - .../disable_uac_remote_restriction.yml | 1 - .../endpoint/disable_windows_app_hotkeys.yml | 1 - .../disable_windows_behavior_monitoring.yml | 1 - .../endpoint/disabling_cmd_application.yml | 1 - .../endpoint/disabling_controlpanel.yml | 1 - .../endpoint/disabling_defender_services.yml | 1 - .../disabling_firewall_with_netsh.yml | 1 - .../endpoint/disabling_net_user_account.yml | 1 - .../endpoint/disabling_norun_windows_app.yml | 1 - .../disabling_systemrestore_in_registry.yml | 1 - .../endpoint/disabling_task_manager.yml | 1 - .../dns_exfiltration_using_nslookup_app.yml | 1 - .../domain_account_discovery_with_net_app.yml | 1 - .../domain_account_discovery_with_wmic.yml | 1 - ...omain_controller_discovery_with_nltest.yml | 1 - .../endpoint/dsquery_domain_discovery.yml | 1 - .../endpoint/dump_lsass_via_comsvcs_dll.yml | 1 - .../endpoint/dump_lsass_via_procdump.yml | 1 - .../elevated_group_discovery_with_net.yml | 1 - .../elevated_group_discovery_with_wmic.yml | 1 - .../enable_rdp_in_other_port_number.yml | 1 - ...le_wdigest_uselogoncredential_registry.yml | 1 - detections/endpoint/etw_registry_disabled.yml | 1 - detections/endpoint/eventvwr_uac_bypass.yml | 1 - .../endpoint/excel_spawning_powershell.yml | 1 - .../excessive_attempt_to_disable_services.yml | 1 - ...ocesses_created_in_windows_temp_folder.yml | 1 - ...r_of_service_control_start_as_disabled.yml | 1 - ...excessive_number_of_taskhost_processes.yml | 1 - .../excessive_service_stop_attempt.yml | 1 - .../endpoint/excessive_usage_of_cacls_app.yml | 1 - .../endpoint/excessive_usage_of_net_app.yml | 1 - .../endpoint/excessive_usage_of_taskkill.yml | 1 - ..._or_script_creation_in_suspicious_path.yml | 1 - ...cute_javascript_with_jscript_com_clsid.yml | 1 - ...ution_of_file_with_multiple_extensions.yml | 1 - .../endpoint/extraction_of_registry_hives.yml | 1 - .../endpoint/file_with_samsam_extension.yml | 1 - .../firewall_allowed_program_enable.yml | 1 - detections/endpoint/fodhelper_uac_bypass.yml | 1 - detections/endpoint/fsutil_zeroing_file.yml | 1 - ...esultantpasswordpolicy_with_powershell.yml | 1 - .../get_domainpolicy_with_powershell.yml | 1 - .../get_domaintrust_with_powershell.yml | 1 - .../get_domainuser_with_powershell.yml | 1 - .../get_foresttrust_with_powershell.yml | 1 - .../getdomaincomputer_with_powershell.yml | 1 - .../getdomaingroup_with_powershell.yml | 1 - ...twmiobject_ds_computer_with_powershell.yml | 1 - .../getwmiobject_ds_group_with_powershell.yml | 1 - .../getwmiobject_ds_user_with_powershell.yml | 1 - .../hide_user_account_from_sign_in_screen.yml | 1 - ..._files_and_directories_with_attrib_exe.yml | 1 - detections/endpoint/icacls_deny_command.yml | 1 - detections/endpoint/icacls_grant_command.yml | 1 - ...ateral_movement_commandline_parameters.yml | 1 - .../jscript_execution_using_cscript_app.yml | 1 - .../linux_pkexec_privilege_escalation.yml | 86 +++++++++++++++++++ .../logon_script_event_trigger_execution.yml | 1 - ...hell_process___execution_policy_bypass.yml | 1 - ...ll_process_with_obfuscation_techniques.yml | 1 - ...mmc_exe_lolbas_execution_process_spawn.yml | 1 - ...dify_acl_permission_to_files_or_folder.yml | 1 - ...nitor_registry_keys_for_print_monitors.yml | 26 ++++-- ...d_suspicious_spawned_by_script_process.yml | 1 - ..._spawning_rundll32_or_regsvr32_process.yml | 1 - .../msmpeng_application_dll_side_loading.yml | 1 - .../endpoint/net_profiler_uac_bypass.yml | 1 - .../endpoint/nishang_powershelltcponeline.yml | 1 - .../nltest_domain_trust_discovery.yml | 1 - detections/endpoint/ntdsutil_export_ntds.yml | 1 - ...ice_application_spawn_regsvr32_process.yml | 1 - ...ice_application_spawn_rundll32_process.yml | 1 - ...ment_spawned_child_process_to_download.yml | 1 - .../office_product_spawn_cmd_process.yml | 1 - .../office_product_spawning_bitsadmin.yml | 1 - .../office_product_spawning_certutil.yml | 1 - .../office_product_spawning_mshta.yml | 1 - ..._product_spawning_rundll32_with_no_dll.yml | 1 - .../endpoint/office_product_spawning_wmic.yml | 1 - .../endpoint/office_spawning_control.yml | 1 - .../overwriting_accessibility_binaries.yml | 1 - ...mission_modification_using_takeown_app.yml | 1 - .../endpoint/ping_sleep_batch_command.yml | 1 - ...ible_lateral_movement_powershell_spawn.yml | 1 - ...entially_malicious_code_on_commandline.yml | 2 + ...powershell_disable_security_monitoring.yml | 1 - ...hell_remove_windows_defender_directory.yml | 2 +- .../powershell_start_bitstransfer.yml | 1 - ...nt_automatic_repair_mode_using_bcdedit.yml | 1 - ...eating_lnk_file_in_suspicious_location.yml | 1 - .../endpoint/process_execution_via_wmi.yml | 1 - .../process_kill_base_on_file_path.yml | 1 - .../endpoint/processes_launching_netsh.yml | 1 - ...rsive_delete_of_directory_in_batch_cmd.yml | 1 - ...ulating_windows_services_registry_keys.yml | 1 - ...istry_keys_for_creating_shim_databases.yml | 21 +++-- .../registry_keys_used_for_persistence.yml | 1 - ...2_silent_and_install_param_dll_loading.yml | 1 - ...svr32_with_known_silent_switch_cmdline.yml | 1 - .../remcos_client_registry_install_entry.yml | 1 - ..._instantiation_via_dcom_and_powershell.yml | 1 - ...instantiation_via_winrm_and_powershell.yml | 1 - ...cess_instantiation_via_winrm_and_winrs.yml | 1 - .../remote_process_instantiation_via_wmi.yml | 1 - ...s_instantiation_via_wmi_and_powershell.yml | 1 - .../remote_system_discovery_with_wmic.yml | 1 - .../endpoint/remote_wmi_command_attempt.yml | 1 - .../endpoint/resize_shadowstorage_volume.yml | 1 - .../endpoint/revil_common_exec_parameter.yml | 1 - detections/endpoint/revil_registry_entry.yml | 1 - ...ontrol_rundll_world_writable_directory.yml | 1 - .../endpoint/rundll32_shimcache_flush.yml | 1 - ...no_command_line_arguments_with_network.yml | 1 - .../endpoint/ryuk_wake_on_lan_command.yml | 1 - .../endpoint/samsam_test_file_write.yml | 1 - .../sc_exe_manipulating_windows_services.yml | 1 - ...k_creation_on_remote_endpoint_using_at.yml | 1 - ...eduled_task_deleted_or_created_via_cmd.yml | 1 - ...led_task_initiation_on_remote_endpoint.yml | 1 - .../endpoint/schtasks_run_task_on_demand.yml | 1 - ...htasks_scheduling_job_on_remote_system.yml | 1 - .../schtasks_used_for_forcing_a_reboot.yml | 1 - .../screensaver_event_trigger_execution.yml | 1 - .../endpoint/script_execution_via_wmi.yml | 1 - detections/endpoint/sdclt_uac_bypass.yml | 20 +++-- .../sdelete_application_execution.yml | 1 - .../secretdumps_offline_ntds_dumping_tool.yml | 1 - ...ceprincipalnames_discovery_with_setspn.yml | 1 - detections/endpoint/services_escalate_exe.yml | 1 - ...ces_exe_lolbas_execution_process_spawn.yml | 1 - ...ution_policy_to_unrestricted_or_bypass.yml | 1 - ...nstallation_with_suspicious_parameters.yml | 1 - .../endpoint/silentcleanup_uac_bypass.yml | 24 ++++-- .../single_letter_process_on_endpoint.yml | 1 - detections/endpoint/slui_runas_elevated.yml | 1 - .../endpoint/slui_spawning_a_process.yml | 1 - .../endpoint/spoolsv_spawning_rundll32.yml | 1 - detections/endpoint/spoolsv_writing_a_dll.yml | 1 - ...detect_dump_lsass_memory_using_comsvcs.yml | 9 +- ..._files_and_directories_with_attrib_exe.yml | 4 +- .../ssa___wbadmin_delete_system_backups.yml | 4 +- .../start_up_during_safe_mode_boot.yml | 1 - .../endpoint/suspicious_copy_on_system32.yml | 1 - ...ious_dllhost_no_command_line_arguments.yml | 1 - ...ous_gpupdate_no_command_line_arguments.yml | 1 - .../suspicious_icedid_rundll32_cmdline.yml | 1 - ...ious_microsoft_workflow_compiler_usage.yml | 1 - .../endpoint/suspicious_msbuild_path.yml | 1 - .../endpoint/suspicious_msbuild_rename.yml | 1 - .../endpoint/suspicious_msbuild_spawn.yml | 1 - .../suspicious_mshta_child_process.yml | 1 - .../endpoint/suspicious_mshta_spawn.yml | 1 - .../endpoint/suspicious_process_file_path.yml | 1 - .../endpoint/suspicious_reg_exe_process.yml | 1 - ...ious_regsvr32_register_suspicious_path.yml | 1 - .../suspicious_rundll32_dllregisterserver.yml | 1 - .../suspicious_rundll32_plugininit.yml | 1 - .../endpoint/suspicious_rundll32_startw.yml | 1 - ...undll32_with_no_command_line_arguments.yml | 1 - ...s_scheduled_task_from_public_directory.yml | 1 - ...protocolhost_no_command_line_arguments.yml | 1 - .../endpoint/suspicious_wevtutil_usage.yml | 1 - ...system_information_discovery_detection.yml | 1 - ...rocesses_run_from_unexpected_locations.yml | 1 - .../time_provider_persistence_registry.yml | 1 - ...d_messaging_service_spawning_a_process.yml | 1 - .../endpoint/uninstall_app_using_msiexec.yml | 1 - .../endpoint/unload_sysmon_filter_driver.yml | 1 - detections/endpoint/usn_journal_deletion.yml | 1 - .../vbscript_execution_using_wscript_app.yml | 1 - detections/endpoint/w3wp_spawning_shell.yml | 1 - .../wbadmin_delete_system_backups.yml | 1 - ...cess_spawned_cmd_or_powershell_process.yml | 1 - detections/endpoint/windows_adfind_exe.yml | 1 - ...ndows_curl_download_to_suspicious_path.yml | 1 - ...dows_curl_upload_to_remote_destination.yml | 1 - ...dows_defender_exclusion_registry_entry.yml | 1 - .../windows_disableantispyware_reg.yml | 1 - .../endpoint/windows_dism_remove_defender.yml | 1 - ...ows_dotnet_binary_in_non_standard_path.yml | 1 - .../windows_installutil_credential_theft.yml | 1 - ...ndows_installutil_in_non_standard_path.yml | 1 - .../windows_installutil_uninstall_option.yml | 1 - ...indows_installutil_url_in_command_line.yml | 1 - .../endpoint/windows_nirsoft_advancedrun.yml | 1 - ...indows_raccine_scheduled_task_deletion.yml | 1 - ...ws_service_creation_on_remote_endpoint.yml | 1 - ..._service_initiation_on_remote_endpoint.yml | 1 - .../endpoint/winhlp32_spawning_a_process.yml | 1 - detections/endpoint/winword_spawning_cmd.yml | 1 - .../endpoint/winword_spawning_powershell.yml | 1 - .../endpoint/wmic_xsl_execution_via_url.yml | 1 - ...sve_exe_lolbas_execution_process_spawn.yml | 1 - ...pt_or_cscript_suspicious_child_process.yml | 1 - ...ost_exe_lolbas_execution_process_spawn.yml | 1 - detections/endpoint/wsreset_uac_bypass.yml | 26 ++++-- .../xsl_script_execution_with_wmic.yml | 1 - ...ry_length_with_high_standard_deviation.yml | 1 - .../detection_ta_mapping.csv | 2 +- .../detection_ta_mapping.yml | 10 +-- .../enrich_detections.py | 43 +++++----- 296 files changed, 234 insertions(+), 376 deletions(-) rename detections/{endpoint => deprecated}/rundll_loading_dll_by_ordinal.yml (97%) rename detections/{endpoint => deprecated}/suspicious_rundll32_rename.yml (84%) create mode 100644 detections/endpoint/linux_pkexec_privilege_escalation.yml diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index f0183ac59b..df978db766 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -66,6 +66,5 @@ tags: - All_Changes.status risk_score: 15 security_domain: network - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index a505241f07..cb1a2b9c7a 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -72,6 +72,5 @@ tags: - All_Changes.user risk_score: 15 security_domain: network - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml index 35e8bb586e..f49fce8cf9 100644 --- a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml +++ b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml @@ -68,6 +68,5 @@ tags: - All_Changes.object risk_score: 36 security_domain: threat - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index e229fe1472..0410a7370e 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -69,6 +69,5 @@ tags: - All_Changes.vendor_region risk_score: 18 security_domain: threat - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml index 2828fb9f29..f61886e671 100644 --- a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml +++ b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml @@ -74,6 +74,5 @@ tags: - All_Changes.user risk_score: 42 security_domain: threat - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml index 8375de8ef8..5b4851a0ae 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml @@ -69,6 +69,5 @@ tags: - All_Changes.user risk_score: 36 security_domain: threat - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index 5c1f453703..1498019242 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -69,6 +69,5 @@ tags: - All_Changes.user risk_score: 30 security_domain: threat - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml index d2c6b9f33e..da2a51b79e 100644 --- a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml @@ -71,6 +71,5 @@ tags: - All_Changes.user risk_score: 42 security_domain: threat - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml index cd548cd7e2..3299a3f417 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml @@ -90,6 +90,5 @@ tags: - All_Changes.command risk_score: 18 security_domain: threat - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml index 621b6c1d73..daeaf8d490 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml @@ -90,6 +90,5 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml index c6144ab8ff..754efaf604 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml @@ -89,6 +89,5 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml index d05b2e7b5d..ac3797daba 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml @@ -90,6 +90,5 @@ tags: - All_Changes.command risk_score: 42 security_domain: threat - cim_version: 5.0.0 supported_tas: - Splunk_TA_aws-kinesis-firehose diff --git a/detections/cloud/o365_added_service_principal.yml b/detections/cloud/o365_added_service_principal.yml index 6bcfb6259b..08efdec24d 100644 --- a/detections/cloud/o365_added_service_principal.yml +++ b/detections/cloud/o365_added_service_principal.yml @@ -1,17 +1,17 @@ name: O365 Added Service Principal id: 1668812a-6047-11eb-ae93-0242ac130002 version: 1 -date: '2021-01-26' +date: '2022-02-03' author: Rod Soto, Splunk type: TTP datamodel: [] description: This search detects the creation of a new Federation setting by alerting about an specific event related to its creation. -search: '`o365_management_activity` Workload=AzureActiveDirectory signature="Add service +search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="Add service principal credentials." | stats min(_time) as firstTime max(_time) as lastTime values(Actor{}.ID) as Actor.ID values(ModifiedProperties{}.Name) as ModifiedProperties.Name values(ModifiedProperties{}.NewValue) as ModifiedProperties.NewValue values(Target{}.ID) as Target.ID by ActorIpAddress - signature | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` + Operation | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `o365_added_service_principal_filter`' how_to_implement: You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity diff --git a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml index 4a9a8ef9ea..aaee2fa67e 100644 --- a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml +++ b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml @@ -1,20 +1,20 @@ name: O365 Bypass MFA via Trusted IP id: c783dd98-c703-4252-9e8a-f19d9f66949e version: 2 -date: '2021-07-19' +date: '2022-02-03' author: Bhavin Patel, Splunk type: TTP datamodel: [] description: This search detects newly added IP addresses/CIDR blocks to the list of MFA Trusted IPs to bypass multi factor authentication. Attackers are often known to use this technique so that they can bypass the MFA system. -search: '`o365_management_activity` signature="Set Company Information." ModifiedProperties{}.Name=StrongAuthenticationPolicy +search: '`o365_management_activity` Operation="Set Company Information." ModifiedProperties{}.Name=StrongAuthenticationPolicy | rex max_match=100 field=ModifiedProperties{}.NewValue "(?\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})" | rex max_match=100 field=ModifiedProperties{}.OldValue "(?\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})" | eval ip_addresses_old=if(isnotnull(ip_addresses_old),ip_addresses_old,"0") | mvexpand ip_addresses_new_added | where isnull(mvfind(ip_addresses_old,ip_addresses_new_added)) |stats count min(_time) as firstTime max(_time) as lastTime values(ip_addresses_old) - as ip_addresses_old by user ip_addresses_new_added signature Workload vendor_account + as ip_addresses_old by user ip_addresses_new_added Operation Workload vendor_account status user_id action | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `o365_bypass_mfa_via_trusted_ip_filter`' how_to_implement: You must install Splunk Microsoft Office 365 add-on. This search diff --git a/detections/cloud/o365_disable_mfa.yml b/detections/cloud/o365_disable_mfa.yml index b80ab26505..3a7ef5e300 100644 --- a/detections/cloud/o365_disable_mfa.yml +++ b/detections/cloud/o365_disable_mfa.yml @@ -1,7 +1,7 @@ name: O365 Disable MFA id: c783dd98-c703-4252-9e8a-f19d9f5c949e version: 1 -date: '2020-12-16' +date: '2022-02-03' author: Rod Soto, Splunk type: TTP datamodel: [] @@ -9,7 +9,7 @@ description: This search detects when multi factor authentication has been disab what entitiy performed the action and against what user search: '`o365_management_activity` Operation="Disable Strong Authentication." | stats count earliest(_time) as firstTime latest(_time) as lastTime by UserType Operation - user status signature dest ResultStatus |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` + UserId ResultStatus |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `o365_disable_mfa_filter`' how_to_implement: You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/deprecated/rundll_loading_dll_by_ordinal.yml similarity index 97% rename from detections/endpoint/rundll_loading_dll_by_ordinal.yml rename to detections/deprecated/rundll_loading_dll_by_ordinal.yml index 92a26b1d19..1a42db412b 100644 --- a/detections/endpoint/rundll_loading_dll_by_ordinal.yml +++ b/detections/deprecated/rundll_loading_dll_by_ordinal.yml @@ -76,6 +76,3 @@ tags: - Processes.parent_process_id risk_score: 70 security_domain: endpoint - cim_version: 5.0.0 - supported_tas: - - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_rundll32_rename.yml b/detections/deprecated/suspicious_rundll32_rename.yml similarity index 84% rename from detections/endpoint/suspicious_rundll32_rename.yml rename to detections/deprecated/suspicious_rundll32_rename.yml index 459457a7d6..57d03b078c 100644 --- a/detections/endpoint/suspicious_rundll32_rename.yml +++ b/detections/deprecated/suspicious_rundll32_rename.yml @@ -1,16 +1,16 @@ name: Suspicious Rundll32 Rename id: 7360137f-abad-473e-8189-acbdaa34d114 -version: 3 -date: '2021-02-04' +version: 4 +date: '2022-02-01' author: Michael Haag, Splunk type: Hunting datamodel: - Endpoint -description: The following analytic identifies renamed instances of rundll32.exe executing. - rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During - investigation, validate it is the legitimate rundll32.exe executing and what script - content it is loading. This query relies on the original filename or internal name - from the PE meta data. Expand the query as needed by looking for specific command +description: The following hunting analytic identifies renamed instances of rundll32.exe + executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + During investigation, validate it is the legitimate rundll32.exe executing and what + script content it is loading. This query relies on the original filename or internal + name from the PE meta data. Expand the query as needed by looking for specific command line arguments outlined in other analytics. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` by Processes.dest diff --git a/detections/endpoint/account_discovery_with_net_app.yml b/detections/endpoint/account_discovery_with_net_app.yml index fc37a87984..f5c8857b30 100644 --- a/detections/endpoint/account_discovery_with_net_app.yml +++ b/detections/endpoint/account_discovery_with_net_app.yml @@ -80,6 +80,5 @@ tags: - Processes.parent_process_id risk_score: 5 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index 3841518418..86071ff0f0 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -76,6 +76,5 @@ tags: - Registry.registry_value_name risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml index ddd19c7253..52aae5c92b 100644 --- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml +++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml @@ -69,6 +69,5 @@ tags: - Registry.dest risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/add_or_set_windows_defender_exclusion.yml b/detections/endpoint/add_or_set_windows_defender_exclusion.yml index d1452fe07d..be1e38c53e 100644 --- a/detections/endpoint/add_or_set_windows_defender_exclusion.yml +++ b/detections/endpoint/add_or_set_windows_defender_exclusion.yml @@ -76,6 +76,5 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index b34b637cdd..41bc3e37ff 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -55,6 +55,5 @@ tags: - Processes.process_path - Processes.parent_process_id security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index 352aab3368..10d10e646c 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -74,6 +74,5 @@ tags: - Registry.user risk_score: 3 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/allow_network_discovery_in_firewall.yml b/detections/endpoint/allow_network_discovery_in_firewall.yml index edfdf48b7b..87fcccb2b4 100644 --- a/detections/endpoint/allow_network_discovery_in_firewall.yml +++ b/detections/endpoint/allow_network_discovery_in_firewall.yml @@ -57,6 +57,5 @@ tags: - Processes.process_path - Processes.parent_process_id security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/allow_operation_with_consent_admin.yml b/detections/endpoint/allow_operation_with_consent_admin.yml index 90a47dd22d..06d6b5dcc7 100644 --- a/detections/endpoint/allow_operation_with_consent_admin.yml +++ b/detections/endpoint/allow_operation_with_consent_admin.yml @@ -74,6 +74,5 @@ tags: - Registry.dest risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index c5ca19cb68..481f9a8198 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -82,6 +82,5 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml index 284b615d7b..ea941bfa39 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/endpoint/any_powershell_downloadfile.yml @@ -88,6 +88,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml index 08135b8c62..0b89645de4 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/endpoint/any_powershell_downloadstring.yml @@ -82,6 +82,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index ae0d935c58..f29439bb45 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index a341612d6a..7c871d858f 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index b7fe41a8ee..4e742ebb72 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -92,6 +92,5 @@ tags: - Processes.parent_process_id risk_score: 20 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml index ebc6d0480e..da30681035 100644 --- a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/auto_admin_logon_registry_entry.yml b/detections/endpoint/auto_admin_logon_registry_entry.yml index eaf227b588..7041013f6a 100644 --- a/detections/endpoint/auto_admin_logon_registry_entry.yml +++ b/detections/endpoint/auto_admin_logon_registry_entry.yml @@ -1,7 +1,7 @@ name: Auto Admin Logon Registry Entry id: 1379d2b8-0f18-11ec-8ca3-acde48001122 -version: 1 -date: '2021-09-06' +version: 2 +date: '2020-01-28' author: Teoderick Contreras, Splunk type: TTP datamodel: @@ -14,10 +14,19 @@ description: this search is to detect a suspicious registry modification to impl premise. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows - NT\\CurrentVersion\\Winlogon*" AND Registry.registry_key_name=AutoAdminLogon AND - Registry.registry_value_name=1 by Registry.registry_path Registry.registry_key_name - Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` - |`security_content_ctime(lastTime)` | `auto_admin_logon_registry_entry_filter`' + NT\\CurrentVersion\\Winlogon*" AND Registry.registry_value_name=AutoAdminLogon AND + Registry.registry_value_data=1 by _time span=1h Registry.dest Registry.user Registry.registry_path + Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data + | `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name + | `auto_admin_logon_registry_entry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure @@ -60,6 +69,5 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index 3f18d1e201..6461f64403 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -83,6 +83,5 @@ tags: - Processes.dest risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml index 1186a5f6e6..4bc260d08d 100644 --- a/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml +++ b/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml @@ -65,6 +65,5 @@ tags: - Processes.user risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/bcdedit_failure_recovery_modification.yml b/detections/endpoint/bcdedit_failure_recovery_modification.yml index cccd1c231f..fd4eacf029 100644 --- a/detections/endpoint/bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/bcdedit_failure_recovery_modification.yml @@ -75,6 +75,5 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/bits_job_persistence.yml b/detections/endpoint/bits_job_persistence.yml index 07befbd67b..1f32249fd9 100644 --- a/detections/endpoint/bits_job_persistence.yml +++ b/detections/endpoint/bits_job_persistence.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/bitsadmin_download_file.yml b/detections/endpoint/bitsadmin_download_file.yml index 840d6f5005..740f549f79 100644 --- a/detections/endpoint/bitsadmin_download_file.yml +++ b/detections/endpoint/bitsadmin_download_file.yml @@ -92,6 +92,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml index 907214d425..0c4f0597aa 100644 --- a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml index 81517f62c1..d7d834a0ef 100644 --- a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml @@ -85,6 +85,5 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/certutil_exe_certificate_extraction.yml b/detections/endpoint/certutil_exe_certificate_extraction.yml index c07b4d39e0..45ba783055 100644 --- a/detections/endpoint/certutil_exe_certificate_extraction.yml +++ b/detections/endpoint/certutil_exe_certificate_extraction.yml @@ -74,6 +74,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/certutil_with_decode_argument.yml b/detections/endpoint/certutil_with_decode_argument.yml index b5de170762..9a0cfa8f5d 100644 --- a/detections/endpoint/certutil_with_decode_argument.yml +++ b/detections/endpoint/certutil_with_decode_argument.yml @@ -85,6 +85,5 @@ tags: - Processes.parent_process_id risk_score: 40 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/change_default_file_association.yml b/detections/endpoint/change_default_file_association.yml index 8dbf4e8075..282c29c085 100644 --- a/detections/endpoint/change_default_file_association.yml +++ b/detections/endpoint/change_default_file_association.yml @@ -66,6 +66,5 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/change_to_safe_mode_with_network_config.yml b/detections/endpoint/change_to_safe_mode_with_network_config.yml index 45919b20bd..90f758f46d 100644 --- a/detections/endpoint/change_to_safe_mode_with_network_config.yml +++ b/detections/endpoint/change_to_safe_mode_with_network_config.yml @@ -64,6 +64,5 @@ tags: - Processes.user risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/check_elevated_cmd_using_whoami.yml b/detections/endpoint/check_elevated_cmd_using_whoami.yml index 9d8f4e0502..20d3b7f612 100644 --- a/detections/endpoint/check_elevated_cmd_using_whoami.yml +++ b/detections/endpoint/check_elevated_cmd_using_whoami.yml @@ -65,6 +65,5 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml index ae3234ff3a..5f95a83096 100644 --- a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml +++ b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml @@ -77,6 +77,5 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/clop_common_exec_parameter.yml b/detections/endpoint/clop_common_exec_parameter.yml index 22ac1853f6..ea8701cc6e 100644 --- a/detections/endpoint/clop_common_exec_parameter.yml +++ b/detections/endpoint/clop_common_exec_parameter.yml @@ -81,6 +81,5 @@ tags: - Processes.parent_process_id risk_score: 100 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/cmd_echo_pipe___escalation.yml b/detections/endpoint/cmd_echo_pipe___escalation.yml index 94218466ce..d2e19bae02 100644 --- a/detections/endpoint/cmd_echo_pipe___escalation.yml +++ b/detections/endpoint/cmd_echo_pipe___escalation.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml index d808f8859d..ca1384fc22 100644 --- a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml @@ -87,6 +87,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/conti_common_exec_parameter.yml b/detections/endpoint/conti_common_exec_parameter.yml index 9633a964b5..5512203ac6 100644 --- a/detections/endpoint/conti_common_exec_parameter.yml +++ b/detections/endpoint/conti_common_exec_parameter.yml @@ -78,6 +78,5 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/control_loading_from_world_writable_directory.yml b/detections/endpoint/control_loading_from_world_writable_directory.yml index 7c5f1634a8..13e215abb1 100644 --- a/detections/endpoint/control_loading_from_world_writable_directory.yml +++ b/detections/endpoint/control_loading_from_world_writable_directory.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml index 2a09722d84..ca3390c2f4 100644 --- a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml +++ b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process_id risk_score: 30 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml index 1d28a87f63..af27466036 100644 --- a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml +++ b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml @@ -83,6 +83,5 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/creation_of_shadow_copy.yml b/detections/endpoint/creation_of_shadow_copy.yml index 4eacd5226c..bc3f53bc27 100644 --- a/detections/endpoint/creation_of_shadow_copy.yml +++ b/detections/endpoint/creation_of_shadow_copy.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml index c9e60418ae..52b61c246c 100644 --- a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml +++ b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml @@ -82,6 +82,5 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml index bc6485ca67..982bb93c5f 100644 --- a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml index 7330ce6b55..e7e11cc09c 100644 --- a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml @@ -82,6 +82,5 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/deleting_of_net_users.yml b/detections/endpoint/deleting_of_net_users.yml index d96446ded4..4e4527f998 100644 --- a/detections/endpoint/deleting_of_net_users.yml +++ b/detections/endpoint/deleting_of_net_users.yml @@ -81,6 +81,5 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml index bfc5f20148..99741805d5 100644 --- a/detections/endpoint/deleting_shadow_copies.yml +++ b/detections/endpoint/deleting_shadow_copies.yml @@ -88,6 +88,5 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_azurehound_command_line_arguments.yml b/detections/endpoint/detect_azurehound_command_line_arguments.yml index d855ae3284..2c4baed941 100644 --- a/detections/endpoint/detect_azurehound_command_line_arguments.yml +++ b/detections/endpoint/detect_azurehound_command_line_arguments.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml index 74103fcfe5..5795b04f12 100644 --- a/detections/endpoint/detect_exchange_web_shell.yml +++ b/detections/endpoint/detect_exchange_web_shell.yml @@ -94,6 +94,5 @@ tags: - Filesystem.user risk_score: 81 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_html_help_spawn_child_process.yml b/detections/endpoint/detect_html_help_spawn_child_process.yml index b2f62ca6cf..ec49b6d6db 100644 --- a/detections/endpoint/detect_html_help_spawn_child_process.yml +++ b/detections/endpoint/detect_html_help_spawn_child_process.yml @@ -94,6 +94,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml index 6d4e8a89f6..4714a277ec 100644 --- a/detections/endpoint/detect_html_help_url_in_command_line.yml +++ b/detections/endpoint/detect_html_help_url_in_command_line.yml @@ -98,6 +98,5 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml index 6b6adb1c36..1b6c30f710 100644 --- a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml +++ b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml @@ -95,6 +95,5 @@ tags: - Processes.parent_process_id risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_mshta_inline_hta_execution.yml b/detections/endpoint/detect_mshta_inline_hta_execution.yml index 184698eecc..499ad568b5 100644 --- a/detections/endpoint/detect_mshta_inline_hta_execution.yml +++ b/detections/endpoint/detect_mshta_inline_hta_execution.yml @@ -90,6 +90,5 @@ tags: - Processes.parent_process_id risk_score: 90 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index 86903995d5..180b73585e 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -91,6 +91,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml index d8eee2b082..cd4be52fb9 100644 --- a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml +++ b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml @@ -85,6 +85,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml index ab329a527a..fc25eaa2bc 100644 --- a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml +++ b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml @@ -88,6 +88,5 @@ tags: - Processes.parent_process_id risk_score: 32 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index 06ff1f3e4d..226b47f814 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -94,6 +94,5 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml index 547f1885f5..5e172ae5d8 100644 --- a/detections/endpoint/detect_rclone_command_line_usage.yml +++ b/detections/endpoint/detect_rclone_command_line_usage.yml @@ -84,6 +84,5 @@ tags: - Processes.original_file_name risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml index 56f7bdb6bb..d7c71727dc 100644 --- a/detections/endpoint/detect_regasm_spawning_a_process.yml +++ b/detections/endpoint/detect_regasm_spawning_a_process.yml @@ -87,6 +87,5 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml index fb5bacf3f9..258427a5e9 100644 --- a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml @@ -89,6 +89,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_regsvcs_spawning_a_process.yml b/detections/endpoint/detect_regsvcs_spawning_a_process.yml index cf0953cb87..cc9286fe4a 100644 --- a/detections/endpoint/detect_regsvcs_spawning_a_process.yml +++ b/detections/endpoint/detect_regsvcs_spawning_a_process.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process_id risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml index 555e08e9c4..12558d8096 100644 --- a/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml @@ -89,6 +89,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml index acb50c61f9..a346085832 100644 --- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml +++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml @@ -96,6 +96,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml index 76bea5fc5b..ea505ebdbf 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml @@ -95,6 +95,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml index 3047bb495e..1bd63ea426 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml @@ -93,6 +93,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml index a47392f985..5be793a4fb 100644 --- a/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml +++ b/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml @@ -95,6 +95,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_rundll32_inline_hta_execution.yml b/detections/endpoint/detect_rundll32_inline_hta_execution.yml index 7b86e40cc4..0ce3298538 100644 --- a/detections/endpoint/detect_rundll32_inline_hta_execution.yml +++ b/detections/endpoint/detect_rundll32_inline_hta_execution.yml @@ -81,6 +81,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_sharphound_command_line_arguments.yml b/detections/endpoint/detect_sharphound_command_line_arguments.yml index 247acc09ab..c884eb7f88 100644 --- a/detections/endpoint/detect_sharphound_command_line_arguments.yml +++ b/detections/endpoint/detect_sharphound_command_line_arguments.yml @@ -71,6 +71,5 @@ tags: - Processes.parent_process_id risk_score: 24 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_sharphound_usage.yml b/detections/endpoint/detect_sharphound_usage.yml index c9690eedee..02400d37b8 100644 --- a/detections/endpoint/detect_sharphound_usage.yml +++ b/detections/endpoint/detect_sharphound_usage.yml @@ -80,6 +80,5 @@ tags: - Processes.parent_process_id risk_score: 24 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index 359c8cf93c..b56f9aa201 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -67,6 +67,5 @@ tags: - Processes.dest risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_amsi_through_registry.yml b/detections/endpoint/disable_amsi_through_registry.yml index 4b4e005678..9387e05324 100644 --- a/detections/endpoint/disable_amsi_through_registry.yml +++ b/detections/endpoint/disable_amsi_through_registry.yml @@ -55,6 +55,5 @@ tags: - Registry.dest - Registry.registry_value_name security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_antivirus_registry.yml b/detections/endpoint/disable_defender_antivirus_registry.yml index e57de9bf06..1561147480 100644 --- a/detections/endpoint/disable_defender_antivirus_registry.yml +++ b/detections/endpoint/disable_defender_antivirus_registry.yml @@ -71,6 +71,5 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml index 68a58f6dbc..dbfea7ede7 100644 --- a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml +++ b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml @@ -70,6 +70,5 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_enhanced_notification.yml b/detections/endpoint/disable_defender_enhanced_notification.yml index 2a9ff8e925..970291b826 100644 --- a/detections/endpoint/disable_defender_enhanced_notification.yml +++ b/detections/endpoint/disable_defender_enhanced_notification.yml @@ -70,6 +70,5 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_mpengine_registry.yml b/detections/endpoint/disable_defender_mpengine_registry.yml index 45d0738226..370a57cfc1 100644 --- a/detections/endpoint/disable_defender_mpengine_registry.yml +++ b/detections/endpoint/disable_defender_mpengine_registry.yml @@ -71,6 +71,5 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_spynet_reporting.yml b/detections/endpoint/disable_defender_spynet_reporting.yml index 724db886aa..99325b43e3 100644 --- a/detections/endpoint/disable_defender_spynet_reporting.yml +++ b/detections/endpoint/disable_defender_spynet_reporting.yml @@ -69,6 +69,5 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml index aed077ea1f..725608f220 100644 --- a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml +++ b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml @@ -69,6 +69,5 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_etw_through_registry.yml b/detections/endpoint/disable_etw_through_registry.yml index ab454be4d7..b29449cebb 100644 --- a/detections/endpoint/disable_etw_through_registry.yml +++ b/detections/endpoint/disable_etw_through_registry.yml @@ -54,6 +54,5 @@ tags: - Registry.dest - Registry.registry_value_name security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_logs_using_wevtutil.yml b/detections/endpoint/disable_logs_using_wevtutil.yml index 77ba6e062c..42a6106f04 100644 --- a/detections/endpoint/disable_logs_using_wevtutil.yml +++ b/detections/endpoint/disable_logs_using_wevtutil.yml @@ -61,6 +61,5 @@ tags: - Processes.process_guid risk_score: 24 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_registry_tool.yml b/detections/endpoint/disable_registry_tool.yml index 508943a557..39f23f330c 100644 --- a/detections/endpoint/disable_registry_tool.yml +++ b/detections/endpoint/disable_registry_tool.yml @@ -68,6 +68,5 @@ tags: - Registry.registry_value_name risk_score: 40 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_schedule_task.yml b/detections/endpoint/disable_schedule_task.yml index a7bfa49691..9a5bce2c78 100644 --- a/detections/endpoint/disable_schedule_task.yml +++ b/detections/endpoint/disable_schedule_task.yml @@ -60,6 +60,5 @@ tags: - Processes.dest risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_security_logs_using_minint_registry.yml b/detections/endpoint/disable_security_logs_using_minint_registry.yml index e81c967a42..8ff1bc575c 100644 --- a/detections/endpoint/disable_security_logs_using_minint_registry.yml +++ b/detections/endpoint/disable_security_logs_using_minint_registry.yml @@ -70,6 +70,5 @@ tags: - Registry.registry_value_data risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_uac_remote_restriction.yml b/detections/endpoint/disable_uac_remote_restriction.yml index a213ea1bab..a8f72f0663 100644 --- a/detections/endpoint/disable_uac_remote_restriction.yml +++ b/detections/endpoint/disable_uac_remote_restriction.yml @@ -74,6 +74,5 @@ tags: - Registry.registry_value_data risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_windows_app_hotkeys.yml b/detections/endpoint/disable_windows_app_hotkeys.yml index 1c0566842f..e65a348ce7 100644 --- a/detections/endpoint/disable_windows_app_hotkeys.yml +++ b/detections/endpoint/disable_windows_app_hotkeys.yml @@ -69,6 +69,5 @@ tags: - Registry.dest Registry.user risk_score: 40 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index 9ce5883694..2117620028 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -75,6 +75,5 @@ tags: - Registry.registry_value_name risk_score: 40 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_cmd_application.yml b/detections/endpoint/disabling_cmd_application.yml index 83f7da59c0..6352615096 100644 --- a/detections/endpoint/disabling_cmd_application.yml +++ b/detections/endpoint/disabling_cmd_application.yml @@ -72,6 +72,5 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_controlpanel.yml b/detections/endpoint/disabling_controlpanel.yml index c912f8981b..1e511acb0e 100644 --- a/detections/endpoint/disabling_controlpanel.yml +++ b/detections/endpoint/disabling_controlpanel.yml @@ -71,6 +71,5 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_defender_services.yml b/detections/endpoint/disabling_defender_services.yml index 5cdbcd3668..954a4147b9 100644 --- a/detections/endpoint/disabling_defender_services.yml +++ b/detections/endpoint/disabling_defender_services.yml @@ -72,6 +72,5 @@ tags: - Registry.registry_value_data risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_firewall_with_netsh.yml b/detections/endpoint/disabling_firewall_with_netsh.yml index a06406df67..dd4de0a3cd 100644 --- a/detections/endpoint/disabling_firewall_with_netsh.yml +++ b/detections/endpoint/disabling_firewall_with_netsh.yml @@ -71,6 +71,5 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_net_user_account.yml b/detections/endpoint/disabling_net_user_account.yml index 9edc5a6c73..c048edf698 100644 --- a/detections/endpoint/disabling_net_user_account.yml +++ b/detections/endpoint/disabling_net_user_account.yml @@ -78,6 +78,5 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_norun_windows_app.yml b/detections/endpoint/disabling_norun_windows_app.yml index e301b5150e..cf96acc806 100644 --- a/detections/endpoint/disabling_norun_windows_app.yml +++ b/detections/endpoint/disabling_norun_windows_app.yml @@ -75,6 +75,5 @@ tags: - Registry.registry_value_name risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_systemrestore_in_registry.yml b/detections/endpoint/disabling_systemrestore_in_registry.yml index 746b3c6318..02bf9ee4e6 100644 --- a/detections/endpoint/disabling_systemrestore_in_registry.yml +++ b/detections/endpoint/disabling_systemrestore_in_registry.yml @@ -74,6 +74,5 @@ tags: - Registry.registry_value_name risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/disabling_task_manager.yml b/detections/endpoint/disabling_task_manager.yml index a654f12a01..dea2692223 100644 --- a/detections/endpoint/disabling_task_manager.yml +++ b/detections/endpoint/disabling_task_manager.yml @@ -73,6 +73,5 @@ tags: - Registry.registry_value_name risk_score: 42 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml index e7f0cdf812..739eb1ad54 100644 --- a/detections/endpoint/dns_exfiltration_using_nslookup_app.yml +++ b/detections/endpoint/dns_exfiltration_using_nslookup_app.yml @@ -85,6 +85,5 @@ tags: - Processes.parent_process_id risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/domain_account_discovery_with_net_app.yml b/detections/endpoint/domain_account_discovery_with_net_app.yml index 57b3db2c23..d08b791f3f 100644 --- a/detections/endpoint/domain_account_discovery_with_net_app.yml +++ b/detections/endpoint/domain_account_discovery_with_net_app.yml @@ -70,6 +70,5 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index c91fca490b..5069bf4f2a 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -71,6 +71,5 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/domain_controller_discovery_with_nltest.yml b/detections/endpoint/domain_controller_discovery_with_nltest.yml index e2df023bdf..f44aa2ab73 100644 --- a/detections/endpoint/domain_controller_discovery_with_nltest.yml +++ b/detections/endpoint/domain_controller_discovery_with_nltest.yml @@ -63,6 +63,5 @@ tags: - Processes.parent_process_id risk_score: 21 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/dsquery_domain_discovery.yml b/detections/endpoint/dsquery_domain_discovery.yml index f7b604c0c2..ae07891213 100644 --- a/detections/endpoint/dsquery_domain_discovery.yml +++ b/detections/endpoint/dsquery_domain_discovery.yml @@ -93,6 +93,5 @@ tags: - Processes.parent_process_id risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml index 162c716972..f0806cf1a4 100644 --- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml +++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/dump_lsass_via_procdump.yml b/detections/endpoint/dump_lsass_via_procdump.yml index 0d141fff62..ac76cbe814 100644 --- a/detections/endpoint/dump_lsass_via_procdump.yml +++ b/detections/endpoint/dump_lsass_via_procdump.yml @@ -89,6 +89,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/elevated_group_discovery_with_net.yml b/detections/endpoint/elevated_group_discovery_with_net.yml index 39f23584ed..5f4c9e0fb8 100644 --- a/detections/endpoint/elevated_group_discovery_with_net.yml +++ b/detections/endpoint/elevated_group_discovery_with_net.yml @@ -70,6 +70,5 @@ tags: - Processes.parent_process_id risk_score: 21 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/elevated_group_discovery_with_wmic.yml b/detections/endpoint/elevated_group_discovery_with_wmic.yml index 68e797fe47..bf92cb2add 100644 --- a/detections/endpoint/elevated_group_discovery_with_wmic.yml +++ b/detections/endpoint/elevated_group_discovery_with_wmic.yml @@ -68,6 +68,5 @@ tags: - Processes.parent_process_id risk_score: 21 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/enable_rdp_in_other_port_number.yml b/detections/endpoint/enable_rdp_in_other_port_number.yml index 35c7250ca3..3ad2ad5db9 100644 --- a/detections/endpoint/enable_rdp_in_other_port_number.yml +++ b/detections/endpoint/enable_rdp_in_other_port_number.yml @@ -68,6 +68,5 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml b/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml index 28e9dc798b..cc55d2f898 100644 --- a/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml +++ b/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml @@ -75,6 +75,5 @@ tags: - Registry.registry_value_data risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/etw_registry_disabled.yml b/detections/endpoint/etw_registry_disabled.yml index 042d3a3fb9..041d54c3a3 100644 --- a/detections/endpoint/etw_registry_disabled.yml +++ b/detections/endpoint/etw_registry_disabled.yml @@ -75,6 +75,5 @@ tags: - Registry.registry_value_data risk_score: 90 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/eventvwr_uac_bypass.yml b/detections/endpoint/eventvwr_uac_bypass.yml index 9e3ba29a7b..d86049b7dc 100644 --- a/detections/endpoint/eventvwr_uac_bypass.yml +++ b/detections/endpoint/eventvwr_uac_bypass.yml @@ -78,6 +78,5 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excel_spawning_powershell.yml b/detections/endpoint/excel_spawning_powershell.yml index 565d53ec51..b838d060fa 100644 --- a/detections/endpoint/excel_spawning_powershell.yml +++ b/detections/endpoint/excel_spawning_powershell.yml @@ -82,6 +82,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_attempt_to_disable_services.yml b/detections/endpoint/excessive_attempt_to_disable_services.yml index 802a903b48..7726131774 100644 --- a/detections/endpoint/excessive_attempt_to_disable_services.yml +++ b/detections/endpoint/excessive_attempt_to_disable_services.yml @@ -64,6 +64,5 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml b/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml index 937c8700fa..31e7e9cd42 100644 --- a/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml +++ b/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml @@ -58,6 +58,5 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_windows diff --git a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml index ee71b5f359..bac83efcff 100644 --- a/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml +++ b/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml @@ -73,6 +73,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_number_of_taskhost_processes.yml b/detections/endpoint/excessive_number_of_taskhost_processes.yml index 46d88e3815..4ddb7bef7a 100644 --- a/detections/endpoint/excessive_number_of_taskhost_processes.yml +++ b/detections/endpoint/excessive_number_of_taskhost_processes.yml @@ -67,6 +67,5 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_windows diff --git a/detections/endpoint/excessive_service_stop_attempt.yml b/detections/endpoint/excessive_service_stop_attempt.yml index 4da5e65371..6c46da14ca 100644 --- a/detections/endpoint/excessive_service_stop_attempt.yml +++ b/detections/endpoint/excessive_service_stop_attempt.yml @@ -72,6 +72,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_usage_of_cacls_app.yml b/detections/endpoint/excessive_usage_of_cacls_app.yml index 1cf73e8a56..4bac489fdd 100644 --- a/detections/endpoint/excessive_usage_of_cacls_app.yml +++ b/detections/endpoint/excessive_usage_of_cacls_app.yml @@ -64,6 +64,5 @@ tags: - Processes.user risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_usage_of_net_app.yml b/detections/endpoint/excessive_usage_of_net_app.yml index 090bb8c518..107c0ce90d 100644 --- a/detections/endpoint/excessive_usage_of_net_app.yml +++ b/detections/endpoint/excessive_usage_of_net_app.yml @@ -76,6 +76,5 @@ tags: - Processes.parent_process_id risk_score: 28 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/excessive_usage_of_taskkill.yml b/detections/endpoint/excessive_usage_of_taskkill.yml index 1fd76c86df..8f76b5ab68 100644 --- a/detections/endpoint/excessive_usage_of_taskkill.yml +++ b/detections/endpoint/excessive_usage_of_taskkill.yml @@ -68,6 +68,5 @@ tags: - Processes.process_id risk_score: 28 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index 01d3cd9741..ee081a33d7 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -79,6 +79,5 @@ tags: - Filesystem.user risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml index 28a02c0210..9a8c8241a2 100644 --- a/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml +++ b/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml @@ -74,6 +74,5 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index eddde66d1e..42dcd578c5 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -74,6 +74,5 @@ tags: - Processes.parent_process risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/extraction_of_registry_hives.yml b/detections/endpoint/extraction_of_registry_hives.yml index 9da67e0c63..cb08f69826 100644 --- a/detections/endpoint/extraction_of_registry_hives.yml +++ b/detections/endpoint/extraction_of_registry_hives.yml @@ -78,6 +78,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml index b4013208c3..bd44cb5cf9 100644 --- a/detections/endpoint/file_with_samsam_extension.yml +++ b/detections/endpoint/file_with_samsam_extension.yml @@ -69,6 +69,5 @@ tags: - Filesystem.file_name risk_score: 90 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/firewall_allowed_program_enable.yml b/detections/endpoint/firewall_allowed_program_enable.yml index ce15567e77..d76c1302c7 100644 --- a/detections/endpoint/firewall_allowed_program_enable.yml +++ b/detections/endpoint/firewall_allowed_program_enable.yml @@ -67,6 +67,5 @@ tags: - Processes.parent_process_id risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/fodhelper_uac_bypass.yml b/detections/endpoint/fodhelper_uac_bypass.yml index 9e153ef472..a92768317f 100644 --- a/detections/endpoint/fodhelper_uac_bypass.yml +++ b/detections/endpoint/fodhelper_uac_bypass.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process_id risk_score: 81 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/fsutil_zeroing_file.yml b/detections/endpoint/fsutil_zeroing_file.yml index 2738bdeb42..53787bc8c5 100644 --- a/detections/endpoint/fsutil_zeroing_file.yml +++ b/detections/endpoint/fsutil_zeroing_file.yml @@ -57,6 +57,5 @@ tags: - Processes.parent_process risk_score: 54 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml index 865fe4c7ab..ff29d907d3 100644 --- a/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml +++ b/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml @@ -71,6 +71,5 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/get_domainpolicy_with_powershell.yml b/detections/endpoint/get_domainpolicy_with_powershell.yml index 918f812f1a..a47bfa8f2e 100644 --- a/detections/endpoint/get_domainpolicy_with_powershell.yml +++ b/detections/endpoint/get_domainpolicy_with_powershell.yml @@ -71,6 +71,5 @@ tags: - Processes.parent_process_name risk_score: 30 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/get_domaintrust_with_powershell.yml b/detections/endpoint/get_domaintrust_with_powershell.yml index a2367a1d36..549a7639fb 100644 --- a/detections/endpoint/get_domaintrust_with_powershell.yml +++ b/detections/endpoint/get_domaintrust_with_powershell.yml @@ -71,6 +71,5 @@ tags: - Processes.parent_process_id risk_score: 12 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml index 816ab95e37..2977e9943a 100644 --- a/detections/endpoint/get_domainuser_with_powershell.yml +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -71,6 +71,5 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/get_foresttrust_with_powershell.yml b/detections/endpoint/get_foresttrust_with_powershell.yml index 661368032d..3a7aed21ae 100644 --- a/detections/endpoint/get_foresttrust_with_powershell.yml +++ b/detections/endpoint/get_foresttrust_with_powershell.yml @@ -72,6 +72,5 @@ tags: - Processes.parent_process_id risk_score: 12 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/getdomaincomputer_with_powershell.yml b/detections/endpoint/getdomaincomputer_with_powershell.yml index 996fd3579c..4da1c3199e 100644 --- a/detections/endpoint/getdomaincomputer_with_powershell.yml +++ b/detections/endpoint/getdomaincomputer_with_powershell.yml @@ -63,6 +63,5 @@ tags: - Processes.parent_process_id risk_score: 24 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/getdomaingroup_with_powershell.yml b/detections/endpoint/getdomaingroup_with_powershell.yml index 6bf0650d8b..e3797d79ed 100644 --- a/detections/endpoint/getdomaingroup_with_powershell.yml +++ b/detections/endpoint/getdomaingroup_with_powershell.yml @@ -65,6 +65,5 @@ tags: - Processes.parent_process_id risk_score: 15 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml b/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml index df304cf24a..71659ca87e 100644 --- a/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml @@ -64,6 +64,5 @@ tags: - Processes.parent_process_id risk_score: 21 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml index 54ab0736ba..37f46c9956 100644 --- a/detections/endpoint/getwmiobject_ds_group_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_group_with_powershell.yml @@ -67,6 +67,5 @@ tags: - Processes.parent_process_id risk_score: 15 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml index fbe98c8ce3..9b10a7f427 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -73,6 +73,5 @@ tags: - Processes.parent_process_name risk_score: 25 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/hide_user_account_from_sign_in_screen.yml b/detections/endpoint/hide_user_account_from_sign_in_screen.yml index 99370134d3..eac5da28f8 100644 --- a/detections/endpoint/hide_user_account_from_sign_in_screen.yml +++ b/detections/endpoint/hide_user_account_from_sign_in_screen.yml @@ -79,6 +79,5 @@ tags: - Registry.dest Registry.user risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index f6595b88f0..8d475b0572 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -74,6 +74,5 @@ tags: - Processes.dest risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/icacls_deny_command.yml b/detections/endpoint/icacls_deny_command.yml index 8246482db2..b83fcbeec1 100644 --- a/detections/endpoint/icacls_deny_command.yml +++ b/detections/endpoint/icacls_deny_command.yml @@ -65,6 +65,5 @@ tags: - Processes.process risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/icacls_grant_command.yml b/detections/endpoint/icacls_grant_command.yml index 2e5a3a82e8..c7d56e34d4 100644 --- a/detections/endpoint/icacls_grant_command.yml +++ b/detections/endpoint/icacls_grant_command.yml @@ -65,6 +65,5 @@ tags: - Processes.process risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml index 0cbeb833ad..0668bed541 100644 --- a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml @@ -81,6 +81,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/jscript_execution_using_cscript_app.yml b/detections/endpoint/jscript_execution_using_cscript_app.yml index 44b797c99a..ab7430fa8c 100644 --- a/detections/endpoint/jscript_execution_using_cscript_app.yml +++ b/detections/endpoint/jscript_execution_using_cscript_app.yml @@ -69,6 +69,5 @@ tags: - Processes.user risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/linux_pkexec_privilege_escalation.yml b/detections/endpoint/linux_pkexec_privilege_escalation.yml new file mode 100644 index 0000000000..5c4b713717 --- /dev/null +++ b/detections/endpoint/linux_pkexec_privilege_escalation.yml @@ -0,0 +1,86 @@ +name: Linux pkexec Privilege Escalation +id: 03e22c1c-8086-11ec-ac2e-acde48001122 +version: 1 +date: '2022-01-28' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies `pkexec` spawning with no command-line + arguments. A vulnerability in Polkit's pkexec component identified as CVE-2021-4034 + (PwnKit) which is present in the default configuration of all major Linux distributions + and can be exploited to gain full root privileges on the system. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + where Processes.process_name=pkexec by _time Processes.dest Processes.process_id + Processes.parent_process_name Processes.process_name Processes.process Processes.process_path + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | regex process="(^.{1}$)" | `linux_pkexec_privilege_escalation_filter`' +how_to_implement: Depending on the EDR product in use, there are multiple ways to + "null" the command-line field, Processes.process. Two that may be useful `process="(^.{0}$)"` + or `| where isnull(process)`. To generate data for this behavior, Sysmon for Linux + was utilized. To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives may be present, filter as needed. +references: +- https://www.reddit.com/r/crowdstrike/comments/sdfeig/20220126_cool_query_friday_hunting_pwnkit_local/ +- https://linux.die.net/man/1/pkexec +- https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/ +- https://access.redhat.com/security/security-updates/#/?q=polkit&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory&documentKind=PortalProduct +tags: + analytic_story: + - Linux Privilege Escalation + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + cve: + - CVE-2021-4034 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/linux-sysmon.log + impact: 80 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$ related to a local privilege escalation in polkit + pkexec. + mitre_attack_id: + - T1068 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 56 + security_domain: endpoint diff --git a/detections/endpoint/logon_script_event_trigger_execution.yml b/detections/endpoint/logon_script_event_trigger_execution.yml index 65f38e8145..cce4592702 100644 --- a/detections/endpoint/logon_script_event_trigger_execution.yml +++ b/detections/endpoint/logon_script_event_trigger_execution.yml @@ -64,6 +64,5 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml index 42549ef692..23a31dc47e 100644 --- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml +++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml @@ -79,6 +79,5 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml index fe4b645d92..1fa77cee67 100644 --- a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml +++ b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml @@ -77,6 +77,5 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml index 42116b7fcf..aab3e5935e 100644 --- a/detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/mmc_exe_lolbas_execution_process_spawn.yml @@ -79,6 +79,5 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/modify_acl_permission_to_files_or_folder.yml b/detections/endpoint/modify_acl_permission_to_files_or_folder.yml index a29a96315d..5f41d4c5c9 100644 --- a/detections/endpoint/modify_acl_permission_to_files_or_folder.yml +++ b/detections/endpoint/modify_acl_permission_to_files_or_folder.yml @@ -62,6 +62,5 @@ tags: - Processes.process_id risk_score: 32 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml index ce986c1257..d445f2249f 100644 --- a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml +++ b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml @@ -1,8 +1,8 @@ name: Monitor Registry Keys for Print Monitors id: f5f6af30-7ba7-4295-bfe9-07de87c01bbc -version: 2 -date: '2020-11-23' -author: Bhavin Patel, Splunk +version: 3 +date: '2020-01-28' +author: Bhavin Patel, Teoderick Contreras, Splunk type: TTP datamodel: [] description: This search looks for registry activity associated with modifications @@ -10,11 +10,20 @@ description: This search looks for registry activity associated with modificatio scenario, an attacker can load an arbitrary .dll into the print-monitor registry by giving the full path name to the after.dll. The system will execute the .dll with elevated (SYSTEM) permissions and will persist after reboot. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime FROM datamodel=Endpoint.Registry where Registry.action=modified AND - Registry.registry_path="*CurrentControlSet\\Control\\Print\\Monitors*" by Registry.dest, - Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_name - Registry.action | `drop_dm_object_name(Registry)` | `monitor_registry_keys_for_print_monitors_filter`' +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry + where Registry.action=modified AND Registry.registry_path="*CurrentControlSet\\Control\\Print\\Monitors*" + by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.process_guid Registry.registry_key_name Registry.registry_value_data | + `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name + | `monitor_registry_keys_for_print_monitors_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response @@ -41,6 +50,7 @@ tags: - Stage:Privilege Escalation dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.010/atomic_red_team/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.010/atomic_red_team/sysmon.log impact: 80 kill_chain_phases: - Actions on Objectives diff --git a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml index 9403ebd3ab..4880410409 100644 --- a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml +++ b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml @@ -69,6 +69,5 @@ tags: - Processes.user risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml index 2b7e0f2981..04b24fdeed 100644 --- a/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml +++ b/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml @@ -72,6 +72,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/msmpeng_application_dll_side_loading.yml b/detections/endpoint/msmpeng_application_dll_side_loading.yml index 34457fed7e..c4f72a52aa 100644 --- a/detections/endpoint/msmpeng_application_dll_side_loading.yml +++ b/detections/endpoint/msmpeng_application_dll_side_loading.yml @@ -47,6 +47,5 @@ tags: - Filesystem.user - Filesystem.file_path security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/net_profiler_uac_bypass.yml b/detections/endpoint/net_profiler_uac_bypass.yml index 4499d7d39c..6a198c5242 100644 --- a/detections/endpoint/net_profiler_uac_bypass.yml +++ b/detections/endpoint/net_profiler_uac_bypass.yml @@ -62,6 +62,5 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/nishang_powershelltcponeline.yml b/detections/endpoint/nishang_powershelltcponeline.yml index 58b0aec14a..e4858581cd 100644 --- a/detections/endpoint/nishang_powershelltcponeline.yml +++ b/detections/endpoint/nishang_powershelltcponeline.yml @@ -72,6 +72,5 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/nltest_domain_trust_discovery.yml b/detections/endpoint/nltest_domain_trust_discovery.yml index cd02725e6f..0351a8b0cc 100644 --- a/detections/endpoint/nltest_domain_trust_discovery.yml +++ b/detections/endpoint/nltest_domain_trust_discovery.yml @@ -75,6 +75,5 @@ tags: - Processes.parent_process_id risk_score: 15 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/ntdsutil_export_ntds.yml b/detections/endpoint/ntdsutil_export_ntds.yml index 6cb6da82e1..aa6664ba7e 100644 --- a/detections/endpoint/ntdsutil_export_ntds.yml +++ b/detections/endpoint/ntdsutil_export_ntds.yml @@ -78,6 +78,5 @@ tags: - Processes.parent_process_id risk_score: 50 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_application_spawn_regsvr32_process.yml b/detections/endpoint/office_application_spawn_regsvr32_process.yml index 8af912be94..7cee8cbf6d 100644 --- a/detections/endpoint/office_application_spawn_regsvr32_process.yml +++ b/detections/endpoint/office_application_spawn_regsvr32_process.yml @@ -67,6 +67,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_application_spawn_rundll32_process.yml b/detections/endpoint/office_application_spawn_rundll32_process.yml index bf01bade6d..30f2fa1600 100644 --- a/detections/endpoint/office_application_spawn_rundll32_process.yml +++ b/detections/endpoint/office_application_spawn_rundll32_process.yml @@ -68,6 +68,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_document_spawned_child_process_to_download.yml b/detections/endpoint/office_document_spawned_child_process_to_download.yml index b4eaba8fd6..f3d8d1fa01 100644 --- a/detections/endpoint/office_document_spawned_child_process_to_download.yml +++ b/detections/endpoint/office_document_spawned_child_process_to_download.yml @@ -67,6 +67,5 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawn_cmd_process.yml b/detections/endpoint/office_product_spawn_cmd_process.yml index 5103e3ac08..69de3a2862 100644 --- a/detections/endpoint/office_product_spawn_cmd_process.yml +++ b/detections/endpoint/office_product_spawn_cmd_process.yml @@ -73,6 +73,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawning_bitsadmin.yml b/detections/endpoint/office_product_spawning_bitsadmin.yml index 6be37ad6a7..094bebf61f 100644 --- a/detections/endpoint/office_product_spawning_bitsadmin.yml +++ b/detections/endpoint/office_product_spawning_bitsadmin.yml @@ -78,6 +78,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawning_certutil.yml b/detections/endpoint/office_product_spawning_certutil.yml index 239f5a9aba..0326a05e7a 100644 --- a/detections/endpoint/office_product_spawning_certutil.yml +++ b/detections/endpoint/office_product_spawning_certutil.yml @@ -78,6 +78,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawning_mshta.yml b/detections/endpoint/office_product_spawning_mshta.yml index b79ecc5484..5c136fd5a4 100644 --- a/detections/endpoint/office_product_spawning_mshta.yml +++ b/detections/endpoint/office_product_spawning_mshta.yml @@ -78,6 +78,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml b/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml index 267abd4696..d2a2ea1b65 100644 --- a/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml +++ b/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml @@ -81,6 +81,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_product_spawning_wmic.yml b/detections/endpoint/office_product_spawning_wmic.yml index 05da4fb63e..cb49a67c41 100644 --- a/detections/endpoint/office_product_spawning_wmic.yml +++ b/detections/endpoint/office_product_spawning_wmic.yml @@ -80,6 +80,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/office_spawning_control.yml b/detections/endpoint/office_spawning_control.yml index cb9db8f1c2..9a776be427 100644 --- a/detections/endpoint/office_spawning_control.yml +++ b/detections/endpoint/office_spawning_control.yml @@ -85,6 +85,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index 1099322ffc..4c2b15a2e0 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -69,6 +69,5 @@ tags: - Filesystem.dest risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/permission_modification_using_takeown_app.yml b/detections/endpoint/permission_modification_using_takeown_app.yml index 7d72e1276e..0a4ff79263 100644 --- a/detections/endpoint/permission_modification_using_takeown_app.yml +++ b/detections/endpoint/permission_modification_using_takeown_app.yml @@ -65,6 +65,5 @@ tags: - Processes.process_guid risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/ping_sleep_batch_command.yml b/detections/endpoint/ping_sleep_batch_command.yml index 31e9370fba..f015fa1240 100644 --- a/detections/endpoint/ping_sleep_batch_command.yml +++ b/detections/endpoint/ping_sleep_batch_command.yml @@ -79,6 +79,5 @@ tags: - Processes.parent_process_id risk_score: 36 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml index 0605b31412..6110ef0b52 100644 --- a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml +++ b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 45 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/potentially_malicious_code_on_commandline.yml b/detections/endpoint/potentially_malicious_code_on_commandline.yml index 6bbeaa5f82..0ca4d0c6fd 100644 --- a/detections/endpoint/potentially_malicious_code_on_commandline.yml +++ b/detections/endpoint/potentially_malicious_code_on_commandline.yml @@ -75,3 +75,5 @@ tags: - Processes.dest risk_score: 12 security_domain: endpoint + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/powershell_disable_security_monitoring.yml b/detections/endpoint/powershell_disable_security_monitoring.yml index ebcae8148a..5f8fcb73e6 100644 --- a/detections/endpoint/powershell_disable_security_monitoring.yml +++ b/detections/endpoint/powershell_disable_security_monitoring.yml @@ -55,6 +55,5 @@ tags: - Processes.process_path - Processes.parent_process_id security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/powershell_remove_windows_defender_directory.yml b/detections/endpoint/powershell_remove_windows_defender_directory.yml index d891abf325..fe08533824 100644 --- a/detections/endpoint/powershell_remove_windows_defender_directory.yml +++ b/detections/endpoint/powershell_remove_windows_defender_directory.yml @@ -11,7 +11,7 @@ description: This analytic will identify a suspicious PowerShell command used to campaign where it used Nirsofts advancedrun.exe to gain administrative privileges to then execute a PowerShell command to delete the Windows Defender folder. This is a good indicator the offending process is trying corrupt a Windows Defender installation. -search: '`powershell` EventCode=4104 Message = "* rmdir *" OR Message = "*\\Microsoft\\Windows +search: '`powershell` EventCode=4104 Message = "* rmdir *" AND Message = "*\\Microsoft\\Windows Defender*" | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `powershell_remove_windows_defender_directory_filter`' diff --git a/detections/endpoint/powershell_start_bitstransfer.yml b/detections/endpoint/powershell_start_bitstransfer.yml index da8e09ed4e..41be205342 100644 --- a/detections/endpoint/powershell_start_bitstransfer.yml +++ b/detections/endpoint/powershell_start_bitstransfer.yml @@ -76,6 +76,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml index 614e344e72..54aa65d39c 100644 --- a/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml +++ b/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml @@ -66,6 +66,5 @@ tags: - Processes.process_guid risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml index dc64f62336..25799511ff 100644 --- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml +++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml @@ -80,6 +80,5 @@ tags: - Filesystem.user risk_score: 63 security_domain: network - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/process_execution_via_wmi.yml b/detections/endpoint/process_execution_via_wmi.yml index 03fa648f65..faec4079dd 100644 --- a/detections/endpoint/process_execution_via_wmi.yml +++ b/detections/endpoint/process_execution_via_wmi.yml @@ -71,6 +71,5 @@ tags: - Processes.process_name risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/process_kill_base_on_file_path.yml b/detections/endpoint/process_kill_base_on_file_path.yml index acbe92e60c..335870e7f0 100644 --- a/detections/endpoint/process_kill_base_on_file_path.yml +++ b/detections/endpoint/process_kill_base_on_file_path.yml @@ -70,6 +70,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index a64175a7ab..f6ebe63ee3 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -76,6 +76,5 @@ tags: - Processes.dest risk_score: 42 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml index 7092068f7c..f05c0a88d0 100644 --- a/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml +++ b/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml @@ -54,6 +54,5 @@ tags: - Processes.process_path - Processes.parent_process_id security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml index cd11cae2a9..dae747c94c 100644 --- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml +++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml @@ -79,6 +79,5 @@ tags: - Processes.dest risk_score: 45 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/registry_keys_for_creating_shim_databases.yml b/detections/endpoint/registry_keys_for_creating_shim_databases.yml index 5d87f2c5a4..1c3534eb54 100644 --- a/detections/endpoint/registry_keys_for_creating_shim_databases.yml +++ b/detections/endpoint/registry_keys_for_creating_shim_databases.yml @@ -1,17 +1,24 @@ name: Registry Keys for Creating SHIM Databases id: f5f6af30-7aa7-4295-bfe9-07fe87c01bbb -version: 3 -date: '2020-11-26' -author: Bhavin Patel, Patrick Bareiss, Splunk +version: 4 +date: '2020-01-28' +author: Bhavin Patel, Patrick Bareiss, Teoderick Contreras, Splunk type: TTP datamodel: [] description: This search looks for registry activity associated with application compatibility shims, which can be leveraged by attackers for various nefarious purposes. -search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) - as registry_key_name min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path=*CurrentVersion\\AppCompatFlags\\Custom* OR Registry.registry_path=*CurrentVersion\\AppCompatFlags\\InstalledSDB* - by Registry.dest Registry.user | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` - | `drop_dm_object_name(Registry)` | `registry_keys_for_creating_shim_databases_filter`' + by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` + |rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` + count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data] + | table _time dest user parent_process_name parent_process process_name process_path + process proc_guid registry_path registry_value_name registry_value_data | `registry_keys_for_creating_shim_databases_filter`' how_to_implement: To successfully implement this search, you must populate the Change_Analysis data model. This is typically populated via endpoint detection and response product, such as Carbon Black or other endpoint data sources such as Sysmon. The data used diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 658492423d..a1d2b48115 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -97,6 +97,5 @@ tags: - Registry.user risk_score: 76 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml index e84f0b5acd..8535dac57e 100644 --- a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml +++ b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 36 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml index 96faeb15ae..9a2eec50d2 100644 --- a/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml +++ b/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remcos_client_registry_install_entry.yml b/detections/endpoint/remcos_client_registry_install_entry.yml index 83e83062b0..17c83f11a9 100644 --- a/detections/endpoint/remcos_client_registry_install_entry.yml +++ b/detections/endpoint/remcos_client_registry_install_entry.yml @@ -61,6 +61,5 @@ tags: - Registry.user risk_score: 90 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml index 61725b63c9..4a7362585c 100644 --- a/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml @@ -67,6 +67,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml index 02db0a3567..fff1f18412 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml @@ -68,6 +68,5 @@ tags: - Processes.parent_process_id risk_score: 45 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml index bc7fe55d99..2abcf01122 100644 --- a/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml +++ b/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml @@ -66,6 +66,5 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_process_instantiation_via_wmi.yml b/detections/endpoint/remote_process_instantiation_via_wmi.yml index 580c9a8749..2f68f5492b 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi.yml @@ -82,6 +82,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml b/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml index f1b824cd55..d9ff14079a 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml @@ -66,6 +66,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_system_discovery_with_wmic.yml b/detections/endpoint/remote_system_discovery_with_wmic.yml index 0cffce5faf..092c163d81 100644 --- a/detections/endpoint/remote_system_discovery_with_wmic.yml +++ b/detections/endpoint/remote_system_discovery_with_wmic.yml @@ -65,6 +65,5 @@ tags: - Processes.parent_process_id risk_score: 15 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/remote_wmi_command_attempt.yml b/detections/endpoint/remote_wmi_command_attempt.yml index e330bed723..b88e03dead 100644 --- a/detections/endpoint/remote_wmi_command_attempt.yml +++ b/detections/endpoint/remote_wmi_command_attempt.yml @@ -76,6 +76,5 @@ tags: - Processes.process_id risk_score: 36 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/resize_shadowstorage_volume.yml b/detections/endpoint/resize_shadowstorage_volume.yml index 314d10d510..ecbd7e4c63 100644 --- a/detections/endpoint/resize_shadowstorage_volume.yml +++ b/detections/endpoint/resize_shadowstorage_volume.yml @@ -73,6 +73,5 @@ tags: - Processes.user risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/revil_common_exec_parameter.yml b/detections/endpoint/revil_common_exec_parameter.yml index a197e5c84e..b48aa0033c 100644 --- a/detections/endpoint/revil_common_exec_parameter.yml +++ b/detections/endpoint/revil_common_exec_parameter.yml @@ -67,6 +67,5 @@ tags: - Processes.process_guid risk_score: 54 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/revil_registry_entry.yml b/detections/endpoint/revil_registry_entry.yml index 8f2374ea2b..d24975ae03 100644 --- a/detections/endpoint/revil_registry_entry.yml +++ b/detections/endpoint/revil_registry_entry.yml @@ -71,6 +71,5 @@ tags: - Registry.registry_key_name risk_score: 60 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml index f763971249..e22be31c8a 100644 --- a/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml +++ b/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml @@ -91,6 +91,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/rundll32_shimcache_flush.yml b/detections/endpoint/rundll32_shimcache_flush.yml index 1ea2ca7251..845bd66115 100644 --- a/detections/endpoint/rundll32_shimcache_flush.yml +++ b/detections/endpoint/rundll32_shimcache_flush.yml @@ -69,6 +69,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml index 217638d28c..632a790430 100644 --- a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process_id risk_score: 70 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/ryuk_wake_on_lan_command.yml b/detections/endpoint/ryuk_wake_on_lan_command.yml index 296a40030e..684c485717 100644 --- a/detections/endpoint/ryuk_wake_on_lan_command.yml +++ b/detections/endpoint/ryuk_wake_on_lan_command.yml @@ -73,6 +73,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/samsam_test_file_write.yml b/detections/endpoint/samsam_test_file_write.yml index 99697d458f..17516b0b39 100644 --- a/detections/endpoint/samsam_test_file_write.yml +++ b/detections/endpoint/samsam_test_file_write.yml @@ -62,6 +62,5 @@ tags: - Filesystem.file_path risk_score: 12 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index 3fb235bf4d..daec04b402 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -78,6 +78,5 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml index b2c0f51639..1a20a684f4 100644 --- a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml +++ b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml @@ -68,6 +68,5 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index d22c63effc..12618ad7a7 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -71,6 +71,5 @@ tags: - Processes.dest risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml index fdd2584d25..8860f35c80 100644 --- a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml +++ b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml @@ -65,6 +65,5 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/schtasks_run_task_on_demand.yml b/detections/endpoint/schtasks_run_task_on_demand.yml index 4ee325ba44..263758ac10 100644 --- a/detections/endpoint/schtasks_run_task_on_demand.yml +++ b/detections/endpoint/schtasks_run_task_on_demand.yml @@ -66,6 +66,5 @@ tags: - Processes.user risk_score: 48 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index ccf5e0e562..a7d455035f 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -73,6 +73,5 @@ tags: - Processes.user risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index 5d1d6016f5..053b428c8e 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -70,6 +70,5 @@ tags: - Processes.user risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml index e2aaa3e2c0..003016f8c8 100644 --- a/detections/endpoint/screensaver_event_trigger_execution.yml +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -67,6 +67,5 @@ tags: - Registry.registry_value_name risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/script_execution_via_wmi.yml b/detections/endpoint/script_execution_via_wmi.yml index f3b88b6a4c..ac87865b4c 100644 --- a/detections/endpoint/script_execution_via_wmi.yml +++ b/detections/endpoint/script_execution_via_wmi.yml @@ -65,6 +65,5 @@ tags: - Processes.dest risk_score: 36 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/sdclt_uac_bypass.yml b/detections/endpoint/sdclt_uac_bypass.yml index ce90d93ae7..cf395a7332 100644 --- a/detections/endpoint/sdclt_uac_bypass.yml +++ b/detections/endpoint/sdclt_uac_bypass.yml @@ -1,7 +1,7 @@ name: Sdclt UAC Bypass id: d71efbf6-da63-11eb-8c6e-acde48001122 -version: 1 -date: '2021-07-01' +version: 2 +date: '2020-01-28' author: Teoderick Contreras, Splunk type: TTP datamodel: @@ -14,9 +14,18 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\Windows\\CurrentVersion\\App Paths\\control.exe*" OR Registry.registry_path= "*\\exefile\\shell\\runas\\command\\*") (Registry.registry_value_name = "(Default)" OR Registry.registry_value_name = "IsolatedCommand") - by Registry.registry_path Registry.registry_key_name Registry.registry_value_name - Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | `sdclt_uac_bypass_filter`' + by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.process_guid Registry.registry_key_name Registry.registry_value_data | + `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name + | `sdclt_uac_bypass_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. @@ -62,6 +71,5 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/sdelete_application_execution.yml b/detections/endpoint/sdelete_application_execution.yml index e6d69bc6db..8b57213736 100644 --- a/detections/endpoint/sdelete_application_execution.yml +++ b/detections/endpoint/sdelete_application_execution.yml @@ -73,6 +73,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index 1b46174d18..9a46d7b579 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -68,6 +68,5 @@ tags: - Processes.process_guid risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml index 1695b3c2d7..916f0a8054 100644 --- a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml +++ b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml @@ -106,6 +106,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/services_escalate_exe.yml b/detections/endpoint/services_escalate_exe.yml index 67a821a3cc..f1f7aa5fe7 100644 --- a/detections/endpoint/services_escalate_exe.yml +++ b/detections/endpoint/services_escalate_exe.yml @@ -75,6 +75,5 @@ tags: - Processes.parent_process_id risk_score: 76 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml index 410184734c..7e4b21420b 100644 --- a/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml @@ -79,6 +79,5 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index f0a0397da4..2f6666750a 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -71,6 +71,5 @@ tags: - Registry.dest risk_score: 48 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index c2b6652199..d8ac0829e0 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -68,6 +68,5 @@ tags: - Processes.user risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/silentcleanup_uac_bypass.yml b/detections/endpoint/silentcleanup_uac_bypass.yml index 1f0a4a2a8f..c1a9885737 100644 --- a/detections/endpoint/silentcleanup_uac_bypass.yml +++ b/detections/endpoint/silentcleanup_uac_bypass.yml @@ -1,7 +1,7 @@ name: SilentCleanup UAC Bypass id: 56d7cfcc-da63-11eb-92d4-acde48001122 -version: 1 -date: '2021-07-01' +version: 2 +date: '2020-01-28' author: Teoderick Contreras, Splunk type: TTP datamodel: @@ -10,11 +10,20 @@ description: This search is to detect a suspicious modification of registry that related to UAC bypassed. This registry will be trigger once the attacker abuse the silentcleanup task schedule to gain high privilege execution that will bypass User control account. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\Environment\\windir" - Registry.registry_value_name = "*.exe*" by Registry.registry_path Registry.registry_key_name - Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | `silentcleanup_uac_bypass_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\Environment\\windir" Registry.registry_value_data + = "*.exe*" by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name + Registry.registry_value_data Registry.process_guid Registry.registry_key_name | + `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid, + _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest + Processes.parent_process_name Processes.parent_process Processes.process_guid | + `drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time + dest user parent_process_name parent_process process_name process_path process proc_guid + registry_path registry_value_name registry_value_data registry_key_name] | table + _time dest user parent_process_name parent_process process_name process_path process + proc_guid registry_path registry_value_name registry_value_data registry_key_name + | `silentcleanup_uac_bypass_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure @@ -60,6 +69,5 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index 91a8047c4b..2d4277a1f6 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -66,6 +66,5 @@ tags: - Processes.process_name risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/slui_runas_elevated.yml b/detections/endpoint/slui_runas_elevated.yml index 5d132649be..fce44aa6e2 100644 --- a/detections/endpoint/slui_runas_elevated.yml +++ b/detections/endpoint/slui_runas_elevated.yml @@ -72,6 +72,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/slui_spawning_a_process.yml b/detections/endpoint/slui_spawning_a_process.yml index 2da907b586..0fa2eac2c0 100644 --- a/detections/endpoint/slui_spawning_a_process.yml +++ b/detections/endpoint/slui_spawning_a_process.yml @@ -70,6 +70,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/spoolsv_spawning_rundll32.yml b/detections/endpoint/spoolsv_spawning_rundll32.yml index 103f405eab..8f7e3d5acc 100644 --- a/detections/endpoint/spoolsv_spawning_rundll32.yml +++ b/detections/endpoint/spoolsv_spawning_rundll32.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml index fb8f31dbf1..f296a79eee 100644 --- a/detections/endpoint/spoolsv_writing_a_dll.yml +++ b/detections/endpoint/spoolsv_writing_a_dll.yml @@ -81,6 +81,5 @@ tags: - Processes.dest risk_score: 72 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml index 805aa68620..3f541dc5f2 100644 --- a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml +++ b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml @@ -14,10 +14,11 @@ search: '| from read_ssa_enriched_events() | eval tenant=ucast(map_get(input_eve "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", null)), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where process_name LIKE "%rundll32.exe%" AND match_regex(process, - /(?i)comsvcs.dll[,\s]+MiniDump/)=true | eval start_time = timestamp, end_time = - timestamp, entities = mvappend(machine), body=create_map(["event_id", event_id, - "process_name", process_name, "process", process]) | into write_ssa_detected_events();' + "event_id"), "string", null) | where process IS NOT NULL AND process_name IS NOT + NULL AND process_name LIKE "%rundll32.exe%" AND match_regex(process, /(?i)comsvcs.dll[,\s]+MiniDump/)=true + | eval start_time = timestamp, end_time = timestamp, entities = mvappend(machine), + body=create_map(["event_id", event_id, "process_name", process_name, "process", + process]) | into write_ssa_detected_events();' how_to_implement: You must be ingesting endpoint data that tracks process activity, including Windows command line logging. You can see how we test this with [Event Code 4688](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4688a) diff --git a/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml index e3fa20820f..7ab062c00c 100644 --- a/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml @@ -16,8 +16,8 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%+h%") AND process_name="attrib.exe" | - eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + cmd_line IS NOT NULL AND match_regex(cmd_line, /\+h/)=true AND process_name="attrib.exe" + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) diff --git a/detections/endpoint/ssa___wbadmin_delete_system_backups.yml b/detections/endpoint/ssa___wbadmin_delete_system_backups.yml index 263ce5b13b..9e3dd02435 100644 --- a/detections/endpoint/ssa___wbadmin_delete_system_backups.yml +++ b/detections/endpoint/ssa___wbadmin_delete_system_backups.yml @@ -15,9 +15,9 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="wbadmin.exe" + (cmd_line IS NOT NULL AND process_name IS NOT NULL) AND (process_name="wbadmin.exe" AND like (cmd_line, "%delete%") OR like (cmd_line, "%catalog%") OR like (cmd_line, - "%systemstatebackup%") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "%systemstatebackup%")) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) diff --git a/detections/endpoint/start_up_during_safe_mode_boot.yml b/detections/endpoint/start_up_during_safe_mode_boot.yml index de2c748490..7e2e1427db 100644 --- a/detections/endpoint/start_up_during_safe_mode_boot.yml +++ b/detections/endpoint/start_up_during_safe_mode_boot.yml @@ -66,6 +66,5 @@ tags: - Registry.dest risk_score: 42 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_copy_on_system32.yml b/detections/endpoint/suspicious_copy_on_system32.yml index ff152f7d63..790e3c976f 100644 --- a/detections/endpoint/suspicious_copy_on_system32.yml +++ b/detections/endpoint/suspicious_copy_on_system32.yml @@ -72,6 +72,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml b/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml index 7abaea2239..3e39f5d928 100644 --- a/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml @@ -74,6 +74,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml b/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml index 42dd64b120..36e0a60730 100644 --- a/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml @@ -73,6 +73,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml index 34c55dba23..8575a27f5d 100644 --- a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml +++ b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml @@ -69,6 +69,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml index 4731d99a13..3b400ef260 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml @@ -75,6 +75,5 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml index f444c4817f..a5d11e2305 100644 --- a/detections/endpoint/suspicious_msbuild_path.yml +++ b/detections/endpoint/suspicious_msbuild_path.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml index a19660278e..fdb7e16f85 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/endpoint/suspicious_msbuild_rename.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_msbuild_spawn.yml b/detections/endpoint/suspicious_msbuild_spawn.yml index 34350db21f..eb3153be52 100644 --- a/detections/endpoint/suspicious_msbuild_spawn.yml +++ b/detections/endpoint/suspicious_msbuild_spawn.yml @@ -81,6 +81,5 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index aa81646a00..95b4ff024d 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -79,6 +79,5 @@ tags: - Processes.user risk_score: 40 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_mshta_spawn.yml b/detections/endpoint/suspicious_mshta_spawn.yml index ab2369d2d8..fb276a88f8 100644 --- a/detections/endpoint/suspicious_mshta_spawn.yml +++ b/detections/endpoint/suspicious_mshta_spawn.yml @@ -75,6 +75,5 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index 3e6a501fb7..17c24c545f 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -74,6 +74,5 @@ tags: - Processes.user risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index be3bd9b497..fd7c536250 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -78,6 +78,5 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml index c991ace093..656aa2d5cb 100644 --- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml +++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml @@ -88,6 +88,5 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml index 4a997aa0da..19e3560a01 100644 --- a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml +++ b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml @@ -88,6 +88,5 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_rundll32_plugininit.yml b/detections/endpoint/suspicious_rundll32_plugininit.yml index 32dfa13f81..b0ddab468c 100644 --- a/detections/endpoint/suspicious_rundll32_plugininit.yml +++ b/detections/endpoint/suspicious_rundll32_plugininit.yml @@ -69,6 +69,5 @@ tags: - Processes.parent_process_id risk_score: 42 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_rundll32_startw.yml b/detections/endpoint/suspicious_rundll32_startw.yml index 4c1913d7e7..c5e148e8c0 100644 --- a/detections/endpoint/suspicious_rundll32_startw.yml +++ b/detections/endpoint/suspicious_rundll32_startw.yml @@ -89,6 +89,5 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml b/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml index d52144e124..ee2bce6a7c 100644 --- a/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml @@ -87,6 +87,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index 5c7a49bbf8..c663f88758 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -73,6 +73,5 @@ tags: - Processes.parent_process_id risk_score: 35 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml b/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml index c208bf6831..a804c6b96f 100644 --- a/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml @@ -74,6 +74,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index a5acbabdb0..ed1d109a7c 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -77,6 +77,5 @@ tags: - Processes.user risk_score: 28 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/system_information_discovery_detection.yml b/detections/endpoint/system_information_discovery_detection.yml index edc8e672bf..955b10fdcd 100644 --- a/detections/endpoint/system_information_discovery_detection.yml +++ b/detections/endpoint/system_information_discovery_detection.yml @@ -66,6 +66,5 @@ tags: - Processes.dest risk_score: 15 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index 517748d29e..09b9bc2061 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -82,6 +82,5 @@ tags: - Processes.process_hash risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml index c00ed4c727..42cbd1ab82 100644 --- a/detections/endpoint/time_provider_persistence_registry.yml +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -74,6 +74,5 @@ tags: - Registry.registry_value_name risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/unified_messaging_service_spawning_a_process.yml b/detections/endpoint/unified_messaging_service_spawning_a_process.yml index b181f06201..5cedb020fb 100644 --- a/detections/endpoint/unified_messaging_service_spawning_a_process.yml +++ b/detections/endpoint/unified_messaging_service_spawning_a_process.yml @@ -71,6 +71,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/uninstall_app_using_msiexec.yml b/detections/endpoint/uninstall_app_using_msiexec.yml index a1c12f056e..83fa05eb28 100644 --- a/detections/endpoint/uninstall_app_using_msiexec.yml +++ b/detections/endpoint/uninstall_app_using_msiexec.yml @@ -65,6 +65,5 @@ tags: - Processes.parent_process_id risk_score: 30 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index e9e40dac75..2327a5c01f 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -65,6 +65,5 @@ tags: - Processes.user risk_score: 45 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/usn_journal_deletion.yml b/detections/endpoint/usn_journal_deletion.yml index 7dc9caaf7c..d02e6ba8a7 100644 --- a/detections/endpoint/usn_journal_deletion.yml +++ b/detections/endpoint/usn_journal_deletion.yml @@ -70,6 +70,5 @@ tags: - Processes.dest risk_score: 45 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/vbscript_execution_using_wscript_app.yml b/detections/endpoint/vbscript_execution_using_wscript_app.yml index 02077abbf5..a80dd8e2b8 100644 --- a/detections/endpoint/vbscript_execution_using_wscript_app.yml +++ b/detections/endpoint/vbscript_execution_using_wscript_app.yml @@ -72,6 +72,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml index ba04b3a96f..850cdb5cb6 100644 --- a/detections/endpoint/w3wp_spawning_shell.yml +++ b/detections/endpoint/w3wp_spawning_shell.yml @@ -80,6 +80,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wbadmin_delete_system_backups.yml b/detections/endpoint/wbadmin_delete_system_backups.yml index c915ee1e6e..6f5715c80a 100644 --- a/detections/endpoint/wbadmin_delete_system_backups.yml +++ b/detections/endpoint/wbadmin_delete_system_backups.yml @@ -64,6 +64,5 @@ tags: - Processes.user risk_score: 15 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml b/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml index 87a1b9cf50..371cf2a000 100644 --- a/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml +++ b/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml @@ -66,6 +66,5 @@ tags: - Processes.parent_process_id risk_score: 56 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_adfind_exe.yml b/detections/endpoint/windows_adfind_exe.yml index 6eafa71e1e..a4dd560dc1 100644 --- a/detections/endpoint/windows_adfind_exe.yml +++ b/detections/endpoint/windows_adfind_exe.yml @@ -58,6 +58,5 @@ tags: - Processes.process_id - Processes.parent_process_id security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index 31e9590167..5f9705d849 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_curl_upload_to_remote_destination.yml b/detections/endpoint/windows_curl_upload_to_remote_destination.yml index f07fd2ef2e..65afeffe87 100644 --- a/detections/endpoint/windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/windows_curl_upload_to_remote_destination.yml @@ -94,6 +94,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_defender_exclusion_registry_entry.yml b/detections/endpoint/windows_defender_exclusion_registry_entry.yml index f5cba30004..f3a273dcc7 100644 --- a/detections/endpoint/windows_defender_exclusion_registry_entry.yml +++ b/detections/endpoint/windows_defender_exclusion_registry_entry.yml @@ -75,6 +75,5 @@ tags: - Registry.registry_value_data risk_score: 64 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_disableantispyware_reg.yml b/detections/endpoint/windows_disableantispyware_reg.yml index 59eff047c9..62174a5077 100644 --- a/detections/endpoint/windows_disableantispyware_reg.yml +++ b/detections/endpoint/windows_disableantispyware_reg.yml @@ -68,6 +68,5 @@ tags: - Registry.registry_path risk_score: 24 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_dism_remove_defender.yml b/detections/endpoint/windows_dism_remove_defender.yml index a1d607addc..9cc4c5bafe 100644 --- a/detections/endpoint/windows_dism_remove_defender.yml +++ b/detections/endpoint/windows_dism_remove_defender.yml @@ -79,6 +79,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: access - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml index e83ae62983..cb6ed79777 100644 --- a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml +++ b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml @@ -95,6 +95,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_installutil_credential_theft.yml b/detections/endpoint/windows_installutil_credential_theft.yml index ed812e47c8..3fb5c0f1e1 100644 --- a/detections/endpoint/windows_installutil_credential_theft.yml +++ b/detections/endpoint/windows_installutil_credential_theft.yml @@ -89,6 +89,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_installutil_in_non_standard_path.yml b/detections/endpoint/windows_installutil_in_non_standard_path.yml index e353d99ecb..1179c42ae8 100644 --- a/detections/endpoint/windows_installutil_in_non_standard_path.yml +++ b/detections/endpoint/windows_installutil_in_non_standard_path.yml @@ -90,6 +90,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_installutil_uninstall_option.yml b/detections/endpoint/windows_installutil_uninstall_option.yml index 800e5e9634..98a9002831 100644 --- a/detections/endpoint/windows_installutil_uninstall_option.yml +++ b/detections/endpoint/windows_installutil_uninstall_option.yml @@ -96,6 +96,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_installutil_url_in_command_line.yml b/detections/endpoint/windows_installutil_url_in_command_line.yml index 0da38ed8f5..b6958ef7af 100644 --- a/detections/endpoint/windows_installutil_url_in_command_line.yml +++ b/detections/endpoint/windows_installutil_url_in_command_line.yml @@ -92,6 +92,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_nirsoft_advancedrun.yml b/detections/endpoint/windows_nirsoft_advancedrun.yml index e1497a56d8..15669cf7d5 100644 --- a/detections/endpoint/windows_nirsoft_advancedrun.yml +++ b/detections/endpoint/windows_nirsoft_advancedrun.yml @@ -83,6 +83,5 @@ tags: - Processes.parent_process_id risk_score: 60 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml index 3dff4b9d7a..e442e6221c 100644 --- a/detections/endpoint/windows_raccine_scheduled_task_deletion.yml +++ b/detections/endpoint/windows_raccine_scheduled_task_deletion.yml @@ -79,6 +79,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml index 6ccd7f379c..e7ee7f4898 100644 --- a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml +++ b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml @@ -67,6 +67,5 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml index bdf5d5a363..fe79ffa24e 100644 --- a/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml +++ b/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml @@ -65,6 +65,5 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/winhlp32_spawning_a_process.yml b/detections/endpoint/winhlp32_spawning_a_process.yml index 776550da9f..94331c9531 100644 --- a/detections/endpoint/winhlp32_spawning_a_process.yml +++ b/detections/endpoint/winhlp32_spawning_a_process.yml @@ -86,6 +86,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/winword_spawning_cmd.yml b/detections/endpoint/winword_spawning_cmd.yml index a53d2a37cd..6edb916edb 100644 --- a/detections/endpoint/winword_spawning_cmd.yml +++ b/detections/endpoint/winword_spawning_cmd.yml @@ -79,6 +79,5 @@ tags: - Processes.parent_process_id risk_score: 70 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/winword_spawning_powershell.yml b/detections/endpoint/winword_spawning_powershell.yml index e1b7ef5f9e..46c8cb7d5a 100644 --- a/detections/endpoint/winword_spawning_powershell.yml +++ b/detections/endpoint/winword_spawning_powershell.yml @@ -81,6 +81,5 @@ tags: - Processes.parent_process_id risk_score: 70 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wmic_xsl_execution_via_url.yml b/detections/endpoint/wmic_xsl_execution_via_url.yml index 9d24ed93dc..06690c892a 100644 --- a/detections/endpoint/wmic_xsl_execution_via_url.yml +++ b/detections/endpoint/wmic_xsl_execution_via_url.yml @@ -84,6 +84,5 @@ tags: - Processes.parent_process_id risk_score: 80 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml index 6c10241917..1460ebef98 100644 --- a/detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/wmiprsve_exe_lolbas_execution_process_spawn.yml @@ -78,6 +78,5 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml index 87aece9016..af04695147 100644 --- a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml +++ b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml @@ -78,6 +78,5 @@ tags: - Processes.parent_process_id risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml index 48049758dc..a459e91554 100644 --- a/detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/wsmprovhost_exe_lolbas_execution_process_spawn.yml @@ -79,6 +79,5 @@ tags: - Processes.parent_process_id risk_score: 54 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/wsreset_uac_bypass.yml b/detections/endpoint/wsreset_uac_bypass.yml index f9f88abf71..b422b0def9 100644 --- a/detections/endpoint/wsreset_uac_bypass.yml +++ b/detections/endpoint/wsreset_uac_bypass.yml @@ -1,7 +1,7 @@ name: WSReset UAC Bypass id: 8b5901bc-da63-11eb-be43-acde48001122 -version: 1 -date: '2021-07-01' +version: 2 +date: '2020-01-28' author: Teoderick Contreras, Splunk type: TTP datamodel: @@ -10,12 +10,21 @@ description: This search is to detect a suspicious modification of registry rela to UAC bypass. This technique is to modify the registry in this detection, create a registry value with the path of the payload and run WSreset.exe to bypass User account Control. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command*" - (Registry.registry_value_name = "(Default)" OR Registry.registry_value_name = "DelegateExecute") - by Registry.registry_path Registry.registry_key_name Registry.registry_value_name - Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | `wsreset_uac_bypass_filter`' +search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command*" + AND (Registry.registry_value_name = "(Default)" OR Registry.registry_value_name + = "DelegateExecute") by _time span=1h Registry.dest Registry.user Registry.registry_path + Registry.registry_value_name Registry.registry_value_data Registry.process_guid + Registry.registry_key_name | `drop_dm_object_name(Registry)` |rename process_guid + as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name + Processes.process Processes.dest Processes.parent_process_name Processes.parent_process + Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as + proc_guid | fields _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name] | table _time dest user parent_process_name parent_process process_name + process_path process proc_guid registry_path registry_value_name registry_value_data + registry_key_name | `wsreset_uac_bypass_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure @@ -61,6 +70,5 @@ tags: - Registry.dest risk_score: 63 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/endpoint/xsl_script_execution_with_wmic.yml b/detections/endpoint/xsl_script_execution_with_wmic.yml index faab307475..0d1b86a632 100644 --- a/detections/endpoint/xsl_script_execution_with_wmic.yml +++ b/detections/endpoint/xsl_script_execution_with_wmic.yml @@ -77,6 +77,5 @@ tags: - Processes.user risk_score: 49 security_domain: endpoint - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/detections/network/dns_query_length_with_high_standard_deviation.yml b/detections/network/dns_query_length_with_high_standard_deviation.yml index a0505fe1c8..30c1805342 100644 --- a/detections/network/dns_query_length_with_high_standard_deviation.yml +++ b/detections/network/dns_query_length_with_high_standard_deviation.yml @@ -66,6 +66,5 @@ tags: - DNS.query risk_score: 56 security_domain: network - cim_version: 5.0.0 supported_tas: - Splunk_TA_microsoft_sysmon diff --git a/security_content_automation/detection_ta_mapping.csv b/security_content_automation/detection_ta_mapping.csv index 1d0823e99c..4ce0deb0aa 100644 --- a/security_content_automation/detection_ta_mapping.csv +++ b/security_content_automation/detection_ta_mapping.csv @@ -127,6 +127,7 @@ any_powershell_downloadstring,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microso linux_change_file_owner_to_root,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" process_creating_lnk_file_in_suspicious_location,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" wbadmin_delete_system_backups,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" +linux_pkexec_privilege_escalation,5.0.0,,Splunk_TA_microsoft_sysmon disabling_controlpanel,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" attempt_to_stop_security_service,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon excel_spawning_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon @@ -231,7 +232,6 @@ disable_security_logs_using_minint_registry,5.0.0,Splunk_TA_microsoft_sysmon,Spl sdelete_application_execution,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon curl_download_and_bash_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon" icacls_grant_command,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR" -rundll_loading_dll_by_ordinal,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon winword_spawning_cmd,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon credential_dumping_via_copy_command_from_shadow_copy,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon detect_regasm_with_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon diff --git a/security_content_automation/detection_ta_mapping.yml b/security_content_automation/detection_ta_mapping.yml index cdfe79fcac..ffb96a2eb7 100644 --- a/security_content_automation/detection_ta_mapping.yml +++ b/security_content_automation/detection_ta_mapping.yml @@ -1140,6 +1140,10 @@ linux_nopasswd_entry_in_sudoers_file: - Splunk_TA_bit9-carbonblack - Splunk_TA_microsoft_sysmon - Splunk_TA_CrowdStrike_FDR +linux_pkexec_privilege_escalation: + cim_version: 5.0.0 + tas_with_cim_mapping: + - Splunk_TA_microsoft_sysmon linux_possible_access_or_modification_of_sshd_config_file: cim_version: 5.0.0 tas_with_cim_mapping: @@ -1575,12 +1579,6 @@ rundll32_with_no_command_line_arguments_with_network: - Splunk_TA_microsoft_sysmon tas_with_cim_mapping: - Splunk_TA_microsoft_sysmon -rundll_loading_dll_by_ordinal: - cim_version: 5.0.0 - supported_tas: - - Splunk_TA_microsoft_sysmon - tas_with_cim_mapping: - - Splunk_TA_microsoft_sysmon ryuk_wake_on_lan_command: cim_version: 5.0.0 supported_tas: diff --git a/security_content_automation/enrich_detections.py b/security_content_automation/enrich_detections.py index 1a0afa2b27..e6d2af4d59 100644 --- a/security_content_automation/enrich_detections.py +++ b/security_content_automation/enrich_detections.py @@ -225,7 +225,6 @@ def main(): if supported_tas_list: keyname = "supported_tas" - enrich_detection_file(filepath, cim_version, "cim_version") enrich_detection_file(filepath, supported_tas_list, keyname) detection_ta_mapping[detection_file_name][ keyname @@ -237,6 +236,27 @@ def main(): [filepath.strip("security_content/")] ) + # Generating detection_ta_mapping yml file + try: + with io.open( + r"./security_content/security_content_automation/detection_ta_mapping.yml", + "w", + encoding="utf8", + ) as outfile: + yaml.safe_dump( + detection_ta_mapping, outfile, default_flow_style=False, allow_unicode=True + ) + + security_content_repo_obj.index.add( + ["security_content_automation/detection_ta_mapping.yml"] + ) + message = "Created detection_ta_mapping.yml file" + logging.info(message) + + except Exception as error: + error_message = f"Unexpected error occurred while generating detection_ta_mapping.yml file, {error}" + logging.error(error_message) + # Generating detection_ta_mapping CSV report try: @@ -264,26 +284,7 @@ def main(): logging.error(error_message) - # Generating detection_ta_mapping yml file - try: - with io.open( - r"./security_content/security_content_automation/detection_ta_mapping.yml", - "w", - encoding="utf8", - ) as outfile: - yaml.safe_dump( - detection_ta_mapping, outfile, default_flow_style=False, allow_unicode=True - ) - - security_content_repo_obj.index.add( - ["security_content_automation/detection_ta_mapping.yml"] - ) - message = "Created detection_ta_mapping.yml file" - logging.info(message) - - except Exception as error: - error_message = f"Unexpected error occurred while generating detection_ta_mapping.yml file, {error}" - logging.error(error_message) + try: From ddc594f451e399b47815a382a8118986867adf25 Mon Sep 17 00:00:00 2001 From: mjobanputra Date: Thu, 17 Feb 2022 17:16:21 +0530 Subject: [PATCH 25/25] Remove DA-ESS_AmazonWebServices_Content from pre-qa --- .gitlab-ci.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 13c1671a13..40b8bb9eb4 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -75,7 +75,7 @@ publish_build_to_pre_qa: script: - mkdir -p artifacts - pip install requests - - python security_content_automation/publish_build_to_pre_qa/publish_build_to_pre_qa.py --version $CI_COMMIT_REF_NAME --builds DA-ESS_AmazonWebServices_Content DA-ESS-ContentUpdate + - python security_content_automation/publish_build_to_pre_qa/publish_build_to_pre_qa.py --version $CI_COMMIT_REF_NAME --builds DA-ESS-ContentUpdate after_script: - cp publish_build_to_pre_qa.log artifacts/publish_build_to_pre_qa.log rules: