mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -48,6 +48,7 @@ tags:
|
||||
message: The process $process_name$ was spawned by $parent_process_name$ without
|
||||
any command-line arguments on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.009
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -56,6 +56,7 @@ tags:
|
||||
to bypass detection and preventative controls was identified on endpoint $dest$
|
||||
by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.010
|
||||
nist:
|
||||
- DE.CM
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
$parent_process_name$ on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1560.001
|
||||
- T1560
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
message: The following $process_name$ has been identified as renamed, spawning from
|
||||
$parent_process_name$ on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1569
|
||||
- T1569.002
|
||||
observable:
|
||||
- name: user
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
$parent_process_name$ on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1560.001
|
||||
- T1560
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -54,6 +54,7 @@ tags:
|
||||
and ieadvpack.dll by calling the LaunchINFSection function on the command line
|
||||
was identified on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -52,6 +52,7 @@ tags:
|
||||
and iesetupapi.dll by calling the LaunchINFSection function on the command line
|
||||
was identified on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -54,6 +54,7 @@ tags:
|
||||
by calling the LaunchINFSection function on the command line was identified on
|
||||
endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -52,6 +52,7 @@ tags:
|
||||
- Exploitation
|
||||
message: Suspicious rundll32.exe inline HTA execution on $dest$
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.005
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -45,10 +45,12 @@ tags:
|
||||
message: Possible SharpHound command-Line arguments identified on $dest$
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087.001
|
||||
- T1482
|
||||
- T1069.002
|
||||
- T1069.001
|
||||
- T1482
|
||||
- T1087.001
|
||||
- T1087
|
||||
- T1069.002
|
||||
- T1069
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -55,10 +55,12 @@ tags:
|
||||
message: Potential SharpHound file modifications identified on $dest$
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087.001
|
||||
- T1482
|
||||
- T1069.002
|
||||
- T1069.001
|
||||
- T1482
|
||||
- T1087.001
|
||||
- T1087
|
||||
- T1069.002
|
||||
- T1069
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -50,10 +50,12 @@ tags:
|
||||
message: Potential SharpHound binary identified on $dest$
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087.001
|
||||
- T1482
|
||||
- T1069.002
|
||||
- T1069.001
|
||||
- T1482
|
||||
- T1087.001
|
||||
- T1087
|
||||
- T1069.002
|
||||
- T1069
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
- Exploitation
|
||||
message: cmd.exe launching script interpreters on $dest$
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059.003
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -57,6 +57,7 @@ tags:
|
||||
message: Possible malicious WMI Subscription created on $dest$
|
||||
mitre_attack_id:
|
||||
- T1546.003
|
||||
- T1546
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -35,6 +35,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -33,6 +33,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
- Exploitation
|
||||
message: WevtUtil.exe used to disable Event Logging on $dest
|
||||
mitre_attack_id:
|
||||
- T1070
|
||||
- T1070.001
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
message: Disabled Registry Tools on $dest$
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -44,6 +44,8 @@ tags:
|
||||
mitre_attack_id:
|
||||
- T1564.001
|
||||
- T1562.001
|
||||
- T1564
|
||||
- T1562
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -37,6 +37,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1548.002
|
||||
- T1548
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
message: Disabled 'Windows App Hotkeys' on $dest$
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
message: Windows Defender real time behavior monitoring disabled on $dest
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
message: The Windows Smartscreen was disabled on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
message: The Windows command prompt was disabled on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
message: The Windows Control Panel was disabled on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
message: The Windows Firewall was disabled on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
message: The Windows Folder Options, to hide files, was disabled on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
start menu on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
Account Control (UAC) were modified on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1548.002
|
||||
- T1548
|
||||
nist:
|
||||
- PR.PT
|
||||
- DE.CM
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
$user$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
message: The Windows Task Manager was disabled on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
message: an instance of process $process_name$ with commandline $process$ in $dest$
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
message: an instance of process $process_name$ with commandline $process$ in $dest$
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
message: an instance of process $process_name$ with commandline $process$ in $dest$
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -37,6 +37,7 @@ tags:
|
||||
- Reconnaissance
|
||||
message: Domain group discovery enumeration using PowerShell on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1069
|
||||
- T1069.002
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
- Reconnaissance
|
||||
message: Domain group discovery enumeration on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1069
|
||||
- T1069.002
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
- Reconnaissance
|
||||
message: Domain group discovery enumeration on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1069
|
||||
- T1069.002
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
- Reconnaissance
|
||||
message: Domain group discovery enumeration on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1069
|
||||
- T1069.002
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -35,6 +35,7 @@ tags:
|
||||
- Exploitation
|
||||
message: process $SourceImage$ create a file $TargetImage$ in host $Computer$
|
||||
mitre_attack_id:
|
||||
- T1204
|
||||
- T1204.002
|
||||
observable:
|
||||
- name: Computer
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
accessing credentials using comsvcs.dll on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1003.001
|
||||
- T1003
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -54,6 +54,7 @@ tags:
|
||||
attempting to dump lsass.exe on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1003.001
|
||||
- T1003
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
- Reconnaissance
|
||||
message: Elevated domain group discovery enumeration on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1069
|
||||
- T1069.002
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
- Reconnaissance
|
||||
message: Elevated group discovery using PowerView on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1069
|
||||
- T1069.002
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
- Reconnaissance
|
||||
message: Elevated domain group discovery enumeration on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1069
|
||||
- T1069.002
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
cracking or observability.
|
||||
mitre_attack_id:
|
||||
- T1003.002
|
||||
- T1003
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -15,9 +15,9 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTim
|
||||
by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name Registry.registry_value_data | `security_content_ctime(lastTime)`
|
||||
| `security_content_ctime(firstTime)` | `etw_registry_disabled_filter`'
|
||||
how_to_implement: To successfully implement this search, you must be ingesting
|
||||
data that records registry activity from your hosts to populate the endpoint data
|
||||
model in the registry node. This is typically populated via endpoint detection-and-response
|
||||
how_to_implement: To successfully implement this search, you must be ingesting data
|
||||
that records registry activity from your hosts to populate the endpoint data model
|
||||
in the registry node. This is typically populated via endpoint detection-and-response
|
||||
product, such as Carbon Black or endpoint data sources, such as Sysmon. The data
|
||||
used for this search is typically generated via logs that report reads and writes
|
||||
to the registry.
|
||||
@@ -35,6 +35,7 @@ tags:
|
||||
mitre_attack_id:
|
||||
- T1562.006
|
||||
- T1127
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
by $user$.
|
||||
mitre_attack_id:
|
||||
- T1548.002
|
||||
- T1548
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
on endpoint $dest$ by user $user$, indicating potential suspicious macro execution.
|
||||
mitre_attack_id:
|
||||
- T1003.002
|
||||
- T1003
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -48,6 +48,7 @@ tags:
|
||||
on endpoint $dest$ by user $user$, indicating potential suspicious macro execution.
|
||||
mitre_attack_id:
|
||||
- T1003.002
|
||||
- T1003
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -48,6 +48,7 @@ tags:
|
||||
to disable services.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
|
||||
@@ -33,6 +33,7 @@ tags:
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1569
|
||||
- T1569.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
10 within 1m) has been detected on $dest$ with a parent process of $parent_process_name$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
where it tries to execute javascript using jscript.encode CLSID (COM OBJ), detected
|
||||
on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059.005
|
||||
observable:
|
||||
- name: user
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
message: process $process$ have double extensions in the file name is executed on
|
||||
$dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1036
|
||||
- T1036.003
|
||||
nist:
|
||||
- DE.CM
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
credentials executed on $dest$ by user $user$, with a parent process of $parent_process_id$
|
||||
mitre_attack_id:
|
||||
- T1003.002
|
||||
- T1003
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -55,6 +55,7 @@ tags:
|
||||
mitre_attack_id:
|
||||
- T1112
|
||||
- T1548.002
|
||||
- T1548
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
message: an instance of process $process_name$ with commandline $process$ in $dest$
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
message: powershell process having commandline $Message$ for user enumeration
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087
|
||||
observable:
|
||||
- name: ComputerName
|
||||
type: Hostname
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
message: an instance of process $process_name$ with commandline $process$ in $dest$
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -36,6 +36,7 @@ tags:
|
||||
message: powershell process having commandline $Message$ for user enumeration
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087
|
||||
observable:
|
||||
- name: ComputerName
|
||||
type: Hostname
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
- Reconnaissance
|
||||
message: System group discovery on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1069
|
||||
- T1069.001
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
Reference in New Issue
Block a user