From 73ba1285903b3a79a3f62d941442e0de4c51658d Mon Sep 17 00:00:00 2001 From: d1vious Date: Fri, 11 Feb 2022 12:11:10 -0500 Subject: [PATCH] fixing duplicate lookups bug --- bin/doc_gen.py | 5 ++++- bin/jinja2_templates/doc_detections.j2 | 2 ++ docs/_pages/detections.md | 4 ++-- .../2017-09-12-detect_new_login_attempts_to_routers.md | 2 ++ .../2017-09-13-detect_unauthorized_assets_by_mac_address.md | 2 ++ docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md | 2 ++ .../2017-09-19-email_attachments_with_lots_of_spaces.md | 2 ++ docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md | 2 ++ ...detect_attackers_scanning_for_vulnerable_jboss_servers.md | 2 ++ ...-23-detect_malicious_requests_to_exploit_jboss_servers.md | 2 ++ .../_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md | 2 ++ docs/_posts/2017-10-13-unusually_long_content-type_length.md | 2 ++ docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md | 2 ++ ...detect_spike_in_blocked_outbound_traffic_from_your_aws.md | 3 ++- docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md | 2 ++ docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md | 2 ++ ..._compute_instance_created_with_previously_unseen_image.md | 2 ++ docs/_posts/2018-10-23-wmi_permanent_event_subscription.md | 2 ++ docs/_posts/2018-10-23-wmi_temporary_event_subscription.md | 2 ++ docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md | 3 ++- docs/_posts/2018-12-03-remote_wmi_command_attempt.md | 2 ++ docs/_posts/2018-12-03-usn_journal_deletion.md | 2 ++ docs/_posts/2018-12-06-suspicious_java_classes.md | 2 ++ docs/_posts/2018-12-14-file_with_samsam_extension.md | 2 ++ docs/_posts/2018-12-14-samsam_test_file_write.md | 2 ++ docs/_posts/2019-01-25-processes_tapping_keyboard_events.md | 2 ++ .../2019-04-01-web_servers_executing_suspicious_processes.md | 2 ++ docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md | 2 ++ ...9-12-03-detect_credential_dumping_through_lsass_access.md | 2 ++ .../_posts/2019-12-03-detect_mimikatz_using_loaded_images.md | 2 ++ .../2019-12-06-access_lsass_memory_for_dump_creation.md | 2 ++ docs/_posts/2019-12-06-create_remote_thread_into_lsass.md | 2 ++ docs/_posts/2019-12-10-creation_of_shadow_copy.md | 2 ++ docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md | 2 ++ docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md | 2 ++ .../2020-01-28-monitor_registry_keys_for_print_monitors.md | 2 ++ .../2020-01-28-registry_keys_for_creating_shim_databases.md | 2 ++ docs/_posts/2020-01-28-sdclt_uac_bypass.md | 2 ++ docs/_posts/2020-01-28-silentcleanup_uac_bypass.md | 2 ++ docs/_posts/2020-01-28-wsreset_uac_bypass.md | 2 ++ .../_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md | 2 ++ docs/_posts/2020-02-07-macos_-_re-opened_applications.md | 2 ++ docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md | 2 ++ docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md | 2 ++ docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md | 2 ++ docs/_posts/2020-03-16-detect_rare_executables.md | 2 ++ docs/_posts/2020-03-16-process_execution_via_wmi.md | 2 ++ docs/_posts/2020-03-16-script_execution_via_wmi.md | 2 ++ docs/_posts/2020-03-16-spike_in_file_writes.md | 2 ++ ...020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md | 2 ++ .../2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md | 2 ++ .../2020-05-20-first_time_seen_child_process_of_zoom.md | 2 ++ ..._cross_account_activity_from_previously_unseen_account.md | 2 ++ .../2020-05-28-detect_aws_console_login_by_new_user.md | 2 ++ ...0-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md | 2 ++ ...03-detect_path_interception_by_creation_of_program_exe.md | 2 ++ docs/_posts/2020-07-06-short_lived_windows_accounts.md | 2 ++ docs/_posts/2020-07-06-windows_event_log_cleared.md | 2 ++ docs/_posts/2020-07-07-remote_desktop_network_traffic.md | 2 ++ docs/_posts/2020-07-08-detect_new_local_admin_account.md | 2 ++ .../2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md | 2 ++ docs/_posts/2020-07-21-attempt_to_stop_security_service.md | 2 ++ .../2020-07-21-detect_excessive_user_account_lockouts.md | 2 ++ docs/_posts/2020-07-21-detect_outbound_smb_traffic.md | 2 ++ .../2020-07-21-detect_outlook_exe_writing_a_zip_file.md | 2 ++ ...21-detect_use_of_cmd_exe_to_launch_script_interpreters.md | 2 ++ .../_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md | 2 ++ ...1-email_files_written_outside_of_the_outlook_directory.md | 2 ++ ...-21-email_servers_sending_high_volume_traffic_to_hosts.md | 2 ++ docs/_posts/2020-07-21-excessive_dns_failures.md | 2 ++ .../2020-07-21-first_time_seen_running_windows_service.md | 2 ++ ...020-07-21-hiding_files_and_directories_with_attrib_exe.md | 2 ++ ...iving_high_volume_of_network_traffic_from_email_server.md | 2 ++ ...malicious_powershell_process_-_execution_policy_bypass.md | 2 ++ ...e_okta_users_with_invalid_credentials_from_the_same_ip.md | 2 ++ docs/_posts/2020-07-21-okta_account_lockout_events.md | 2 ++ docs/_posts/2020-07-21-okta_failed_sso_attempts.md | 2 ++ .../2020-07-21-okta_user_logins_from_multiple_cities.md | 2 ++ docs/_posts/2020-07-21-overwriting_accessibility_binaries.md | 2 ++ docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md | 2 ++ docs/_posts/2020-07-21-protocol_or_port_mismatch.md | 2 ++ docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md | 2 ++ .../2020-07-21-remote_desktop_process_running_on_system.md | 2 ++ .../2020-07-21-sc_exe_manipulating_windows_services.md | 2 ++ docs/_posts/2020-07-21-sql_injection_with_long_urls.md | 2 ++ docs/_posts/2020-07-22-smb_traffic_spike.md | 2 ++ docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md | 2 ++ .../2020-07-22-suspicious_email_attachment_extensions.md | 2 ++ docs/_posts/2020-07-22-suspicious_reg_exe_process.md | 2 ++ .../2020-07-22-suspicious_writes_to_windows_recycle_bin.md | 2 ++ docs/_posts/2020-07-22-tor_traffic.md | 2 ++ docs/_posts/2020-07-22-unload_sysmon_filter_driver.md | 2 ++ docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md | 2 ++ docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md | 2 ++ docs/_posts/2020-07-27-aws_detect_role_creation.md | 2 ++ docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md | 2 ++ .../2020-07-27-aws_detect_sts_get_session_token_abuse.md | 2 ++ ...2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md | 2 ++ docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md | 2 ++ ...7-29-cloud_instance_modified_by_previously_unseen_user.md | 2 ++ docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md | 2 ++ .../_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md | 2 ++ .../2020-08-10-detect_gcp_storage_access_from_a_new_ip.md | 3 ++- docs/_posts/2020-08-11-detect_arp_poisoning.md | 2 ++ docs/_posts/2020-08-11-detect_rogue_dhcp_server.md | 2 ++ ...rovisioning_activity_from_previously_unseen_ip_address.md | 2 ++ ...ud_provisioning_activity_from_previously_unseen_region.md | 2 ++ ...21-abnormally_high_number_of_cloud_instances_destroyed.md | 2 ++ ...-21-abnormally_high_number_of_cloud_instances_launched.md | 2 ++ ...shing_email_detection_by_machine_learning_method_-_ssa.md | 2 ++ ...-08-25-system_process_running_from_unexpected_location.md | 2 ++ .../2020-08-25-unusual_lolbas_in_short_period_of_time.md | 2 ++ ...d_compute_instance_created_in_previously_unused_region.md | 2 ++ ...9-04-cloud_api_calls_from_previously_unseen_user_roles.md | 2 ++ ...normally_high_number_of_cloud_infrastructure_api_calls.md | 2 ++ ...normally_high_number_of_cloud_security_group_api_calls.md | 2 ++ ..._instance_created_with_previously_unseen_instance_type.md | 2 ++ docs/_posts/2020-09-15-detect_zerologon_via_zeek.md | 2 ++ ...20-09-16-create_or_delete_windows_shares_using_net_exe.md | 2 ++ ...0-09-18-detect_computer_changed_with_anonymous_account.md | 2 ++ ...0-10-07-detect_aws_console_login_by_user_from_new_city.md | 2 ++ ...0-07-detect_aws_console_login_by_user_from_new_country.md | 2 ++ ...10-07-detect_aws_console_login_by_user_from_new_region.md | 2 ++ docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md | 2 ++ ...loud_provisioning_activity_from_previously_unseen_city.md | 2 ++ ...d_provisioning_activity_from_previously_unseen_country.md | 2 ++ ...10-15-detect_activity_related_to_pass_the_hash_attacks.md | 2 ++ ...20-10-16-kerberoasting_spn_request_with_rc4_encryption.md | 2 ++ docs/_posts/2020-10-21-detect_kerberoasting.md | 2 ++ docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md | 2 ++ .../2020-10-28-detect_ipv6_network_infrastructure_threats.md | 2 ++ docs/_posts/2020-10-28-detect_port_security_violation.md | 2 ++ .../2020-10-28-detect_software_download_to_network_device.md | 2 ++ docs/_posts/2020-10-28-detect_traffic_mirroring.md | 2 ++ docs/_posts/2020-11-06-ryuk_test_files_detected.md | 2 ++ ..._powershell_execution_policy_to_unrestricted_or_bypass.md | 2 ++ .../2020-11-06-windows_security_account_manager_stopped.md | 2 ++ docs/_posts/2020-11-09-common_ransomware_extensions.md | 2 ++ docs/_posts/2020-11-09-common_ransomware_notes.md | 2 ++ docs/_posts/2020-11-09-deleting_shadow_copies.md | 2 ++ ...-11-09-detect_excessive_account_lockouts_from_endpoint.md | 2 ++ ...cesses_used_for_system_network_configuration_discovery.md | 2 ++ ...-11-10-detect_prohibited_applications_spawning_cmd_exe.md | 2 ++ .../2020-11-18-disabling_remote_user_account_control.md | 2 ++ .../2020-11-18-execution_of_file_with_multiple_extensions.md | 2 ++ ...-shim_database_installation_with_suspicious_parameters.md | 2 ++ ...26-reg_exe_manipulating_windows_services_registry_keys.md | 2 ++ docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md | 2 ++ docs/_posts/2020-12-08-shim_database_file_creation.md | 2 ++ docs/_posts/2020-12-08-single_letter_process_on_endpoint.md | 2 ++ ...0-12-08-system_processes_run_from_unexpected_locations.md | 2 ++ docs/_posts/2020-12-08-unusually_long_command_line.md | 2 ++ .../2020-12-08-wmi_permanent_event_subscription_-_sysmon.md | 2 ++ .../2020-12-14-sunburst_correlation_dll_and_network_event.md | 2 ++ docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md | 2 ++ ...-16-high_number_of_login_failures_from_a_single_source.md | 2 ++ ...020-12-16-o365_excessive_authentication_failures_alert.md | 2 ++ docs/_posts/2020-12-16-o365_pst_export_alert.md | 2 ++ .../2020-12-16-o365_suspicious_admin_email_forwarding.md | 2 ++ .../2020-12-16-o365_suspicious_user_email_forwarding.md | 2 ++ .../2020-12-17-scheduled_task_deleted_or_created_via_cmd.md | 2 ++ .../2020-12-21-bcdedit_failure_recovery_modification.md | 2 ++ docs/_posts/2021-01-06-supernova_webshell.md | 2 ++ ...ct_users_creating_keys_with_encrypt_policy_without_mfa.md | 2 ++ ...ws_detect_users_with_kms_keys_performing_encryption_s3.md | 2 ++ ...etwork_access_control_list_created_with_all_open_ports.md | 2 ++ .../2021-01-12-aws_network_access_control_list_deleted.md | 2 ++ ...021-01-12-suspicious_microsoft_workflow_compiler_usage.md | 2 ++ docs/_posts/2021-01-12-suspicious_msbuild_path.md | 2 ++ docs/_posts/2021-01-12-suspicious_msbuild_rename.md | 2 ++ docs/_posts/2021-01-12-suspicious_msbuild_spawn.md | 2 ++ docs/_posts/2021-01-12-suspicious_mshta_child_process.md | 2 ++ ...14-detect_hosts_connecting_to_dynamic_domain_providers.md | 2 ++ ...licious_powershell_process_with_obfuscation_techniques.md | 2 ++ .../2021-01-20-detect_rundll32_inline_hta_execution.md | 2 ++ docs/_posts/2021-01-20-suspicious_mshta_spawn.md | 2 ++ docs/_posts/2021-01-22-wbadmin_delete_system_backups.md | 2 ++ docs/_posts/2021-01-25-nltest_domain_trust_discovery.md | 2 ++ ...1-01-26-aws_saml_access_by_provider_user_and_principal.md | 2 ++ docs/_posts/2021-01-26-aws_saml_update_identity_provider.md | 2 ++ .../_posts/2021-01-26-certutil_exe_certificate_extraction.md | 2 ++ ...tect_spike_in_aws_security_hub_alerts_for_ec2_instance.md | 2 ++ ...01-26-detect_spike_in_aws_security_hub_alerts_for_user.md | 2 ++ .../2021-01-26-o365_add_app_role_assignment_grant_user.md | 2 ++ docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md | 2 ++ docs/_posts/2021-01-26-o365_new_federated_domain_added.md | 2 ++ docs/_posts/2021-01-26-revil_registry_entry.md | 2 ++ docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md | 2 ++ ...1-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md | 2 ++ .../2021-01-28-detect_regsvr32_application_control_bypass.md | 2 ++ docs/_posts/2021-01-28-ntdsutil_export_ntds.md | 2 ++ ...021-01-28-suspicious_regsvr32_register_suspicious_path.md | 2 ++ ...2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md | 2 ++ ...4-detect_rundll32_application_control_bypass_-_advpack.md | 2 ++ ...-detect_rundll32_application_control_bypass_-_setupapi.md | 2 ++ ...-detect_rundll32_application_control_bypass_-_syssetup.md | 2 ++ docs/_posts/2021-02-04-suspicious_rundll32_startw.md | 2 ++ .../2021-02-09-suspicious_rundll32_dllregisterserver.md | 2 ++ .../2021-02-11-detect_html_help_spawn_child_process.md | 2 ++ docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md | 2 ++ docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md | 2 ++ .../2021-02-16-detect_regasm_with_network_connection.md | 2 ++ .../2021-02-16-detect_regsvcs_with_network_connection.md | 2 ++ ...02-22-aws_create_policy_version_to_allow_all_resources.md | 2 ++ docs/_posts/2021-02-22-cobalt_strike_named_pipes.md | 2 ++ docs/_posts/2021-02-22-suspicious_curl_network_connection.md | 2 ++ docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md | 2 ++ .../2021-02-22-suspicious_plistbuddy_usage_via_osquery.md | 2 ++ .../2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md | 2 ++ docs/_posts/2021-03-01-any_powershell_downloadfile.md | 2 ++ docs/_posts/2021-03-01-any_powershell_downloadstring.md | 2 ++ docs/_posts/2021-03-01-fodhelper_uac_bypass.md | 2 ++ docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md | 2 ++ ...-03-01-suspicious_scheduled_task_from_public_directory.md | 2 ++ docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md | 2 ++ ...021-03-02-unified_messaging_service_spawning_a_process.md | 2 ++ .../_posts/2021-03-02-windows_disableantispyware_registry.md | 2 ++ docs/_posts/2021-03-03-nishang_powershelltcponeline.md | 2 ++ docs/_posts/2021-03-03-w3wp_spawning_shell.md | 2 ++ docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md | 2 ++ docs/_posts/2021-03-12-resize_shadowstorage_volume.md | 2 ++ docs/_posts/2021-03-16-high_file_deletion_frequency.md | 2 ++ docs/_posts/2021-03-16-high_process_termination_frequency.md | 2 ++ docs/_posts/2021-03-17-clop_common_exec_parameter.md | 2 ++ docs/_posts/2021-03-17-clop_ransomware_known_service_name.md | 2 ++ .../2021-03-17-process_deleting_its_process_file_path.md | 2 ++ ...23-certutil_download_with_urlcache_and_split_arguments.md | 2 ++ ...3-certutil_download_with_verifyctl_and_split_arguments.md | 2 ++ docs/_posts/2021-03-23-certutil_with_decode_argument.md | 2 ++ docs/_posts/2021-03-29-powershell_start-bitstransfer.md | 2 ++ docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md | 2 ++ docs/_posts/2021-03-31-disabling_firewall_with_netsh.md | 2 ++ docs/_posts/2021-03-31-dsquery_domain_discovery.md | 2 ++ .../2021-04-01-aws_iam_assume_role_policy_brute_force.md | 2 ++ docs/_posts/2021-04-01-aws_iam_delete_policy.md | 2 ++ docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md | 2 ++ .../2021-04-07-malicious_powershell_executed_as_a_service.md | 2 ++ ...users_failing_to_authenticate_from_host_using_kerberos.md | 2 ++ ...-08-winevent_scheduled_task_created_within_public_path.md | 2 ++ docs/_posts/2021-04-12-excel_spawning_powershell.md | 2 ++ docs/_posts/2021-04-12-excel_spawning_windows_script_host.md | 2 ++ ...1-04-12-winevent_scheduled_task_created_to_spawn_shell.md | 2 ++ docs/_posts/2021-04-12-winword_spawning_powershell.md | 2 ++ .../2021-04-12-winword_spawning_windows_script_host.md | 2 ++ docs/_posts/2021-04-13-aws_excessive_security_scanning.md | 2 ++ ..._attempting_to_authenticate_using_explicit_credentials.md | 2 ++ ...ple_users_failing_to_authenticate_from_host_using_ntlm.md | 2 ++ ...13-multiple_users_failing_to_authenticate_from_process.md | 2 ++ ...tiple_users_remotely_failing_to_authenticate_from_host.md | 2 ++ .../2021-04-13-office_application_spawn_rundll32_process.md | 2 ++ ...users_failing_to_authenticate_from_host_using_kerberos.md | 2 ++ ...users_failing_to_authenticate_from_host_using_kerberos.md | 2 ++ .../2021-04-14-office_document_creating_schedule_task.md | 2 ++ .../2021-04-14-office_document_executing_macro_code.md | 2 ++ .../_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md | 2 ++ ...lid_users_failing_to_authenticate_from_host_using_ntlm.md | 2 ++ ...9-gpupdate_with_no_command_line_arguments_with_network.md | 2 ++ ...4-19-powershell_remote_thread_to_known_windows_process.md | 2 ++ .../2021-04-19-schedule_task_with_http_command_arguments.md | 2 ++ ...2021-04-19-schedule_task_with_rundll32_command_trigger.md | 2 ++ ...-19-wermgr_process_connecting_to_ip_check_web_services.md | 2 ++ .../2021-04-19-wermgr_process_create_executable_file.md | 2 ++ ...04-19-wermgr_process_spawned_cmd_or_powershell_process.md | 2 ++ docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md | 2 ++ .../2021-04-21-multiple_archive_files_http_post_traffic.md | 2 ++ docs/_posts/2021-04-22-anomalous_usage_of_7zip.md | 2 ++ ...021-04-22-office_product_spawning_rundll32_with_no_dll.md | 2 ++ docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md | 2 ++ docs/_posts/2021-04-22-winword_spawning_cmd.md | 2 ++ docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md | 2 ++ docs/_posts/2021-04-26-office_product_spawning_certutil.md | 2 ++ docs/_posts/2021-04-26-office_product_spawning_mshta.md | 2 ++ docs/_posts/2021-04-26-trickbot_named_pipe.md | 2 ++ docs/_posts/2021-04-29-icacls_deny_command.md | 2 ++ docs/_posts/2021-04-29-suspicious_driver_loaded_path.md | 2 ++ docs/_posts/2021-04-29-xmrig_driver_loaded.md | 2 ++ docs/_posts/2021-05-04-deleting_of_net_users.md | 2 ++ docs/_posts/2021-05-04-disabling_net_user_account.md | 2 ++ .../2021-05-04-excessive_attempt_to_disable_services.md | 2 ++ docs/_posts/2021-05-04-excessive_service_stop_attempt.md | 2 ++ docs/_posts/2021-05-04-excessive_usage_of_taskkill.md | 2 ++ docs/_posts/2021-05-04-icacls_grant_command.md | 2 ++ .../2021-05-04-modify_acl_permission_to_files_or_folder.md | 2 ++ docs/_posts/2021-05-04-process_kill_base_on_file_path.md | 2 ++ docs/_posts/2021-05-05-suspicious_process_file_path.md | 2 ++ docs/_posts/2021-05-06-download_files_using_telegram.md | 2 ++ .../2021-05-06-enumerate_users_local_group_using_telegram.md | 2 ++ docs/_posts/2021-05-06-excessive_usage_of_net_app.md | 2 ++ ...5-06-executables_or_script_creation_in_suspicious_path.md | 2 ++ docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md | 2 ++ docs/_posts/2021-05-07-schtasks_run_task_on_demand.md | 2 ++ docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md | 2 ++ docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md | 2 ++ docs/_posts/2021-05-13-slui_runas_elevated.md | 2 ++ docs/_posts/2021-05-13-slui_spawning_a_process.md | 2 ++ docs/_posts/2021-05-18-services_escalate_exe.md | 2 ++ .../2021-05-19-allow_inbound_traffic_in_firewall_rule.md | 2 ++ docs/_posts/2021-05-19-mailsniper_invoke_functions.md | 2 ++ docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md | 2 ++ docs/_posts/2021-05-21-winrm_spawning_a_process.md | 2 ++ .../2021-05-26-secretdumps_offline_ntds_dumping_tool.md | 2 ++ .../2021-05-27-detect_sharphound_file_modifications.md | 2 ++ docs/_posts/2021-05-27-detect_sharphound_usage.md | 2 ++ .../2021-06-01-detect_azurehound_command-line_arguments.md | 2 ++ .../2021-06-01-detect_azurehound_file_modifications.md | 2 ++ .../2021-06-01-detect_sharphound_command-line_arguments.md | 2 ++ docs/_posts/2021-06-02-conti_common_exec_parameter.md | 2 ++ docs/_posts/2021-06-02-modification_of_wallpaper.md | 2 ++ docs/_posts/2021-06-02-revil_common_exec_parameter.md | 2 ++ docs/_posts/2021-06-02-wbemprox_com_object_execution.md | 2 ++ ...r_of_distinct_processes_created_in_windows_temp_folder.md | 2 ++ .../_posts/2021-06-04-known_services_killed_by_ransomware.md | 2 ++ .../2021-06-07-excessive_number_of_taskhost_processes.md | 2 ++ ...wershell_fileless_process_injection_via_getprocaddress.md | 2 ++ ...rshell_fileless_script_contains_base64_encoded_content.md | 2 ++ ...-09-detect_empire_with_powershell_script_block_logging.md | 2 ++ ...9-detect_mimikatz_with_powershell_script_block_logging.md | 2 ++ docs/_posts/2021-06-09-unloading_amsi_via_reflection.md | 2 ++ .../2021-06-10-clear_unallocated_sector_using_cipher_app.md | 2 ++ docs/_posts/2021-06-10-disable_logs_using_wevtutil.md | 2 ++ .../2021-06-10-permission_modification_using_takeown_app.md | 2 ++ docs/_posts/2021-06-10-powershell_creating_thread_mutex.md | 2 ++ docs/_posts/2021-06-10-powershell_domain_enumeration.md | 2 ++ ...ding_dotnet_into_memory_via_system_reflection_assembly.md | 2 ++ .../2021-06-10-powershell_processing_stream_of_data.md | 2 ++ .../2021-06-10-powershell_using_memory_as_backing_store.md | 2 ++ ...2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md | 2 ++ docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md | 2 ++ docs/_posts/2021-06-10-recon_using_wmi_class.md | 2 ++ .../2021-06-14-wmi_recon_running_process_or_services.md | 2 ++ docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md | 2 ++ docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md | 2 ++ .../2021-06-16-detect_wmi_event_subscription_persistence.md | 2 ++ .../2021-06-17-suspicious_event_log_service_behavior.md | 2 ++ .../2021-06-22-execute_javascript_with_jscript_com_clsid.md | 2 ++ .../2021-06-22-powershell_enable_smb1protocol_feature.md | 2 ++ .../2021-06-22-recursive_delete_of_directory_in_batch_cmd.md | 2 ++ ...2021-06-23-allow_file_and_printing_sharing_in_firewall.md | 2 ++ .../_posts/2021-06-23-allow_network_discovery_in_firewall.md | 2 ++ .../2021-06-24-excessive_usage_of_sc_service_utility.md | 2 ++ ...-excessive_number_of_service_control_start_as_disabled.md | 2 ++ .../2021-07-01-print_spooler_adding_a_printer_driver.md | 2 ++ .../2021-07-01-print_spooler_failed_to_load_a_plug-in.md | 2 ++ docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md | 2 ++ docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md | 2 ++ docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md | 2 ++ docs/_posts/2021-07-01-spoolsv_writing_a_dll.md | 2 ++ docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md | 2 ++ .../2021-07-05-msmpeng_application_dll_side_loading.md | 2 ++ .../2021-07-05-powershell_disable_security_monitoring.md | 2 ++ docs/_posts/2021-07-12-net_profiler_uac_bypass.md | 2 ++ docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md | 2 ++ ...oud_compute_instance_created_by_previously_unseen_user.md | 2 ++ docs/_posts/2021-07-19-aws_createaccesskey.md | 2 ++ docs/_posts/2021-07-19-aws_createloginprofile.md | 2 ++ docs/_posts/2021-07-19-aws_updateloginprofile.md | 2 ++ docs/_posts/2021-07-19-detect_new_open_s3_buckets.md | 2 ++ .../2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md | 2 ++ ...2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md | 2 ++ docs/_posts/2021-07-19-office_product_spawn_cmd_process.md | 2 ++ docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md | 2 ++ ...21-detect_copy_of_shadowcopy_with_script_block_logging.md | 2 ++ docs/_posts/2021-07-23-sam_database_file_access_attempt.md | 2 ++ .../2021-07-26-rundll32_createremotethread_in_browser.md | 2 ++ docs/_posts/2021-07-26-rundll32_dnsquery.md | 2 ++ .../2021-07-26-rundll32_process_creating_exe_dll_files.md | 2 ++ docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md | 2 ++ docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md | 2 ++ docs/_posts/2021-07-27-chcp_command_execution.md | 2 ++ .../2021-07-27-regsvr32_with_known_silent_switch_cmdline.md | 2 ++ .../2021-07-29-rundll32_create_remote_thread_to_a_process.md | 2 ++ docs/_posts/2021-07-30-drop_icedid_license_dat.md | 2 ++ .../2021-07-30-icedid_exfiltrated_archived_file_creation.md | 2 ++ .../2021-07-30-office_application_spawn_regsvr32_process.md | 2 ++ docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md | 2 ++ .../2021-08-04-create_remote_thread_in_shell_application.md | 2 ++ docs/_posts/2021-08-09-uninstall_app_using_msiexec.md | 2 ++ docs/_posts/2021-08-10-powershell_execute_com_object.md | 2 ++ docs/_posts/2021-08-11-fsutil_zeroing_file.md | 2 ++ docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md | 2 ++ .../2021-08-16-gsuite_drive_share_in_external_email.md | 2 ++ docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md | 2 ++ docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md | 2 ++ .../2021-08-17-aws_ecr_container_scanning_findings_high.md | 2 ++ ..._container_scanning_findings_low_informational_unknown.md | 2 ++ .../2021-08-17-aws_ecr_container_scanning_findings_medium.md | 2 ++ ...uite_outbound_email_with_attachment_to_external_domain.md | 2 ++ docs/_posts/2021-08-18-esentutl_sam_copy.md | 2 ++ docs/_posts/2021-08-18-powershell_4104_hunting.md | 2 ++ ...-08-19-aws_ecr_container_upload_outside_business_hours.md | 2 ++ .../2021-08-19-aws_ecr_container_upload_unknown_user.md | 2 ++ ...-08-19-gsuite_email_suspicious_subject_with_attachment.md | 2 ++ ...21-08-19-protocols_passing_authentication_in_cleartext.md | 2 ++ docs/_posts/2021-08-20-github_commit_changes_in_master.md | 2 ++ docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md | 2 ++ docs/_posts/2021-08-23-getlocaluser_with_powershell.md | 2 ++ .../2021-08-23-getlocaluser_with_powershell_script_block.md | 2 ++ .../2021-08-23-getwmiobject_user_account_with_powershell.md | 2 ++ ...getwmiobject_user_account_with_powershell_script_block.md | 2 ++ ...1-08-23-gsuite_email_with_known_abuse_web_service_link.md | 2 ++ docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md | 2 ++ docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md | 2 ++ docs/_posts/2021-08-24-adsisearcher_account_discovery.md | 2 ++ .../2021-08-24-domain_account_discovery_with_dsquery.md | 2 ++ .../2021-08-24-domain_account_discovery_with_net_app.md | 2 ++ docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md | 2 ++ docs/_posts/2021-08-24-get-domaintrust_with_powershell.md | 2 ++ ...021-08-24-get-domaintrust_with_powershell_script_block.md | 2 ++ docs/_posts/2021-08-24-get_aduser_with_powershell.md | 2 ++ .../2021-08-24-get_aduser_with_powershell_script_block.md | 2 ++ docs/_posts/2021-08-24-get_domainuser_with_powershell.md | 2 ++ ...2021-08-24-get_domainuser_with_powershell_script_block.md | 2 ++ .../2021-08-24-getwmiobject_ds_user_with_powershell.md | 2 ++ ...8-24-getwmiobject_ds_user_with_powershell_script_block.md | 2 ++ docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md | 2 ++ .../2021-08-25-domain_group_discovery_with_adsisearcher.md | 2 ++ docs/_posts/2021-08-25-domain_group_discovery_with_net.md | 2 ++ docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md | 2 ++ docs/_posts/2021-08-25-elevated_group_discovery_with_net.md | 2 ++ .../2021-08-25-elevated_group_discovery_with_powerview.md | 2 ++ docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md | 2 ++ docs/_posts/2021-08-25-getadgroup_with_powershell.md | 2 ++ .../2021-08-25-getadgroup_with_powershell_script_block.md | 2 ++ docs/_posts/2021-08-25-getdomaingroup_with_powershell.md | 2 ++ .../_posts/2021-08-25-getnettcpconnection_with_powershell.md | 2 ++ .../2021-08-25-getwmiobject_ds_group_with_powershell.md | 2 ++ ...-25-getwmiobject_ds_group_with_powershell_script_block.md | 2 ++ ...8-26-get_addefaultdomainpasswordpolicy_with_powershell.md | 2 ++ ...faultdomainpasswordpolicy_with_powershell_script_block.md | 2 ++ ...8-26-get_aduserresultantpasswordpolicy_with_powershell.md | 2 ++ ...erresultantpasswordpolicy_with_powershell_script_block.md | 2 ++ docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md | 2 ++ ...21-08-26-get_domainpolicy_with_powershell_script_block.md | 2 ++ ...2021-08-26-getdomaingroup_with_powershell_script_block.md | 2 ++ docs/_posts/2021-08-26-password_policy_discovery_with_net.md | 2 ++ ...08-26-process_creating_lnk_file_in_suspicious_location.md | 2 ++ docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md | 2 ++ docs/_posts/2021-08-27-exchange_powershell_module_usage.md | 2 ++ .../2021-08-30-domain_controller_discovery_with_nltest.md | 2 ++ docs/_posts/2021-08-30-remote_system_discovery_with_net.md | 2 ++ .../2021-08-31-petitpotam_network_share_access_request.md | 2 ++ .../2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md | 2 ++ .../2021-08-31-remote_system_discovery_with_dsquery.md | 2 ++ docs/_posts/2021-09-01-circle_ci_disable_security_step.md | 2 ++ .../2021-09-01-domain_controller_discovery_with_wmic.md | 2 ++ .../_posts/2021-09-01-domain_group_discovery_with_dsquery.md | 2 ++ .../2021-09-01-getadcomputer_with_powershell_script_block.md | 2 ++ ...-getwmiobject_ds_computer_with_powershell_script_block.md | 2 ++ docs/_posts/2021-09-01-github_commit_in_develop.md | 2 ++ docs/_posts/2021-09-01-github_dependabot_alert.md | 2 ++ .../2021-09-01-github_pull_request_from_unknown_user.md | 2 ++ .../2021-09-01-remote_system_discovery_with_adsisearcher.md | 2 ++ docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md | 2 ++ docs/_posts/2021-09-02-circle_ci_disable_security_job.md | 2 ++ docs/_posts/2021-09-02-get-foresttrust_with_powershell.md | 2 ++ ...021-09-02-get-foresttrust_with_powershell_script_block.md | 2 ++ ...1-09-02-getdomaincomputer_with_powershell_script_block.md | 2 ++ ...09-02-getdomaincontroller_with_powershell_script_block.md | 2 ++ .../2021-09-06-bcdedit_command_back_to_normal_mode_boot.md | 2 ++ .../2021-09-06-change_to_safe_mode_with_network_config.md | 2 ++ docs/_posts/2021-09-06-correlation_by_repository_and_risk.md | 2 ++ docs/_posts/2021-09-06-correlation_by_user_and_risk.md | 2 ++ docs/_posts/2021-09-07-getadcomputer_with_powershell.md | 2 ++ docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md | 2 ++ .../_posts/2021-09-07-getdomaincontroller_with_powershell.md | 2 ++ .../2021-09-07-getwmiobject_ds_computer_with_powershell.md | 2 ++ ...-schcache_change_by_app_connect_and_create_adsi_object.md | 2 ++ .../2021-09-07-system_information_discovery_detection.md | 2 ++ ...21-09-08-control_loading_from_world_writable_directory.md | 2 ++ .../2021-09-08-create_local_admin_accounts_using_net_exe.md | 2 ++ docs/_posts/2021-09-08-office_spawning_control.md | 2 ++ docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md | 2 ++ ...09-08-rundll32_control_rundll_world_writable_directory.md | 2 ++ docs/_posts/2021-09-09-extraction_of_registry_hives.md | 2 ++ .../2021-09-09-mshtml_module_load_in_office_product.md | 2 ++ ...09-10-getnettcpconnection_with_powershell_script_block.md | 2 ++ .../2021-09-10-network_connection_discovery_with_arp.md | 2 ++ .../2021-09-10-network_connection_discovery_with_net.md | 2 ++ .../2021-09-10-network_connection_discovery_with_netstat.md | 2 ++ docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md | 2 ++ docs/_posts/2021-09-13-getcurrent_user_with_powershell.md | 2 ++ ...021-09-13-getcurrent_user_with_powershell_script_block.md | 2 ++ .../_posts/2021-09-13-jscript_execution_using_cscript_app.md | 2 ++ .../2021-09-13-ms_scripting_process_loading_ldap_module.md | 2 ++ .../2021-09-13-ms_scripting_process_loading_wmi_module.md | 2 ++ docs/_posts/2021-09-13-office_application_drop_executable.md | 2 ++ docs/_posts/2021-09-13-system_user_discovery_with_query.md | 2 ++ docs/_posts/2021-09-13-system_user_discovery_with_whoami.md | 2 ++ .../2021-09-13-user_discovery_with_env_vars_powershell.md | 2 ++ ...3-user_discovery_with_env_vars_powershell_script_block.md | 2 ++ docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md | 2 ++ .../2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md | 2 ++ docs/_posts/2021-09-14-get_wmiobject_group_discovery.md | 2 ++ ...et_wmiobject_group_discovery_with_script_block_logging.md | 2 ++ docs/_posts/2021-09-14-net_localgroup_discovery.md | 2 ++ .../_posts/2021-09-14-powershell_get_localgroup_discovery.md | 2 ++ ...ell_get_localgroup_discovery_with_script_block_logging.md | 2 ++ docs/_posts/2021-09-14-wmic_group_discovery.md | 2 ++ docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md | 2 ++ ...-09-15-non_chrome_process_accessing_chrome_default_dir.md | 2 ++ ...1-09-15-non_firefox_process_access_firefox_profile_dir.md | 2 ++ docs/_posts/2021-09-16-account_discovery_with_net_app.md | 2 ++ ...21-09-16-attempt_to_add_certificate_to_untrusted_store.md | 2 ++ ...16-attempted_credential_dump_from_registry_via_reg_exe.md | 2 ++ docs/_posts/2021-09-16-batch_file_write_to_system32.md | 2 ++ docs/_posts/2021-09-16-bits_job_persistence.md | 2 ++ docs/_posts/2021-09-16-bitsadmin_download_file.md | 2 ++ ...09-16-creation_of_shadow_copy_with_wmic_and_powershell.md | 2 ++ ...6-credential_dumping_via_copy_command_from_shadow_copy.md | 2 ++ ...21-09-16-credential_dumping_via_symlink_to_shadow_copy.md | 2 ++ docs/_posts/2021-09-16-detect_html_help_renamed.md | 2 ++ .../2021-09-16-detect_html_help_url_in_command_line.md | 2 ++ ...09-16-detect_html_help_using_infotech_storage_handlers.md | 2 ++ docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md | 2 ++ docs/_posts/2021-09-16-detect_mshta_renamed.md | 2 ++ docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md | 2 ++ docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md | 2 ++ docs/_posts/2021-09-16-detect_renamed_7-zip.md | 2 ++ docs/_posts/2021-09-16-detect_renamed_psexec.md | 2 ++ docs/_posts/2021-09-16-detect_renamed_rclone.md | 2 ++ docs/_posts/2021-09-16-detect_renamed_winrar.md | 2 ++ docs/_posts/2021-09-16-dump_lsass_via_procdump.md | 2 ++ docs/_posts/2021-09-16-local_account_discovery_with_net.md | 2 ++ docs/_posts/2021-09-16-local_account_discovery_with_wmic.md | 2 ++ docs/_posts/2021-09-16-office_product_spawning_wmic.md | 2 ++ docs/_posts/2021-09-16-processes_launching_netsh.md | 2 ++ ...021-09-20-detect_regasm_with_no_command_line_arguments.md | 2 ++ ...21-09-20-detect_regsvcs_with_no_command_line_arguments.md | 2 ++ ...9-20-office_document_spawned_child_process_to_download.md | 2 ++ ...021-09-20-suspicious_dllhost_no_command_line_arguments.md | 2 ++ ...21-09-20-suspicious_gpupdate_no_command_line_arguments.md | 2 ++ ...21-09-20-suspicious_microsoft_workflow_compiler_rename.md | 2 ++ ...21-09-20-suspicious_rundll32_no_command_line_arguments.md | 2 ++ ...uspicious_searchprotocolhost_no_command_line_arguments.md | 2 ++ .../2021-09-21-remcos_rat_file_creation_in_remcos_folder.md | 2 ++ ...2021-09-21-suspicious_image_creation_in_appdata_folder.md | 2 ++ .../2021-09-21-suspicious_wav_file_in_appdata_folder.md | 2 ++ docs/_posts/2021-09-27-change_default_file_association.md | 2 ++ .../2021-09-27-logon_script_event_trigger_execution.md | 2 ++ .../_posts/2021-09-27-screensaver_event_trigger_execution.md | 2 ++ docs/_posts/2021-09-28-print_processor_registry_autostart.md | 2 ++ docs/_posts/2021-09-29-verclsid_clsid_execution.md | 2 ++ .../2021-10-01-vbscript_execution_using_wscript_app.md | 2 ++ ...021-10-04-msbuild_suspicious_spawned_by_script_process.md | 2 ++ ...21-10-04-regsvr32_silent_and_install_param_dll_loading.md | 2 ++ docs/_posts/2021-10-05-detect_exchange_web_shell.md | 2 ++ .../2021-10-05-malicious_inprocserver32_modification.md | 2 ++ docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md | 2 ++ docs/_posts/2021-10-05-rundll32_shimcache_flush.md | 2 ++ docs/_posts/2021-10-05-suspicious_copy_on_system32.md | 2 ++ docs/_posts/2021-10-05-winhlp32_spawning_a_process.md | 2 ++ ...21-10-06-dns_query_length_with_high_standard_deviation.md | 2 ++ docs/_posts/2021-10-06-sdelete_application_execution.md | 2 ++ ...2021-10-06-wscript_or_cscript_suspicious_child_process.md | 2 ++ docs/_posts/2021-10-11-suspicious_wevtutil_usage.md | 2 ++ ...13-dllhost_with_no_command_line_arguments_with_network.md | 2 ++ ...3-rundll32_with_no_command_line_arguments_with_network.md | 2 ++ ...3-searchprotocolhost_with_no_command_line_with_network.md | 2 ++ ...-10-14-serviceprincipalnames_discovery_with_powershell.md | 2 ++ ...2021-10-14-serviceprincipalnames_discovery_with_setspn.md | 2 ++ docs/_posts/2021-10-18-disable_schedule_task.md | 2 ++ .../2021-10-19-windows_curl_download_to_suspicious_path.md | 2 ++ ...9-winevent_windows_task_scheduler_event_action_started.md | 2 ++ .../2021-10-20-wmic_noninteractive_app_uninstallation.md | 2 ++ docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md | 2 ++ docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md | 2 ++ docs/_posts/2021-11-03-windows_adfind_exe.md | 2 ++ docs/_posts/2021-11-04-attacker_tools_on_endpoint.md | 2 ++ ...e_token_or_hash_observed_by_an_event_collecting_device.md | 2 ++ .../2021-11-10-windows_curl_upload_to_remote_destination.md | 2 ++ ...2021-11-10-windows_service_creation_on_remote_endpoint.md | 2 ++ ...21-11-10-windows_service_initiation_on_remote_endpoint.md | 2 ++ ...11-11-remote_process_instantiation_via_winrm_and_winrs.md | 2 ++ ...11-scheduled_task_creation_on_remote_endpoint_using_at.md | 2 ++ ...021-11-11-scheduled_task_initiation_on_remote_endpoint.md | 2 ++ .../2021-11-11-schtasks_scheduling_job_on_remote_system.md | 2 ++ docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md | 2 ++ .../2021-11-12-aws_iam_accessdenied_discovery_events.md | 2 ++ docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md | 2 ++ docs/_posts/2021-11-12-firewall_allowed_program_enable.md | 2 ++ .../2021-11-12-network_discovery_using_route_windows_app.md | 2 ++ .../2021-11-12-remote_process_instantiation_via_wmi.md | 2 ++ docs/_posts/2021-11-12-runas_execution_in_commandline.md | 2 ++ .../2021-11-12-windows_installutil_credential_theft.md | 2 ++ ...21-11-12-windows_installutil_remote_network_connection.md | 2 ++ .../2021-11-12-windows_installutil_uninstall_option.md | 2 ++ ...1-12-windows_installutil_uninstall_option_with_network.md | 2 ++ .../2021-11-12-windows_installutil_url_in_command_line.md | 2 ++ ...5-remote_process_instantiation_via_dcom_and_powershell.md | 2 ++ ...ess_instantiation_via_dcom_and_powershell_script_block.md | 2 ++ ...15-remote_process_instantiation_via_wmi_and_powershell.md | 2 ++ ...cess_instantiation_via_wmi_and_powershell_script_block.md | 2 ++ docs/_posts/2021-11-15-sdelete_application_execution.md | 2 ++ docs/_posts/2021-11-15-windows_diskcryptor_usage.md | 2 ++ ...21-11-16-high_frequency_copy_of_files_in_network_share.md | 2 ++ ...-remote_process_instantiation_via_winrm_and_powershell.md | 2 ++ ...ss_instantiation_via_winrm_and_powershell_script_block.md | 2 ++ docs/_posts/2021-11-17-windows_dism_remove_defender.md | 2 ++ ...18-executable_file_written_in_administrative_smb_share.md | 2 ++ ...interactive_session_on_remote_endpoint_with_powershell.md | 2 ++ docs/_posts/2021-11-18-loading_of_dynwrapx_module.md | 2 ++ ...1-11-19-system_info_gathering_using_dxdiag_application.md | 2 ++ docs/_posts/2021-11-22-anomalous_usage_of_archive_tools.md | 2 ++ .../2021-11-22-possible_browser_pass_view_parameter.md | 2 ++ .../2021-11-22-services_lolbas_execution_process_spawn.md | 2 ++ .../2021-11-22-svchost_lolbas_execution_process_spawn.md | 2 ++ ...2-windows_service_created_with_suspicious_service_path.md | 2 ++ .../2021-11-22-windows_service_created_within_public_path.md | 2 ++ .../2021-11-22-wmiprsve_lolbas_execution_process_spawn.md | 2 ++ .../2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md | 2 ++ docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md | 2 ++ docs/_posts/2021-11-24-attempt_to_delete_services.md | 2 ++ docs/_posts/2021-11-24-attempt_to_disable_services.md | 2 ++ .../2021-11-25-add_or_set_windows_defender_exclusion.md | 2 ++ ...1-11-25-powershell_windows_defender_exclusion_commands.md | 2 ++ .../2021-11-25-windows_defender_exclusion_registry_entry.md | 2 ++ ...29-attempted_credential_dump_from_registry_via_reg_exe.md | 2 ++ .../_posts/2021-11-29-deny_permission_using_cacls_utility.md | 2 ++ .../2021-11-29-detect_dump_lsass_memory_using_comsvcs.md | 2 ++ docs/_posts/2021-11-29-detect_rclone_command-line_usage.md | 2 ++ .../2021-11-29-possible_lateral_movement_powershell_spawn.md | 2 ++ .../2021-11-29-randomly_generated_scheduled_task_name.md | 2 ++ .../2021-11-29-randomly_generated_windows_service_name.md | 2 ++ docs/_posts/2021-11-30-delete_a_net_user.md | 2 ++ docs/_posts/2021-11-30-disable_net_user_account.md | 2 ++ .../2021-11-30-first_time_seen_command_line_argument.md | 2 ++ .../2021-11-30-grant_permission_using_cacls_utility.md | 2 ++ .../2021-11-30-modify_acls_permission_of_files_or_folders.md | 2 ++ ...s_the_token_or_hash_observed_at_the_destination_device.md | 2 ++ .../2021-11-30-rare_parent-child_process_relationship.md | 2 ++ docs/_posts/2021-11-30-resize_shadowstorage_volume.md | 2 ++ ...1-unusual_number_of_computer_service_tickets_requested.md | 2 ++ ...nusual_number_of_remote_endpoint_authentication_events.md | 2 ++ docs/_posts/2021-12-03-detect_rclone_command-line_usage.md | 2 ++ docs/_posts/2021-12-03-short_lived_scheduled_task.md | 2 ++ .../2021-12-03-windows_curl_upload_to_remote_destination.md | 2 ++ .../2021-12-07-anomalous_usage_of_account_credentials.md | 2 ++ .../2021-12-07-bcdedit_failure_recovery_modification.md | 2 ++ .../_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md | 2 ++ .../2021-12-07-excessive_number_of_office_files_copied.md | 2 ++ docs/_posts/2021-12-07-fsutil_zeroing_file.md | 2 ++ docs/_posts/2021-12-07-high_file_deletion_frequency.md | 2 ++ ...ailbox_replication_service_writing_active_server_pages.md | 2 ++ docs/_posts/2021-12-07-wbadmin_delete_system_backups.md | 2 ++ .../2021-12-07-windows_raccine_scheduled_task_deletion.md | 2 ++ .../_posts/2021-12-08-disable_defender_antivirus_registry.md | 2 ++ .../2021-12-08-msi_module_loaded_by_non-system_binary.md | 2 ++ docs/_posts/2021-12-10-curl_download_and_bash_execution.md | 2 ++ docs/_posts/2021-12-11-wget_download_and_bash_execution.md | 2 ++ docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md | 2 ++ ...2021-12-13-java_class_file_download_by_java_user_agent.md | 2 ++ docs/_posts/2021-12-13-linux_java_spawning_shell.md | 2 ++ .../2021-12-13-log4shell_jndi_payload_injection_attempt.md | 2 ++ ...4shell_jndi_payload_injection_with_outbound_connection.md | 2 ++ ...bound_network_connection_from_java_using_default_ports.md | 2 ++ docs/_posts/2021-12-13-windows_java_spawning_shells.md | 2 ++ docs/_posts/2021-12-14-hunting_for_log4shell.md | 2 ++ ...021-12-17-linux_add_files_in_known_crontab_directories.md | 2 ++ .../_posts/2021-12-17-linux_at_allow_config_file_creation.md | 2 ++ docs/_posts/2021-12-17-linux_at_application_execution.md | 2 ++ docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md | 2 ++ ...-linux_possible_append_command_to_at_allow_config_file.md | 2 ++ ...possible_append_cronjob_entry_on_existing_cronjob_file.md | 2 ++ ...-12-17-linux_possible_cronjob_modification_with_editor.md | 2 ++ .../2021-12-20-clear_unallocated_sector_using_cipher_app.md | 2 ++ ...021-12-20-hiding_files_and_directories_with_attrib_exe.md | 2 ++ .../2021-12-20-linux_file_creation_in_init_boot_directory.md | 2 ++ .../2021-12-20-linux_file_creation_in_profile_directory.md | 2 ++ ...0-linux_possible_append_command_to_profile_config_file.md | 2 ++ ...-12-20-linux_service_file_created_in_systemd_directory.md | 2 ++ docs/_posts/2021-12-20-linux_service_restarted.md | 2 ++ docs/_posts/2021-12-20-linux_service_started_or_enabled.md | 2 ++ .../2021-12-20-suspicious_computer_account_name_change.md | 2 ++ .../2021-12-20-suspicious_kerberos_service_ticket_request.md | 2 ++ docs/_posts/2021-12-21-linux_add_user_account.md | 2 ++ docs/_posts/2021-12-21-linux_change_file_owner_to_root.md | 2 ++ .../2021-12-21-linux_nopasswd_entry_in_sudoers_file.md | 2 ++ docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md | 2 ++ docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md | 2 ++ docs/_posts/2021-12-21-linux_visudo_utility_execution.md | 2 ++ .../2021-12-21-suspicious_ticket_granting_ticket_request.md | 2 ++ ...21-12-22-linux_file_created_in_kernel_driver_directory.md | 2 ++ ...-12-22-linux_insert_kernel_module_using_insmod_utility.md | 2 ++ ...-22-linux_install_kernel_module_using_modprobe_utility.md | 2 ++ docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md | 2 ++ .../2021-12-23-linux_common_process_for_elevation_control.md | 2 ++ docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md | 2 ++ docs/_posts/2022-01-04-linux_sudo_or_su_execution.md | 2 ++ docs/_posts/2022-01-05-linux_doas_conf_file_creation.md | 2 ++ docs/_posts/2022-01-05-linux_doas_tool_execution.md | 2 ++ .../2022-01-10-linux_possible_access_to_credential_files.md | 2 ++ .../2022-01-10-linux_possible_access_to_sudoers_file.md | 2 ++ ...ux_possible_access_or_modification_of_sshd_config_file.md | 2 ++ .../2022-01-11-linux_possible_ssh_key_file_creation.md | 2 ++ ...12-powershell_-_connect_to_internet_with_hidden_window.md | 2 ++ ...2-01-12-windows_hunting_system_account_targeting_lsass.md | 2 ++ .../2022-01-12-windows_non-system_account_targeting_lsass.md | 2 ++ .../2022-01-14-potentially_malicious_code_on_commandline.md | 2 ++ .../2022-01-18-cmd_carry_out_string_command_parameter.md | 2 ++ ...01-18-impacket_lateral_movement_commandline_parameters.md | 2 ++ ...2-01-18-malicious_powershell_process_-_encoded_command.md | 2 ++ ...-suspicious_process_dns_query_known_abuse_web_services.md | 2 ++ .../2022-01-19-suspicious_process_with_discord_dns_query.md | 2 ++ .../2022-01-19-windows_dotnet_binary_in_non_standard_path.md | 2 ++ .../2022-01-19-windows_installutil_in_non_standard_path.md | 2 ++ ...22-01-20-excessive_file_deletion_in_windefender_folder.md | 2 ++ docs/_posts/2022-01-20-ping_sleep_batch_command.md | 2 ++ ...022-01-20-powershell_remove_windows_defender_directory.md | 2 ++ docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md | 2 ++ docs/_posts/2022-01-24-windows_nirsoft_utilities.md | 2 ++ docs/_posts/2022-01-26-active_setup_registry_autostart.md | 2 ++ .../2022-01-26-add_defaultuser_and_password_in_registry.md | 2 ++ ...-01-26-allow_inbound_traffic_by_firewall_rule_registry.md | 2 ++ docs/_posts/2022-01-26-allow_operation_with_consent_admin.md | 2 ++ docs/_posts/2022-01-26-disable_amsi_through_registry.md | 2 ++ .../_posts/2022-01-26-disable_defender_antivirus_registry.md | 2 ++ .../2022-01-26-disable_defender_blockatfirstseen_feature.md | 2 ++ .../2022-01-26-disable_defender_enhanced_notification.md | 2 ++ docs/_posts/2022-01-26-disable_defender_mpengine_registry.md | 2 ++ docs/_posts/2022-01-26-disable_defender_spynet_reporting.md | 2 ++ ...-01-26-disable_defender_submit_samples_consent_feature.md | 2 ++ docs/_posts/2022-01-26-registry_keys_used_for_persistence.md | 2 ++ ...2022-01-26-registry_keys_used_for_privilege_escalation.md | 2 ++ .../2022-01-26-remcos_client_registry_install_entry.md | 2 ++ docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md | 2 ++ docs/_posts/2022-01-26-time_provider_persistence_registry.md | 2 ++ docs/_posts/2022-01-27-disable_etw_through_registry.md | 2 ++ docs/_posts/2022-01-27-disable_registry_tool.md | 2 ++ ...2022-01-27-disable_security_logs_using_minint_registry.md | 2 ++ docs/_posts/2022-01-27-disable_show_hidden_files.md | 2 ++ docs/_posts/2022-01-27-disable_uac_remote_restriction.md | 2 ++ docs/_posts/2022-01-27-disable_windows_app_hotkeys.md | 2 ++ .../_posts/2022-01-27-disable_windows_behavior_monitoring.md | 2 ++ .../2022-01-27-disable_windows_smartscreen_protection.md | 2 ++ docs/_posts/2022-01-27-disabling_cmd_application.md | 2 ++ docs/_posts/2022-01-27-disabling_controlpanel.md | 2 ++ .../_posts/2022-01-27-windows_possible_credential_dumping.md | 2 ++ docs/_posts/2022-01-28-disabling_defender_services.md | 2 ++ .../2022-01-28-disabling_folderoptions_windows_feature.md | 2 ++ docs/_posts/2022-01-28-disabling_norun_windows_app.md | 2 ++ .../_posts/2022-01-28-disabling_systemrestore_in_registry.md | 2 ++ docs/_posts/2022-01-28-disabling_task_manager.md | 2 ++ docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md | 2 ++ .../2022-01-28-enable_wdigest_uselogoncredential_registry.md | 2 ++ docs/_posts/2022-01-28-etw_registry_disabled.md | 2 ++ docs/_posts/2022-01-28-eventvwr_uac_bypass.md | 2 ++ .../2022-01-28-hide_user_account_from_sign-in_screen.md | 2 ++ docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md | 2 ++ docs/_posts/2022-02-03-o365_added_service_principal.md | 2 ++ docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md | 2 ++ docs/_posts/2022-02-03-o365_disable_mfa.md | 2 ++ docs/_stories/credential_dumping.md | 2 +- docs/_stories/windows_defense_evasion_tactics.md | 2 +- docs/_stories/windows_persistence_techniques.md | 2 +- 754 files changed, 1507 insertions(+), 9 deletions(-) diff --git a/bin/doc_gen.py b/bin/doc_gen.py index 0e5ba698ec..83c71a4cdb 100644 --- a/bin/doc_gen.py +++ b/bin/doc_gen.py @@ -345,11 +345,14 @@ def generate_doc_detections(REPO_PATH, OUTPUT_DIR, TEMPLATE_PATH, attack, messag additional_detection_lookups = parse_and_add_lookups(detection_yaml['search'], lookups) if len(additional_detection_lookups) > 0: for lookup in additional_detection_lookups: + # skip duplicate lookups + if lookup in detection_lookups: + continue detection_lookups.append(lookup) detection_yaml['lookups'] = detection_lookups detection_yaml['lookups'] = detection_lookups - # sort macros and lookups + # sort macros and lookups sorted_macros = sorted(detection_yaml['macros'], key=lambda i: i['name']) detection_yaml['macros'] = sorted_macros sorted_lookups = sorted(detection_yaml['lookups'], key=lambda i: i['name']) diff --git a/bin/jinja2_templates/doc_detections.j2 b/bin/jinja2_templates/doc_detections.j2 index 0d6f20535d..06e358a438 100644 --- a/bin/jinja2_templates/doc_detections.j2 +++ b/bin/jinja2_templates/doc_detections.j2 @@ -119,6 +119,8 @@ The SPL above uses the following Lookups: | {{(detection.tags.impact * detection.tags.confidence)/100}} | {{ detection.tags.impact }} | {{ detection.tags.confidence }} | {{detection.tags.message}} | {% endif %} +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + {% if detection.cve %} #### CVE diff --git a/docs/_pages/detections.md b/docs/_pages/detections.md index 4886efadc9..cb94713d5c 100644 --- a/docs/_pages/detections.md +++ b/docs/_pages/detections.md @@ -61,8 +61,8 @@ sidebar: | [Attempt To Delete Services](/endpoint/attempt_to_delete_services/) | [Service Stop](/tags/#service-stop), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | | [Attempt To Disable Services](/endpoint/attempt_to_disable_services/) | [Service Stop](/tags/#service-stop) | TTP | | [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [OS Credential Dumping](/tags/#os-credential-dumping), [Security Account Manager](/tags/#security-account-manager) | TTP | +| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Auto Admin Logon Registry Entry](/endpoint/auto_admin_logon_registry_entry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials) | TTP | | [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | @@ -357,8 +357,8 @@ sidebar: | [Gsuite Suspicious Shared File Name](/cloud/gsuite_suspicious_shared_file_name/) | [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing) | Anomaly | | [Gsuite suspicious calendar invite](/cloud/gsuite_suspicious_calendar_invite/) | [Phishing](/tags/#phishing) | Hunting | | [Hide User Account From Sign-In Screen](/endpoint/hide_user_account_from_sign-in_screen/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | -| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | | [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | +| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | | [High File Deletion Frequency](/endpoint/high_file_deletion_frequency/) | [Data Destruction](/tags/#data-destruction) | Anomaly | | [High File Deletion Frequency](/endpoint/high_file_deletion_frequency/) | [Data Destruction](/tags/#data-destruction) | Anomaly | | [High Frequency Copy Of Files In Network Share](/endpoint/high_frequency_copy_of_files_in_network_share/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | Anomaly | diff --git a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md index a29b070bbd..848b89865f 100644 --- a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md +++ b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md @@ -73,6 +73,8 @@ Legitimate router connections may appear as new connections +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md index 650696bef5..91ad0bfa73 100644 --- a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md +++ b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md @@ -76,6 +76,8 @@ This search might be prone to high false positives. Please consider this when co +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md index bb8a83c18d..02bbc6f802 100644 --- a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md +++ b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md @@ -75,6 +75,8 @@ None identified +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md index d6b8c5a242..c286a458fc 100644 --- a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md +++ b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md @@ -79,6 +79,8 @@ None at this time +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md index 57c4a26d94..4cd80b693d 100644 --- a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md +++ b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md @@ -82,6 +82,8 @@ Legitimate ANY requests may trigger this search, however it is unusual to see a +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md index de8511ad97..ac6c61880c 100644 --- a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md @@ -82,6 +82,8 @@ It's possible for legitimate HTTP requests to be made to URLs containing the +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md index 8447ccf664..e47cff84db 100644 --- a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md @@ -76,6 +76,8 @@ No known false positives for this detection. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md index 8ba02f7477..e3249233cd 100644 --- a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md +++ b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md @@ -76,6 +76,8 @@ None at this time +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2017-10-13-unusually_long_content-type_length.md b/docs/_posts/2017-10-13-unusually_long_content-type_length.md index 6718992b26..3d88168e32 100644 --- a/docs/_posts/2017-10-13-unusually_long_content-type_length.md +++ b/docs/_posts/2017-10-13-unusually_long_content-type_length.md @@ -70,6 +70,8 @@ Very few legitimate Content-Type fields will have a length greater than 100 char +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md index 8a28c1e6b1..ebddea9d5a 100644 --- a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md +++ b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md @@ -82,6 +82,8 @@ None at this time +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md index c5aaa5955d..87d7d44189 100644 --- a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md +++ b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md @@ -60,7 +60,6 @@ Note that `detect_spike_in_blocked_outbound_traffic_from_your_aws_filter` is a e #### Lookups The SPL above uses the following Lookups: -* [baseline_blocked_outbound_connections](https://github.com/splunk/security_content/blob/develop/lookups/baseline_blocked_outbound_connections.yml) with [data](https://github.com/splunk/security_content/blob/develop/lookups/baseline_blocked_outbound_connections.csv) * [baseline_blocked_outbound_connections](https://github.com/splunk/security_content/blob/develop/lookups/baseline_blocked_outbound_connections.yml) with [data](https://github.com/splunk/security_content/blob/develop/lookups/baseline_blocked_outbound_connections.csv) #### Required field @@ -89,6 +88,8 @@ The false-positive rate may vary based on the values of`dataPointThreshold` and +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md index d70a6dff23..41a8a13207 100644 --- a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md +++ b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md @@ -85,6 +85,8 @@ ICMP packets are used in a variety of ways to help troubleshoot networking issue +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md index 512a5e1674..cb49e6796c 100644 --- a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md +++ b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md @@ -87,6 +87,8 @@ S3 buckets can be accessed from any IP, as long as it can make a successful conn +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md b/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md index b0177d256b..f9970a7d43 100644 --- a/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md +++ b/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md @@ -87,6 +87,8 @@ After a new image is created, the first systems created with that image will cau | 36.0 | 60 | 60 | User $user$ is creating an instance $dest$ with an image that has not been previously seen. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md index 992b0179b8..ae51645314 100644 --- a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md @@ -83,6 +83,8 @@ Although unlikely, administrators may use event subscriptions for legitimate pur +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md index af9d904ab3..f05b2a1938 100644 --- a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md @@ -81,6 +81,8 @@ Some software may create WMI temporary event subscriptions for various purposes. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md index 118bb9a794..9f9d2527e6 100644 --- a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md +++ b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md @@ -73,7 +73,6 @@ Note that `detect_spike_in_s3_bucket_deletion_filter` is a empty macro by defaul #### Lookups The SPL above uses the following Lookups: -* [s3_deletion_baseline](https://github.com/splunk/security_content/blob/develop/lookups/s3_deletion_baseline.yml) with [data](https://github.com/splunk/security_content/blob/develop/lookups/s3_deletion_baseline.csv) * [s3_deletion_baseline](https://github.com/splunk/security_content/blob/develop/lookups/s3_deletion_baseline.yml) with [data](https://github.com/splunk/security_content/blob/develop/lookups/s3_deletion_baseline.csv) #### Required field @@ -98,6 +97,8 @@ Based on the values of`dataPointThreshold` and `deviationThreshold`, the false p +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-12-03-remote_wmi_command_attempt.md b/docs/_posts/2018-12-03-remote_wmi_command_attempt.md index 99f1a25afc..cf71ad52d2 100644 --- a/docs/_posts/2018-12-03-remote_wmi_command_attempt.md +++ b/docs/_posts/2018-12-03-remote_wmi_command_attempt.md @@ -89,6 +89,8 @@ Administrators may use this legitimately to gather info from remote systems. Fil | 36.0 | 60 | 60 | A wmic.exe process $process$ contain node commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-12-03-usn_journal_deletion.md b/docs/_posts/2018-12-03-usn_journal_deletion.md index d018df239f..a17ff3cde3 100644 --- a/docs/_posts/2018-12-03-usn_journal_deletion.md +++ b/docs/_posts/2018-12-03-usn_journal_deletion.md @@ -89,6 +89,8 @@ None identified | 45.0 | 50 | 90 | Possible USN journal deletion on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-12-06-suspicious_java_classes.md b/docs/_posts/2018-12-06-suspicious_java_classes.md index 9f628dca7d..2552d5f088 100644 --- a/docs/_posts/2018-12-06-suspicious_java_classes.md +++ b/docs/_posts/2018-12-06-suspicious_java_classes.md @@ -77,6 +77,8 @@ There are no known false positives. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-12-14-file_with_samsam_extension.md b/docs/_posts/2018-12-14-file_with_samsam_extension.md index e661f24ff2..2773fd90af 100644 --- a/docs/_posts/2018-12-14-file_with_samsam_extension.md +++ b/docs/_posts/2018-12-14-file_with_samsam_extension.md @@ -78,6 +78,8 @@ Because these extensions are not typically used in normal operations, you should | 90.0 | 100 | 90 | File writes $file_name$ with extensions consistent with a SamSam ransomware attack seen on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2018-12-14-samsam_test_file_write.md b/docs/_posts/2018-12-14-samsam_test_file_write.md index a341cf6aa9..4098507a1d 100644 --- a/docs/_posts/2018-12-14-samsam_test_file_write.md +++ b/docs/_posts/2018-12-14-samsam_test_file_write.md @@ -85,6 +85,8 @@ No false positives have been identified. | 12.0 | 60 | 20 | A samsam ransomware test file creation in $file_path$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md index 2616237784..f2542e5ca7 100644 --- a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md +++ b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md @@ -72,6 +72,8 @@ There might be some false positives as keyboard event taps are used by processes +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md index 8bf22f477b..080ebe2dda 100644 --- a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md +++ b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md @@ -82,6 +82,8 @@ Some of these processes may be used legitimately on web servers during maintenan +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md index c00539a07e..754067fe76 100644 --- a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md +++ b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md @@ -80,6 +80,8 @@ Some legitimate applications use long command lines for installs or updates. You +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md b/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md index b8752e8916..76c6a4b899 100644 --- a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md +++ b/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md @@ -93,6 +93,8 @@ The activity may be legitimate. Other tools can access lsass for legitimate reas | 80.0 | 80 | 100 | The $source_image$ has attempted access to read $TargetImage$ was identified on endpoint $Computer$, this is indicative of credential dumping and should be investigated. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md b/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md index 2544b67105..a5da0aaa95 100644 --- a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md +++ b/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md @@ -93,6 +93,8 @@ Other tools can import the same DLLs. These tools should be part of a whitelist. | 64.0 | 80 | 80 | A process, $Image$, has loaded $ImageLoaded$ that are typically related to credential dumping on $Computer$. Review for further details. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md b/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md index 37dd81d3d9..9720416e8d 100644 --- a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md +++ b/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md @@ -91,6 +91,8 @@ Administrators can create memory dumps for debugging purposes, but memory dumps | 63.0 | 70 | 90 | process $SourceImage$ injected into $TargetImage$ and was attempted dump LSASS on $dest$. Adversaries tend to do this when trying to accesss credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md b/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md index 2048c716cc..c81e475186 100644 --- a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md +++ b/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md @@ -91,6 +91,8 @@ Other tools can access LSASS for legitimate reasons and generate an event. In th | 81.0 | 90 | 90 | A process has created a remote thread into $TargetImage$ on $dest$. This behavior is indicative of credential dumping and should be investigated. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2019-12-10-creation_of_shadow_copy.md b/docs/_posts/2019-12-10-creation_of_shadow_copy.md index 40cc22dc54..cf986ef1a7 100644 --- a/docs/_posts/2019-12-10-creation_of_shadow_copy.md +++ b/docs/_posts/2019-12-10-creation_of_shadow_copy.md @@ -96,6 +96,8 @@ Legitimate administrator usage of Vssadmin or Wmic will create false positives. | 81.0 | 90 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to create a shadow copy to perform offline password cracking. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md index 7b02d1d34c..83bd3fd38d 100644 --- a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md +++ b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md @@ -100,6 +100,8 @@ If you are seeing more results than desired, you may consider reducing the value +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md b/docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md index 507f417639..2f3c482246 100644 --- a/docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md +++ b/docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md @@ -93,6 +93,8 @@ unknown | 63.0 | 70 | 90 | modified registry key $registry_key_name$ with registry value $registry_value_name$ to prepare autoadminlogon | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md b/docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md index 81920e53a7..624903ecfb 100644 --- a/docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md +++ b/docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md @@ -97,6 +97,8 @@ You will encounter noise from legitimate print-monitor registry entries. | 64.0 | 80 | 80 | New print monitor added on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md b/docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md index 03cfb71d14..cf0d71a0bc 100644 --- a/docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md +++ b/docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md @@ -95,6 +95,8 @@ There are many legitimate applications that leverage shim databases for compatib | 56.0 | 70 | 80 | A registry activity in $registry_path$ related to shim modication in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-01-28-sdclt_uac_bypass.md b/docs/_posts/2020-01-28-sdclt_uac_bypass.md index 0bd5b88d45..9402aa992d 100644 --- a/docs/_posts/2020-01-28-sdclt_uac_bypass.md +++ b/docs/_posts/2020-01-28-sdclt_uac_bypass.md @@ -95,6 +95,8 @@ Limited to no false positives are expected. | 63.0 | 70 | 90 | Suspicious modification of registry $registry_path$ with possible payload path $registry_value_name$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-01-28-silentcleanup_uac_bypass.md b/docs/_posts/2020-01-28-silentcleanup_uac_bypass.md index 9d3155d8dd..bee604b8bc 100644 --- a/docs/_posts/2020-01-28-silentcleanup_uac_bypass.md +++ b/docs/_posts/2020-01-28-silentcleanup_uac_bypass.md @@ -95,6 +95,8 @@ unknown | 63.0 | 70 | 90 | Suspicious modification of registry $registry_path$ with possible payload path $registry_value_name$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-01-28-wsreset_uac_bypass.md b/docs/_posts/2020-01-28-wsreset_uac_bypass.md index bf55049c5e..c6b5cc762a 100644 --- a/docs/_posts/2020-01-28-wsreset_uac_bypass.md +++ b/docs/_posts/2020-01-28-wsreset_uac_bypass.md @@ -95,6 +95,8 @@ unknown | 63.0 | 70 | 90 | Suspicious modification of registry $registry_path$ with possible payload path $registry_value_name$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md b/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md index d049b94220..bc225fe201 100644 --- a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md +++ b/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md @@ -89,6 +89,8 @@ Administrators can create memory dumps for debugging purposes, but memory dumps | 80.0 | 80 | 100 | $process_name$ was identified on endpoint $Computer$ writing $TargetFilename$ to disk. This behavior is related to dumping credentials via Task Manager. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md index 7c75058eb1..0cc6f59d08 100644 --- a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md +++ b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md @@ -74,6 +74,8 @@ At this stage, there are no known false positives. During testing, no process ev +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md index f25313b1db..82801cdac1 100644 --- a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md +++ b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md @@ -71,6 +71,8 @@ Uploading container is a normal behavior from developers or users with access to +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md b/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md index 58a3f74610..9a1c8938a9 100644 --- a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md +++ b/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md @@ -99,6 +99,8 @@ None identified. | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified accessing credentials using comsvcs.dll on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md index a6933d540a..0b3d076c32 100644 --- a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md +++ b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md @@ -85,6 +85,8 @@ Some legitimate printer-related processes may show up as children of spoolsv.exe +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2020-03-16-detect_rare_executables.md b/docs/_posts/2020-03-16-detect_rare_executables.md index 0058f2d863..ef38c3b72f 100644 --- a/docs/_posts/2020-03-16-detect_rare_executables.md +++ b/docs/_posts/2020-03-16-detect_rare_executables.md @@ -89,6 +89,8 @@ Some legitimate processes may be only rarely executed in your environment. As th +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-03-16-process_execution_via_wmi.md b/docs/_posts/2020-03-16-process_execution_via_wmi.md index d2cd92fb5d..0c34939b1d 100644 --- a/docs/_posts/2020-03-16-process_execution_via_wmi.md +++ b/docs/_posts/2020-03-16-process_execution_via_wmi.md @@ -86,6 +86,8 @@ Although unlikely, administrators may use wmi to execute commands for legitimate | 49.0 | 70 | 70 | A remote instance execution of wmic.exe that will spawn $parent_process_name$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-03-16-script_execution_via_wmi.md b/docs/_posts/2020-03-16-script_execution_via_wmi.md index e402a87aaa..94fcfce857 100644 --- a/docs/_posts/2020-03-16-script_execution_via_wmi.md +++ b/docs/_posts/2020-03-16-script_execution_via_wmi.md @@ -84,6 +84,8 @@ Although unlikely, administrators may use wmi to launch scripts for legitimate p | 36.0 | 60 | 60 | A wmic.exe process $process_name$ taht execute script in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-03-16-spike_in_file_writes.md b/docs/_posts/2020-03-16-spike_in_file_writes.md index a59bbb1860..7d30285671 100644 --- a/docs/_posts/2020-03-16-spike_in_file_writes.md +++ b/docs/_posts/2020-03-16-spike_in_file_writes.md @@ -72,6 +72,8 @@ It is important to understand that if you happen to install any new applications +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md index d025fd1699..c0450ba2ee 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md @@ -86,6 +86,8 @@ Not all unauthenticated requests are malicious, but frequency, UA and source IPs +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md index 17c2446de2..0bfa556de7 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md @@ -87,6 +87,8 @@ Not all unauthenticated requests are malicious, but frequency, UA and source IPs +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md index 8eecb3d6b6..8328714ed0 100644 --- a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md +++ b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md @@ -98,6 +98,8 @@ A new child process of zoom isn't malicious by that fact alone. Further inve | 64.0 | 80 | 80 | Child process $process_name$ with $process_id$ spawned by zoom.exe or zoom.us which has not been previously on host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md b/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md index 69ba49d44f..7bb0458e75 100644 --- a/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md +++ b/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md @@ -88,6 +88,8 @@ Using multiple AWS accounts and roles is perfectly valid behavior. It's susp | 15.0 | 30 | 50 | AWS account $requestingAccountId$ is trying to access resource from some other account $requestedAccountId$, for the first time. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md b/docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md index 0fce192856..5fdf216414 100644 --- a/docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md +++ b/docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md @@ -83,6 +83,8 @@ When a legitimate new user logins for the first time, this activity will be dete | 30.0 | 50 | 60 | User $user$ is logging into the AWS console for the first time | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md index 3730b87892..42eaf133ce 100644 --- a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md +++ b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md @@ -70,6 +70,8 @@ Kubectl calls are not malicious by nature. However source IP, verb and Object ca +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md b/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md index 813182bc81..05b514b13f 100644 --- a/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md +++ b/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md @@ -107,6 +107,8 @@ unknown | 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to perform privilege escalation by using unquoted service paths. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-06-short_lived_windows_accounts.md b/docs/_posts/2020-07-06-short_lived_windows_accounts.md index e5be7ad3b3..cb7a0c7403 100644 --- a/docs/_posts/2020-07-06-short_lived_windows_accounts.md +++ b/docs/_posts/2020-07-06-short_lived_windows_accounts.md @@ -90,6 +90,8 @@ It is possible that an administrator created and deleted an account in a short t | 63.0 | 70 | 90 | A user account created or delete shortly in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-06-windows_event_log_cleared.md b/docs/_posts/2020-07-06-windows_event_log_cleared.md index 57d853aa82..2ad60b568b 100644 --- a/docs/_posts/2020-07-06-windows_event_log_cleared.md +++ b/docs/_posts/2020-07-06-windows_event_log_cleared.md @@ -88,6 +88,8 @@ It is possible that these logs may be legitimately cleared by Administrators. Fi | 70.0 | 70 | 100 | Windows event logs cleared on $dest$ via EventCode $EventCode$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md index a9c2867f01..f46820f9d4 100644 --- a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md +++ b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md @@ -90,6 +90,8 @@ Remote Desktop may be used legitimately by users on the network. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-08-detect_new_local_admin_account.md b/docs/_posts/2020-07-08-detect_new_local_admin_account.md index cd752c0445..d3698f594c 100644 --- a/docs/_posts/2020-07-08-detect_new_local_admin_account.md +++ b/docs/_posts/2020-07-08-detect_new_local_admin_account.md @@ -92,6 +92,8 @@ The activity may be legitimate. For this reason, it's best to verify the acc | 42.0 | 60 | 70 | A $user$ on $dest$ was added recently. Identify if this was legitimate behavior or not. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md index 644215088e..6602bbd27d 100644 --- a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md +++ b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md @@ -82,6 +82,8 @@ Not all unauthenticated requests are malicious, but frequency, User Agent, sourc +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-attempt_to_stop_security_service.md b/docs/_posts/2020-07-21-attempt_to_stop_security_service.md index 1700025a46..640772987e 100644 --- a/docs/_posts/2020-07-21-attempt_to_stop_security_service.md +++ b/docs/_posts/2020-07-21-attempt_to_stop_security_service.md @@ -107,6 +107,8 @@ None identified. Attempts to disable security-related services should be identif | 20.0 | 40 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified attempting to disable security services on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md b/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md index c09fd3030f..339506e5a8 100644 --- a/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md +++ b/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md @@ -95,6 +95,8 @@ It is possible that a legitimate user is experiencing an issue causing multiple | 36.0 | 60 | 60 | Multiple accounts have been locked out. Review $nodename$ and $result$ related to $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md index 6daa9cb924..05665d5f90 100644 --- a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md +++ b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md @@ -91,6 +91,8 @@ It is likely that the outbound Server Message Block (SMB) traffic is legitimate, +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md index 3e2be95791..5875eb63cb 100644 --- a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md +++ b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md @@ -98,6 +98,8 @@ It is not uncommon for outlook to write legitimate zip files to the disk. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md b/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md index cf1e0799bb..25b405aee7 100644 --- a/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md +++ b/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md @@ -92,6 +92,8 @@ Some legitimate applications may exhibit this behavior. | 35.0 | 70 | 50 | cmd.exe launching script interpreters on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md index ee97b67dbd..2ef9392175 100644 --- a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md +++ b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md @@ -83,6 +83,8 @@ While legitimate, these NirSoft tools are prone to abuse. You should verfiy that +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md index b63d8cc813..7a644734ff 100644 --- a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md +++ b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md @@ -86,6 +86,8 @@ Administrators and users sometimes prefer backing up their email data by moving +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md index 4c77199c8d..26adafdea7 100644 --- a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md +++ b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md @@ -88,6 +88,8 @@ The false-positive rate will vary based on how you set the deviation_threshold a +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-excessive_dns_failures.md b/docs/_posts/2020-07-21-excessive_dns_failures.md index 8c7dbc4d95..f6b6c27dd8 100644 --- a/docs/_posts/2020-07-21-excessive_dns_failures.md +++ b/docs/_posts/2020-07-21-excessive_dns_failures.md @@ -89,6 +89,8 @@ It is possible legitimate traffic can trigger this rule. Please investigate as a +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md index 0cfa41e016..2e9cc0e635 100644 --- a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md +++ b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md @@ -92,6 +92,8 @@ A previously unseen service is not necessarily malicious. Verify that the servic +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md b/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md index 937eaa4ef4..bc8abe10ed 100644 --- a/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md +++ b/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md @@ -91,6 +91,8 @@ Some applications and users may legitimately use attrib.exe to interact with the | 72.0 | 90 | 80 | Attrib.exe with +h flag to hide files on $dest$ executed by $user$ is detected. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md index 7a3b372e04..65412214de 100644 --- a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md +++ b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md @@ -87,6 +87,8 @@ The false-positive rate will vary based on how you set the deviation_threshold a +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md b/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md index 16d1e18ac8..8807d6c973 100644 --- a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md +++ b/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md @@ -99,6 +99,8 @@ There may be legitimate reasons to bypass the PowerShell execution policy. The P | 42.0 | 70 | 60 | PowerShell local execution policy bypass attempt on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md index 175776fcce..6fe60a80fb 100644 --- a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md +++ b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md @@ -93,6 +93,8 @@ A single public IP address servicing multiple legitmate users may trigger this s +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-okta_account_lockout_events.md b/docs/_posts/2020-07-21-okta_account_lockout_events.md index bd50c4d8bd..db2367dad0 100644 --- a/docs/_posts/2020-07-21-okta_account_lockout_events.md +++ b/docs/_posts/2020-07-21-okta_account_lockout_events.md @@ -86,6 +86,8 @@ None. Account lockouts should be followed up on to determine if the actual user +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md index 42ec91189a..d80fb2a790 100644 --- a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md +++ b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md @@ -89,6 +89,8 @@ There may be a faulty config preventing legitmate users from accessing apps they +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md index 11374bc0b6..e017844871 100644 --- a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md +++ b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md @@ -89,6 +89,8 @@ Users in your enviornment may legitmately be travelling and loggin in from diffe +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md b/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md index 4560df7a7d..06c68fd3bd 100644 --- a/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md +++ b/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md @@ -91,6 +91,8 @@ Microsoft may provide updates to these binaries. Verify that these changes do no | 72.0 | 80 | 90 | A suspicious file modification or replace in $file_path$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md index a647aff3b4..1a8d02af91 100644 --- a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md +++ b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md @@ -86,6 +86,8 @@ None identified +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md index d942cebac8..ff7a201b66 100644 --- a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md +++ b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md @@ -86,6 +86,8 @@ None identified +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md index 1c63cbe857..b973bd6e19 100644 --- a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md +++ b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md @@ -87,6 +87,8 @@ RDP gateways may have unusually high amounts of traffic from all other hosts' +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md index c3185d4581..2f38a78798 100644 --- a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md +++ b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md @@ -86,6 +86,8 @@ Remote Desktop may be used legitimately by users on the network. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md b/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md index 8fec1118f7..a763a52d23 100644 --- a/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md +++ b/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md @@ -97,6 +97,8 @@ Using sc.exe to manipulate Windows services is uncommon. However, there may be l | 56.0 | 70 | 80 | A sc process $process_name$ with commandline $process$ to create of configure services in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md index 34b695b410..138a0ff6ee 100644 --- a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md +++ b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md @@ -83,6 +83,8 @@ It's possible that legitimate traffic will have long URLs or long user agent +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-22-smb_traffic_spike.md b/docs/_posts/2020-07-22-smb_traffic_spike.md index 3baccd2a57..ce817934d8 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike.md @@ -89,6 +89,8 @@ A file server may experience high-demand loads that could cause this analytic to +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md index 663c2347ee..866e70a22a 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md @@ -95,6 +95,8 @@ If you are seeing more results than desired, you may consider reducing the value +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md index 806848820d..ead71021d1 100644 --- a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md +++ b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md @@ -94,6 +94,8 @@ None identified +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-22-suspicious_reg_exe_process.md b/docs/_posts/2020-07-22-suspicious_reg_exe_process.md index c3c8055857..443fe3d7b7 100644 --- a/docs/_posts/2020-07-22-suspicious_reg_exe_process.md +++ b/docs/_posts/2020-07-22-suspicious_reg_exe_process.md @@ -98,6 +98,8 @@ It's possible for system administrators to write scripts that exhibit this b | 35.0 | 70 | 50 | Suspicious $Processes.process_path.file_path$ process running with an uncommon parent process $Processes.parent_process_name$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md b/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md index a0f5deef09..61c497c2e7 100644 --- a/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md +++ b/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md @@ -89,6 +89,8 @@ Because the Recycle Bin is a hidden folder in modern versions of Windows, it wou | 28.0 | 40 | 70 | Suspicious writes to windows Recycle Bin process $Processes.process_name$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-22-tor_traffic.md b/docs/_posts/2020-07-22-tor_traffic.md index ff46982a56..46b8a629d9 100644 --- a/docs/_posts/2020-07-22-tor_traffic.md +++ b/docs/_posts/2020-07-22-tor_traffic.md @@ -89,6 +89,8 @@ None at this time +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md b/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md index 0431142e13..f81ae6c0d0 100644 --- a/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md +++ b/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md @@ -92,6 +92,8 @@ You must be ingesting data that records process activity from your hosts to popu | 45.0 | 50 | 90 | Possible Sysmon filter driver unloading on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md index b3133924c0..f7408a07a5 100644 --- a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md +++ b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md @@ -77,6 +77,8 @@ Attach to policy can create a lot of noise. This search can be adjusted to provi +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md index 7502eaf8c5..a0af3f9bd7 100644 --- a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md @@ -87,6 +87,8 @@ Not all permanent key creations are malicious. If there is a policy of rotating +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-27-aws_detect_role_creation.md b/docs/_posts/2020-07-27-aws_detect_role_creation.md index f3231b38ce..1b2a99dfb9 100644 --- a/docs/_posts/2020-07-27-aws_detect_role_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_role_creation.md @@ -92,6 +92,8 @@ CreateRole is not very common in common users. This search can be adjusted to pr +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md index 93512639cb..1613443534 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md @@ -86,6 +86,8 @@ Sts:AssumeRole can be very noisy as it is a standard mechanism to provide cross +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md index b23ae8e210..96891cb8e8 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md @@ -85,6 +85,8 @@ Sts:GetSessionToken can be very noisy as in certain environments numerous calls +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md index 9323d26dfc..a1cd428847 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md @@ -81,6 +81,8 @@ unknown +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md index 63600160c2..5b76d34377 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md @@ -85,6 +85,8 @@ unknown +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md b/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md index 8eafba8ea8..be533680fe 100644 --- a/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md +++ b/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md @@ -107,6 +107,8 @@ It's possible that a new user will start to modify EC2 instances when they h | 42.0 | 70 | 60 | User $user$ is modifying an instance $dest$ for the first time. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md index f4c0fbe13c..16079da667 100644 --- a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md +++ b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md @@ -74,6 +74,8 @@ unknown +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md index 14c665d98a..408775f3bd 100644 --- a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md +++ b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md @@ -89,6 +89,8 @@ While this search has no known false positives, it is possible that a GCP admin +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md index fedd690d65..931f8d21a0 100644 --- a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md +++ b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md @@ -71,7 +71,6 @@ Note that `detect_gcp_storage_access_from_a_new_ip_filter` is a empty macro by d #### Lookups The SPL above uses the following Lookups: -* [previously_seen_gcp_storage_access_from_remote_ip](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_gcp_storage_access_from_remote_ip.yml) with [data](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_gcp_storage_access_from_remote_ip.csv) * [previously_seen_gcp_storage_access_from_remote_ip](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_gcp_storage_access_from_remote_ip.yml) with [data](https://github.com/splunk/security_content/blob/develop/lookups/previously_seen_gcp_storage_access_from_remote_ip.csv) #### Required field @@ -99,6 +98,8 @@ GCP Storage buckets can be accessed from any IP (if the ACLs are open to allow i +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-08-11-detect_arp_poisoning.md b/docs/_posts/2020-08-11-detect_arp_poisoning.md index d3149ab70a..0c0affcd73 100644 --- a/docs/_posts/2020-08-11-detect_arp_poisoning.md +++ b/docs/_posts/2020-08-11-detect_arp_poisoning.md @@ -99,6 +99,8 @@ This search might be prone to high false positives if DHCP Snooping or ARP inspe +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md index 05f56898c8..ad46b2f7b8 100644 --- a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md +++ b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md @@ -91,6 +91,8 @@ This search might be prone to high false positives if DHCP Snooping has been inc +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md index 318efa433e..d608b315f6 100644 --- a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md +++ b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md @@ -101,6 +101,8 @@ This is a strictly behavioral search, so we define "false positive" slig | 42.0 | 70 | 60 | User $user$ is starting or creating an instance $object_id$ for the first time from IP address $src$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md index 21f87098ed..a6d25cadc8 100644 --- a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md +++ b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md @@ -103,6 +103,8 @@ This is a strictly behavioral search, so we define "false positive" slig | 42.0 | 70 | 60 | User $user$ is starting or creating an instance $object$ for the first time in region $Region$ from IP address $src$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md index 5940234596..cc144f830a 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md @@ -101,6 +101,8 @@ Many service accounts configured within a cloud infrastructure are known to exhi +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md index 82d970f5a6..07a2a6ecc6 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md @@ -102,6 +102,8 @@ Many service accounts configured within an AWS infrastructure are known to exhib +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md index 322ec6b390..bfef2b3a5c 100644 --- a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md +++ b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md @@ -76,6 +76,8 @@ Because of imbalance of anomaly data in training, the model will less likely rep +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md b/docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md index 279195b74f..a8c7f7b4b9 100644 --- a/docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md +++ b/docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md @@ -107,6 +107,8 @@ None | 56.0 | 70 | 80 | A system process $process_name$ with commandline $cmd_line$ spawn in non-default folder path in host $dest_device_id$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-08-25-unusual_lolbas_in_short_period_of_time.md b/docs/_posts/2020-08-25-unusual_lolbas_in_short_period_of_time.md index 528fce7e55..a927fb39b3 100644 --- a/docs/_posts/2020-08-25-unusual_lolbas_in_short_period_of_time.md +++ b/docs/_posts/2020-08-25-unusual_lolbas_in_short_period_of_time.md @@ -91,6 +91,8 @@ Some administrative tasks may involve multiple use of LOLBAS applications in a s | 25.0 | 50 | 50 | A system process $process_name$ with commandline $cmd_line$ spawn iin short period of time in host $dest_device_id$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md b/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md index c9bc14e27a..25c8be3565 100644 --- a/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md +++ b/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md @@ -95,6 +95,8 @@ It's possible that a user has unknowingly started an instance in a new regio | 42.0 | 70 | 60 | User $user$ is creating an instance $dest$ in a new region for the first time | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md b/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md index adf8061f2b..a54753a5cb 100644 --- a/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md +++ b/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md @@ -99,6 +99,8 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. | 36.0 | 60 | 60 | User $user$ of type AssumedRole attempting to execute new API calls $command$ that have not been seen before | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md index fc57c804cd..76971e4519 100644 --- a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md +++ b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md @@ -104,6 +104,8 @@ You must be ingesting your cloud infrastructure logs. You also must run the base | 15.0 | 30 | 50 | user $user$ has made $api_calls$ api calls, violating the dynamic threshold of $expected_upper_threshold$ with the following command $command$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md index 04d5b163ee..6171b9d95b 100644 --- a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md +++ b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md @@ -105,6 +105,8 @@ You must be ingesting your cloud infrastructure logs. You also must run the base | 15.0 | 30 | 50 | user $user$ has made $api_calls$ api calls related to security groups, violating the dynamic threshold of $expected_upper_threshold$ with the following command $command$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md b/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md index 37cfa4fa3d..572695b587 100644 --- a/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md +++ b/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md @@ -87,6 +87,8 @@ It is possible that an admin will create a new system using a new instance type | 30.0 | 50 | 60 | User $user$ is creating an instance $dest$ with an instance type $instance_type$ that has not been previously seen. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md index 5ef8f28acd..58ac2575e2 100644 --- a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md +++ b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md @@ -76,6 +76,8 @@ unknown +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md b/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md index 2b9a1fff54..50661ff540 100644 --- a/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md +++ b/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md @@ -98,6 +98,8 @@ Administrators often leverage net.exe to create or delete network shares. You sh | 25.0 | 50 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ enumerating Windows file shares. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md index d042182027..712c18cfda 100644 --- a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md +++ b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md @@ -84,6 +84,8 @@ None thus far found | 49.0 | 70 | 70 | The following $EventCode$ occurred on $dest$ by $user$ with Logon Type 3, which may be indicative of the an account or group being changed by an anonymous account. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md index be200b8866..cd08353b6c 100644 --- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md +++ b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md @@ -100,6 +100,8 @@ When a legitimate new user logins for the first time, this activity will be dete | 18.0 | 30 | 60 | User $user$ is logging into the AWS console from City $City$ for the first time | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md index 86d9ccef2e..47b3f573b2 100644 --- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md +++ b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md @@ -100,6 +100,8 @@ When a legitimate new user logins for the first time, this activity will be dete | 42.0 | 70 | 60 | User $user$ is logging into the AWS console from Country $Country$ for the first time | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md index c6a060077f..e1cd06a4c3 100644 --- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md +++ b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md @@ -100,6 +100,8 @@ When a legitimate new user logins for the first time, this activity will be dete | 36.0 | 60 | 60 | User $user$ is logging into the AWS console from Region $Region$ for the first time | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md index ccc371a6f9..bff0afad11 100644 --- a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md +++ b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md @@ -83,6 +83,8 @@ Payload.request.function.timeout value can possibly be match with other function +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md index 221794b79f..6acbb8edca 100644 --- a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md +++ b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md @@ -103,6 +103,8 @@ This is a strictly behavioral search, so we define "false positive" slig | 18.0 | 30 | 60 | User $user$ is starting or creating an instance $dest$ for the first time in City $City$ from IP address $src$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md index 206c30f0dc..1b3ec960ca 100644 --- a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md +++ b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md @@ -102,6 +102,8 @@ This is a strictly behavioral search, so we define "false positive" slig | 42.0 | 70 | 60 | User $user$ is starting or creating an instance $object$ for the first time in Country $Country$ from IP address $src$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md index fe82571a0e..e20802e283 100644 --- a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md +++ b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md @@ -92,6 +92,8 @@ Legitimate logon activity by authorized NTLM systems may be detected by this sea | 49.0 | 70 | 70 | The following $EventCode$ occurred on $dest$ by $user$ with Logon Type 3, which may be indicative of the pass the hash technique. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md b/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md index c90715d4c2..9ed99bc712 100644 --- a/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md +++ b/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md @@ -89,6 +89,8 @@ Older systems that support kerberos RC4 by default NetApp may generate false pos | 72.0 | 90 | 80 | Potential kerberoasting attack via service principal name requests detected on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-21-detect_kerberoasting.md b/docs/_posts/2020-10-21-detect_kerberoasting.md index 91b3dfab1b..ac558b4614 100644 --- a/docs/_posts/2020-10-21-detect_kerberoasting.md +++ b/docs/_posts/2020-10-21-detect_kerberoasting.md @@ -92,6 +92,8 @@ Older systems that support kerberos RC4 by default NetApp may generate false pos | 14.0 | 70 | 20 | Kerberoasting malware is potentially applying stolen credentials. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md index eaf0ed902d..4a5f5a5d5c 100644 --- a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md +++ b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md @@ -88,6 +88,8 @@ Unknown +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md index 68d02f63e0..f97b961bed 100644 --- a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md +++ b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md @@ -104,6 +104,8 @@ None currently known +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-28-detect_port_security_violation.md b/docs/_posts/2020-10-28-detect_port_security_violation.md index 2db24011cc..b6b8fae8a8 100644 --- a/docs/_posts/2020-10-28-detect_port_security_violation.md +++ b/docs/_posts/2020-10-28-detect_port_security_violation.md @@ -103,6 +103,8 @@ This search might be prone to high false positives if you have malfunctioning de +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md index 781679351a..ca84b61019 100644 --- a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md +++ b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md @@ -89,6 +89,8 @@ This search will also report any legitimate attempts of software downloads to ne +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-10-28-detect_traffic_mirroring.md b/docs/_posts/2020-10-28-detect_traffic_mirroring.md index 1db9849eb6..ee0a057eea 100644 --- a/docs/_posts/2020-10-28-detect_traffic_mirroring.md +++ b/docs/_posts/2020-10-28-detect_traffic_mirroring.md @@ -91,6 +91,8 @@ This search will return false positives for any legitimate traffic captures by n +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-06-ryuk_test_files_detected.md b/docs/_posts/2020-11-06-ryuk_test_files_detected.md index ba81fc858e..5b0c21a34a 100644 --- a/docs/_posts/2020-11-06-ryuk_test_files_detected.md +++ b/docs/_posts/2020-11-06-ryuk_test_files_detected.md @@ -83,6 +83,8 @@ If there are files with this keywoord as file names it might trigger false possi | 70.0 | 70 | 100 | A creation of ryuk test file $file_path$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md b/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md index 76641c3c31..e2f2336e14 100644 --- a/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md +++ b/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md @@ -92,6 +92,8 @@ Administrators may attempt to change the default execution policy on a system fo | 48.0 | 60 | 80 | A registry modification in $registry_path$ with reg key $registry_key_name$ and reg value $registry_value_name$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md b/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md index 8a3f6289c7..a0eae2ff28 100644 --- a/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md +++ b/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md @@ -84,6 +84,8 @@ SAM is a critical windows service, stopping it would cause major issues on an en | 70.0 | 70 | 100 | The Windows Security Account Manager (SAM) was stopped via cli by $user$ on $dest$ by this command: $processs$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-09-common_ransomware_extensions.md b/docs/_posts/2020-11-09-common_ransomware_extensions.md index d43c67c5b2..eaf05768cd 100644 --- a/docs/_posts/2020-11-09-common_ransomware_extensions.md +++ b/docs/_posts/2020-11-09-common_ransomware_extensions.md @@ -100,6 +100,8 @@ It is possible for a legitimate file with these extensions to be created. If thi | 90.0 | 90 | 100 | A file - $file_name$ was written to disk on endpoint $dest$ by user $user$, this is indicative of a known ransomware file extension and should be reviewed immediately. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-09-common_ransomware_notes.md b/docs/_posts/2020-11-09-common_ransomware_notes.md index b24b64ffbc..3913ec95f6 100644 --- a/docs/_posts/2020-11-09-common_ransomware_notes.md +++ b/docs/_posts/2020-11-09-common_ransomware_notes.md @@ -95,6 +95,8 @@ It's possible that a legitimate file could be created with the same name use | 90.0 | 90 | 100 | A file - $file_name$ was written to disk on endpoint $dest$ by user $user$, this is indicative of a known ransomware note file and should be reviewed immediately. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-09-deleting_shadow_copies.md b/docs/_posts/2020-11-09-deleting_shadow_copies.md index ad23a6ce73..c76e1529a4 100644 --- a/docs/_posts/2020-11-09-deleting_shadow_copies.md +++ b/docs/_posts/2020-11-09-deleting_shadow_copies.md @@ -95,6 +95,8 @@ vssadmin.exe and wmic.exe are standard applications shipped with modern versions | 81.0 | 90 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to delete shadow copies. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md b/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md index aa00009ab1..632344edcb 100644 --- a/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md +++ b/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md @@ -100,6 +100,8 @@ It's possible that a widely used system, such as a kiosk, could cause a larg | 36.0 | 60 | 60 | Multiple accounts have been locked out. Review $dest$ and results related to $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md b/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md index 9932ebf456..e98e783b6b 100644 --- a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md +++ b/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md @@ -99,6 +99,8 @@ It is uncommon for normal users to execute a series of commands used for network | 32.0 | 40 | 80 | An instance of $parent_process_name$ spawning multiple $process_name$ was identified on endpoint $dest$ by user $user$ typically not a normal behavior of the process. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md index 290a04a004..09b9bf4dcc 100644 --- a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md +++ b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md @@ -86,6 +86,8 @@ There are circumstances where an application may legitimately execute and intera | 35.0 | 70 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event that warrants investigating. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-18-disabling_remote_user_account_control.md b/docs/_posts/2020-11-18-disabling_remote_user_account_control.md index ef8c5de8b7..b668f55369 100644 --- a/docs/_posts/2020-11-18-disabling_remote_user_account_control.md +++ b/docs/_posts/2020-11-18-disabling_remote_user_account_control.md @@ -91,6 +91,8 @@ This registry key may be modified via administrators to implement a change in sy | 42.0 | 70 | 60 | The Windows registry keys that control the enforcement of Windows User Account Control (UAC) were modified on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md b/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md index 5124e0ddf9..353903eebc 100644 --- a/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md +++ b/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md @@ -90,6 +90,8 @@ None identified. | 56.0 | 80 | 70 | process $process$ have double extensions in the file name is executed on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md b/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md index 7e9b0800d9..544e81dc76 100644 --- a/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md +++ b/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md @@ -91,6 +91,8 @@ None identified | 63.0 | 70 | 90 | A process $process_name$ that possible create a shim db silently in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md b/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md index 656d5a3574..c8c9643e14 100644 --- a/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md +++ b/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md @@ -96,6 +96,8 @@ It is unusual for a service to be created or modified by directly manipulating t | 45.0 | 75 | 60 | A reg.exe process $process_name$ with commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md b/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md index 4e44caf07e..520d87b135 100644 --- a/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md +++ b/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md @@ -95,6 +95,8 @@ Administrators may create jobs on systems forcing reboots to perform updates, ma | 56.0 | 70 | 80 | A schedule task process $process_name$ with force reboot commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-08-shim_database_file_creation.md b/docs/_posts/2020-12-08-shim_database_file_creation.md index 34a4be73a2..5fff61547d 100644 --- a/docs/_posts/2020-12-08-shim_database_file_creation.md +++ b/docs/_posts/2020-12-08-shim_database_file_creation.md @@ -90,6 +90,8 @@ Because legitimate shim files are created and used all the time, this event, in | 56.0 | 70 | 80 | A process that possibly write shim database in $file_path$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md b/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md index a70ffa2fbe..6e8b75dc0f 100644 --- a/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md +++ b/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md @@ -92,6 +92,8 @@ Single-letter executables are not always malicious. Investigate this activity wi | 63.0 | 70 | 90 | A suspicious process $process_name$ with single letter in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md b/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md index e290aacc01..8b8b3a208b 100644 --- a/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md +++ b/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md @@ -104,6 +104,8 @@ This detection may require tuning based on third party applications utilizing na | 49.0 | 70 | 70 | System process running from unexpected location on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-08-unusually_long_command_line.md b/docs/_posts/2020-12-08-unusually_long_command_line.md index ce3469275f..ad68228635 100644 --- a/docs/_posts/2020-12-08-unusually_long_command_line.md +++ b/docs/_posts/2020-12-08-unusually_long_command_line.md @@ -85,6 +85,8 @@ Some legitimate applications start with long command lines. | 42.0 | 70 | 60 | Unusually long command line $Processes.process_name$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md b/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md index 481762c613..ec4742bfe7 100644 --- a/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md +++ b/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md @@ -96,6 +96,8 @@ Although unlikely, administrators may use event subscriptions for legitimate pur | 30.0 | 30 | 100 | User $user$ on $host$ executed the following suspicious WMI query: $Query$. Filter: $filter$. Consumer: $Consumer$. EventCode: $EventCode$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md index 79ecf90ed5..060292b09e 100644 --- a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md +++ b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md @@ -81,6 +81,8 @@ unknown +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md index ca41bf7cfe..04bde8ed49 100644 --- a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md +++ b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md @@ -89,6 +89,8 @@ Service Accounts | 48.0 | 80 | 60 | User $user$ has delegated suspicious rights $AccessRights$ to user $dest_user$ that allow access to sensitive | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md index 8260fbfc93..62ffbded74 100644 --- a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md +++ b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md @@ -87,6 +87,8 @@ unknown +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md b/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md index 80be2b8a77..d1bf5ff0c0 100644 --- a/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md +++ b/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md @@ -87,6 +87,8 @@ The threshold for alert is above 10 attempts and this should reduce the number o | 64.0 | 80 | 80 | User $user$ has caused excessive number of authentication failures from $src_ip$ using UserAgent $UserAgent$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-16-o365_pst_export_alert.md b/docs/_posts/2020-12-16-o365_pst_export_alert.md index d271a1647c..5c3b66c80a 100644 --- a/docs/_posts/2020-12-16-o365_pst_export_alert.md +++ b/docs/_posts/2020-12-16-o365_pst_export_alert.md @@ -87,6 +87,8 @@ PST export can be done for legitimate purposes but due to the sensitive nature o | 48.0 | 80 | 60 | User $Source$ has exported a PST file from the search using this operation- $Operation$ with a severity of $Severity$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md index a00ebd9794..7de46cf473 100644 --- a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md +++ b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md @@ -91,6 +91,8 @@ unknown | 48.0 | 80 | 60 | User $user$ has configured a forwarding rule for multiple mailboxes to the same destination $ForwardingAddress$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md index 827517be27..fa5b6c1462 100644 --- a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md +++ b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md @@ -91,6 +91,8 @@ unknown | 48.0 | 80 | 60 | User $user$ configured multiple users $src_user$ with a count of $count_src_user$, a forwarding rule to same destination $ForwardingSmtpAddress$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md b/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md index 3919624069..bfb047be62 100644 --- a/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md +++ b/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md @@ -96,6 +96,8 @@ Tasks should not be manually created via CLI, this is rarely done by admins as w | 56.0 | 70 | 80 | A schedule task process $process_name$ with create or delete commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md b/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md index b63021ff09..52c6edf2ab 100644 --- a/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md +++ b/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md @@ -87,6 +87,8 @@ Administrators may modify the boot configuration. | 80.0 | 100 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting disable the ability to recover the endpoint. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-06-supernova_webshell.md b/docs/_posts/2021-01-06-supernova_webshell.md index c5ff556d0e..8878cae96c 100644 --- a/docs/_posts/2021-01-06-supernova_webshell.md +++ b/docs/_posts/2021-01-06-supernova_webshell.md @@ -79,6 +79,8 @@ There might be false positives associted with this detection since items like ar +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md b/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md index 27d3299fb8..7c363796e9 100644 --- a/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md +++ b/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md @@ -92,6 +92,8 @@ unknown | 25.0 | 50 | 50 | AWS account is potentially compromised and user $userIdentity.principalId$ is trying to compromise other accounts. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md b/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md index 6c4f44912a..b2f5010846 100644 --- a/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md +++ b/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md @@ -87,6 +87,8 @@ bucket with S3 encryption | 15.0 | 30 | 50 | User $user$ with KMS keys is performing encryption, against S3 buckets on these files $dest_file$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md b/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md index 0501524009..1e0c3ceca3 100644 --- a/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md +++ b/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md @@ -98,6 +98,8 @@ It's possible that an admin has created this ACL with all ports open for som | 48.0 | 60 | 80 | User $user_arn$ has created network ACLs with all the ports open to a specified CIDR $requestParameters.cidrBlock$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md b/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md index 90481fd30d..778517ceb6 100644 --- a/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md +++ b/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md @@ -91,6 +91,8 @@ It's possible that a user has legitimately deleted a network ACL. | 5.0 | 10 | 50 | User $user_arn$ from $src$ has sucessfully deleted network ACLs entry (eventName= $eventName$), such that the instance is accessible from anywhere | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md b/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md index daae7b88bc..6b01746d49 100644 --- a/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md +++ b/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md @@ -93,6 +93,8 @@ Although unlikely, limited instances have been identified coming from native Mic | 35.0 | 70 | 50 | Suspicious microsoft.workflow.compiler.exe process ran on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_path.md b/docs/_posts/2021-01-12-suspicious_msbuild_path.md index 5b8d0c02ef..dfaa95b20b 100644 --- a/docs/_posts/2021-01-12-suspicious_msbuild_path.md +++ b/docs/_posts/2021-01-12-suspicious_msbuild_path.md @@ -107,6 +107,8 @@ Some legitimate applications may use a moved copy of msbuild.exe, triggering a f | 49.0 | 70 | 70 | Msbuild.exe ran from an uncommon path on $dest$ execyted by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_rename.md b/docs/_posts/2021-01-12-suspicious_msbuild_rename.md index 23ea599cce..9413aedc4e 100644 --- a/docs/_posts/2021-01-12-suspicious_msbuild_rename.md +++ b/docs/_posts/2021-01-12-suspicious_msbuild_rename.md @@ -107,6 +107,8 @@ Although unlikely, some legitimate applications may use a moved copy of msbuild, | 63.0 | 70 | 90 | Suspicious renamed msbuild.exe binary ran on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md b/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md index e6c4885ebb..b4ac3fdf44 100644 --- a/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md +++ b/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md @@ -97,6 +97,8 @@ Although unlikely, some legitimate applications may exhibit this behavior, trigg | 42.0 | 70 | 60 | Suspicious msbuild.exe process executed on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-12-suspicious_mshta_child_process.md b/docs/_posts/2021-01-12-suspicious_mshta_child_process.md index 60472da69b..aec552e8c6 100644 --- a/docs/_posts/2021-01-12-suspicious_mshta_child_process.md +++ b/docs/_posts/2021-01-12-suspicious_mshta_child_process.md @@ -91,6 +91,8 @@ Although unlikely, some legitimate applications may exhibit this behavior, trigg | 40.0 | 50 | 80 | suspicious mshta child process detected on host $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md b/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md index 7d76860d9e..ca70bfc371 100644 --- a/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md +++ b/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md @@ -103,6 +103,8 @@ Some users and applications may leverage Dynamic DNS to reach out to some domain | 56.0 | 70 | 80 | A dns query $query$ from your infra connecting to suspicious domain in host $host$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md b/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md index aa40219ba0..9723b2760d 100644 --- a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md +++ b/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md @@ -100,6 +100,8 @@ These characters might be legitimately on the command-line, but it is not common | 42.0 | 70 | 60 | Powershell.exe running with potential obfuscated arguments on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md b/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md index 92bd572314..d6c26640ad 100644 --- a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md +++ b/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md @@ -98,6 +98,8 @@ Although unlikely, some legitimate applications may exhibit this behavior, trigg | 56.0 | 70 | 80 | Suspicious rundll32.exe inline HTA execution on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md b/docs/_posts/2021-01-20-suspicious_mshta_spawn.md index a68360f0a5..f85a5cae16 100644 --- a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md +++ b/docs/_posts/2021-01-20-suspicious_mshta_spawn.md @@ -97,6 +97,8 @@ Although unlikely, some legitimate applications may exhibit this behavior, trigg | 42.0 | 70 | 60 | mshta.exe spawned by wmiprvse.exe on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md b/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md index 8d9127dfaf..890889c8e9 100644 --- a/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md +++ b/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md @@ -87,6 +87,8 @@ Administrators may modify the boot configuration. | 15.0 | 30 | 50 | System backups deletion on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-25-nltest_domain_trust_discovery.md b/docs/_posts/2021-01-25-nltest_domain_trust_discovery.md index 6ab95ee750..1d78896c91 100644 --- a/docs/_posts/2021-01-25-nltest_domain_trust_discovery.md +++ b/docs/_posts/2021-01-25-nltest_domain_trust_discovery.md @@ -91,6 +91,8 @@ Administrators may use nltest for troubleshooting purposes, otherwise, rarely us | 15.0 | 30 | 50 | Domain trust discovery execution on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md b/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md index 1f070ebcec..c6f9e89788 100644 --- a/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md +++ b/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md @@ -90,6 +90,8 @@ Attacks using a Golden SAML or SAML assertion hijacks or forgeries are very diff | 64.0 | 80 | 80 | From IP address $sourceIPAddress$, user agent $userAgent$ has trigged an event $eventName$ for account ID $recipientAccountId$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md b/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md index 85af5f6d57..d1ba287ca0 100644 --- a/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md +++ b/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md @@ -89,6 +89,8 @@ Updating a SAML provider or creating a new one may not necessarily be malicious | 64.0 | 80 | 80 | User $userIdentity.principalId$ from IP address $sourceIPAddress$ has trigged an event $eventName$ to update the SAML provider to $requestParameters.sAMLProviderArn$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md b/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md index c5fd69aeed..5ec24f4b34 100644 --- a/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md +++ b/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md @@ -83,6 +83,8 @@ Unless there are specific use cases, manipulating or exporting certificates usin | 63.0 | 90 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting export a certificate. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md index f414d083c6..6200a45168 100644 --- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md +++ b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md @@ -80,6 +80,8 @@ None | 15.0 | 30 | 50 | Spike in AWS security Hub alerts with title $Title$ for EC2 instance $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md index d9c002d920..635f171522 100644 --- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md +++ b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md @@ -72,6 +72,8 @@ None +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md index 2f173a8259..4b2ec9be2f 100644 --- a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md +++ b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md @@ -92,6 +92,8 @@ The creation of a new Federation is not necessarily malicious, however this even | 18.0 | 30 | 60 | User $Actor.ID$ has created a new federation setting on $dest$ from IP Address $ActorIpAddress$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md b/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md index d21d8a1de2..aede587463 100644 --- a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md +++ b/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md @@ -89,6 +89,8 @@ Logon errors may not be malicious in nature however it may indicate attempts to | 64.0 | 80 | 80 | User $UserId$ has caused excessive number of SSO logon errors from $ActorIpAddress$ using UserAgent $UserAgent$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md index a107f285b4..5a863cdab9 100644 --- a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md +++ b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md @@ -93,6 +93,8 @@ The creation of a new Federated domain is not necessarily malicious, however the | 64.0 | 80 | 80 | User $UserId$ has added a new federated domaain $Parameters.Value$ for $OrganizationName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-26-revil_registry_entry.md b/docs/_posts/2021-01-26-revil_registry_entry.md index 91dc707482..412b745317 100644 --- a/docs/_posts/2021-01-26-revil_registry_entry.md +++ b/docs/_posts/2021-01-26-revil_registry_entry.md @@ -91,6 +91,8 @@ unknown | 60.0 | 60 | 100 | A registry entry $registry_path$ with registry value $registry_value_name$ and $registry_value_name$ related to revil ransomware in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md index 6d86259c4f..0a2527ecde 100644 --- a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md +++ b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md @@ -73,6 +73,8 @@ unknown +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md index 5456b359c8..6f479f7245 100644 --- a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md +++ b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md @@ -74,6 +74,8 @@ unknown +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md b/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md index a625b55a31..da01973045 100644 --- a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md +++ b/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md @@ -99,6 +99,8 @@ Limited false positives related to third party software registering .DLL's. | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ in an attempt to bypass detection and preventative controls was identified on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-28-ntdsutil_export_ntds.md b/docs/_posts/2021-01-28-ntdsutil_export_ntds.md index 5c9793da42..5eaf8e0f7b 100644 --- a/docs/_posts/2021-01-28-ntdsutil_export_ntds.md +++ b/docs/_posts/2021-01-28-ntdsutil_export_ntds.md @@ -95,6 +95,8 @@ Highly possible Server Administrators will troubleshoot with ntdsutil.exe, gener | 50.0 | 100 | 50 | Active Directory NTDS export on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md b/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md index 6e457f0dde..8cd015315d 100644 --- a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md +++ b/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md @@ -98,6 +98,8 @@ Limited false positives with the query restricted to specified paths. Add more w | 35.0 | 70 | 50 | Suspicious $Processes.process_path.file_path$ process potentially loading malicious code | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md index 129e3f94ec..ea4fb3c5bd 100644 --- a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md +++ b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md @@ -76,6 +76,8 @@ If sudoedit is throwing segfaults for other reasons this will pick those up too. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md index a5d64251bb..6fca2af169 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md @@ -97,6 +97,8 @@ Although unlikely, some legitimate applications may use advpack.dll or ieadvpack | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ loading advpack.dll and ieadvpack.dll by calling the LaunchINFSection function on the command line was identified on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md index 75cf61c6b1..53f3b473ed 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md @@ -97,6 +97,8 @@ Although unlikely, some legitimate applications may use setupapi triggering a fa | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ loading setupapi.dll and iesetupapi.dll by calling the LaunchINFSection function on the command line was identified on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md index 9995c74278..7de42141b4 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md @@ -97,6 +97,8 @@ Although unlikely, some legitimate applications may use syssetup.dll, triggering | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ loading syssetup.dll by calling the LaunchINFSection function on the command line was identified on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md b/docs/_posts/2021-02-04-suspicious_rundll32_startw.md index df5b7c1427..84b7edf779 100644 --- a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md +++ b/docs/_posts/2021-02-04-suspicious_rundll32_startw.md @@ -99,6 +99,8 @@ Although unlikely, some legitimate applications may use Start as a function and | 35.0 | 70 | 50 | rundll32.exe running with suspicious parameters on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md b/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md index b2f8d76426..f2238e4931 100644 --- a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md +++ b/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md @@ -97,6 +97,8 @@ This is likely to produce false positives and will require some filtering. Tune | 35.0 | 70 | 50 | $Processes.process_path.file_path$ process potentially loading malicious code | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md b/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md index 281d4edb0f..109b8fc446 100644 --- a/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md +++ b/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md @@ -96,6 +96,8 @@ Although unlikely, some legitimate applications (ex. web browsers) may spawn a c | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ spawning a child process, typically not normal behavior. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md b/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md index a202ae9c5e..cfdc8e0ab1 100644 --- a/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md +++ b/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md @@ -92,6 +92,8 @@ Although unlikely, limited instances of regasm.exe or regsvcs.exe may cause a fa | 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ spawning a child process, typically not normal behavior for $parent_process_name$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md b/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md index 3fca77c1f7..6b3995b061 100644 --- a/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md +++ b/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md @@ -93,6 +93,8 @@ Although unlikely, limited instances of regasm.exe or regsvcs.exe may cause a fa | 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ typically not normal for this process. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md b/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md index 9311d225c8..d221b02118 100644 --- a/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md +++ b/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md @@ -92,6 +92,8 @@ Although unlikely, limited instances of regasm.exe with a network connection may | 80.0 | 80 | 100 | An instance of $process_name$ contacting a remote destination was identified on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md b/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md index e554c387a6..57f94297ac 100644 --- a/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md +++ b/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md @@ -91,6 +91,8 @@ Although unlikely, limited instances of regsvcs.exe may cause a false positive. | 80.0 | 80 | 100 | An instance of $process_name$ contacting a remote destination was identified on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md b/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md index 6d9c365300..da31deb082 100644 --- a/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md +++ b/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md @@ -98,6 +98,8 @@ While this search has no known false positives, it is possible that an AWS admin | 49.0 | 70 | 70 | User $user$ created a policy version that allows them to access any resource in their account | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md b/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md index 0c447dcf0b..686b3f5207 100644 --- a/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md +++ b/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md @@ -90,6 +90,8 @@ The idea of using named pipes with Cobalt Strike is to blend in. Therefore, some | 72.0 | 80 | 90 | An instance of $process_name$ was identified on endpoint $Computer$ by user $user$ accessing known suspicious named pipes related to Cobalt Strike. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md index e27ff20cfd..050828d0cf 100644 --- a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md +++ b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md @@ -85,6 +85,8 @@ Unknown. Filter as needed. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md index 66c80f2b20..fce8fd9384 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md @@ -97,6 +97,8 @@ Some legitimate applications may use PlistBuddy to create or modify property lis +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md index fd5c3c0389..889c287c58 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md @@ -85,6 +85,8 @@ Some legitimate applications may use PlistBuddy to create or modify property lis +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md index 4202b50957..2df145bac5 100644 --- a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md +++ b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md @@ -84,6 +84,8 @@ Unknown. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-01-any_powershell_downloadfile.md b/docs/_posts/2021-03-01-any_powershell_downloadfile.md index 80d4b932d4..945783002e 100644 --- a/docs/_posts/2021-03-01-any_powershell_downloadfile.md +++ b/docs/_posts/2021-03-01-any_powershell_downloadfile.md @@ -100,6 +100,8 @@ False positives may be present and filtering will need to occur by parent proces | 56.0 | 80 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadFile within PowerShell. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-03-01-any_powershell_downloadstring.md b/docs/_posts/2021-03-01-any_powershell_downloadstring.md index 39e95861b2..5f1068053b 100644 --- a/docs/_posts/2021-03-01-any_powershell_downloadstring.md +++ b/docs/_posts/2021-03-01-any_powershell_downloadstring.md @@ -99,6 +99,8 @@ False positives may be present and filtering will need to occur by parent proces | 56.0 | 80 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadString within PowerShell. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-01-fodhelper_uac_bypass.md b/docs/_posts/2021-03-01-fodhelper_uac_bypass.md index 83ea873a58..912861ba77 100644 --- a/docs/_posts/2021-03-01-fodhelper_uac_bypass.md +++ b/docs/_posts/2021-03-01-fodhelper_uac_bypass.md @@ -105,6 +105,8 @@ Limited to no false positives are expected. | 81.0 | 90 | 90 | Suspcious registy keys added by process fodhelper.exe (process_id- $process_id), with a parent_process of $parent_process_name$ that has been executed on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md b/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md index 609e91a902..d0c3276678 100644 --- a/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md +++ b/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md @@ -94,6 +94,8 @@ Limited to no known false positives. | 63.0 | 70 | 90 | A process $process_name$ with wake on LAN commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md b/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md index b6eb609c7b..925d2ccbaf 100644 --- a/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md +++ b/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md @@ -100,6 +100,8 @@ Limited false positives may be present. Filter as needed by parent process or co | 35.0 | 70 | 50 | Suspicious scheduled task registered on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md b/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md index 68580045bf..434f012346 100644 --- a/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md +++ b/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md @@ -95,6 +95,8 @@ While this search has no known false positives, it is possible that an AWS admin | 30.0 | 50 | 60 | From IP address $sourceIPAddress$, user agent $userAgent$ has trigged an event $eventName$ for updating the the default policy version | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md b/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md index 8ced3b6b48..a48b3a267c 100644 --- a/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md +++ b/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md @@ -89,6 +89,8 @@ Unknown. Tune out child processes as needed to limit volume of false positives. | 56.0 | 70 | 80 | Possible CVE-2021-26857 exploitation on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-03-02-windows_disableantispyware_registry.md b/docs/_posts/2021-03-02-windows_disableantispyware_registry.md index 478fc1bb35..1c031c56dc 100644 --- a/docs/_posts/2021-03-02-windows_disableantispyware_registry.md +++ b/docs/_posts/2021-03-02-windows_disableantispyware_registry.md @@ -91,6 +91,8 @@ It is unusual to turn this feature off a Windows system since it is a default se | 24.0 | 30 | 80 | Windows DisableAntiSpyware registry key set to 'disabled' on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md b/docs/_posts/2021-03-03-nishang_powershelltcponeline.md index 3839c46625..1bebbdd826 100644 --- a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md +++ b/docs/_posts/2021-03-03-nishang_powershelltcponeline.md @@ -97,6 +97,8 @@ Limited false positives may be present. Filter as needed based on initial analys | 42.0 | 70 | 60 | Possible Nishang Invoke-PowerShellTCPOneLine behavior on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-03-w3wp_spawning_shell.md b/docs/_posts/2021-03-03-w3wp_spawning_shell.md index 45e83e2b38..e32c4a77f3 100644 --- a/docs/_posts/2021-03-03-w3wp_spawning_shell.md +++ b/docs/_posts/2021-03-03-w3wp_spawning_shell.md @@ -102,6 +102,8 @@ Baseline your environment before production. It is possible build systems using | 56.0 | 70 | 80 | Possible Web Shell execution on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md b/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md index 79ee7a96a0..d307de8981 100644 --- a/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md +++ b/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md @@ -90,6 +90,8 @@ unknown | 81.0 | 90 | 90 | A high frequency file creation of $file_name$ in different file path in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-12-resize_shadowstorage_volume.md b/docs/_posts/2021-03-12-resize_shadowstorage_volume.md index 9abbb94fb4..e415efba99 100644 --- a/docs/_posts/2021-03-12-resize_shadowstorage_volume.md +++ b/docs/_posts/2021-03-12-resize_shadowstorage_volume.md @@ -87,6 +87,8 @@ network admin can resize the shadowstorage for valid purposes. | 72.0 | 80 | 90 | A process $parent_process_name$ attempt to resize shadow copy with commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-16-high_file_deletion_frequency.md b/docs/_posts/2021-03-16-high_file_deletion_frequency.md index b1ba84e878..55f63f1698 100644 --- a/docs/_posts/2021-03-16-high_file_deletion_frequency.md +++ b/docs/_posts/2021-03-16-high_file_deletion_frequency.md @@ -88,6 +88,8 @@ user may delete bunch of pictures or files in a folder. | 72.0 | 90 | 80 | High frequency file deletion activity detected on host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-16-high_process_termination_frequency.md b/docs/_posts/2021-03-16-high_process_termination_frequency.md index 1dfa1d3685..dd0e389b58 100644 --- a/docs/_posts/2021-03-16-high_process_termination_frequency.md +++ b/docs/_posts/2021-03-16-high_process_termination_frequency.md @@ -86,6 +86,8 @@ admin or user tool that can terminate multiple process. | 72.0 | 90 | 80 | High frequency process termination (more than 15 processes within 3s) detected on host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-17-clop_common_exec_parameter.md b/docs/_posts/2021-03-17-clop_common_exec_parameter.md index 9ff0e39833..8ffcc0ab77 100644 --- a/docs/_posts/2021-03-17-clop_common_exec_parameter.md +++ b/docs/_posts/2021-03-17-clop_common_exec_parameter.md @@ -92,6 +92,8 @@ Operators can execute third party tools using these parameters. | 100.0 | 100 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting using arguments to execute its main code or feature of its code related to Clop ransomware. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md b/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md index 3187904952..1663c0ce0f 100644 --- a/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md +++ b/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md @@ -87,6 +87,8 @@ unknown | 100.0 | 100 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ executing known Clop Ransomware service names. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md b/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md index 4746685d8c..bd124a4d8e 100644 --- a/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md +++ b/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md @@ -93,6 +93,8 @@ unknown | 60.0 | 60 | 100 | A process $Image$ tries to delete its process path in commandline $cmdline$ as part of defense evasion in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md b/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md index be06dcb77a..156161fa1b 100644 --- a/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md +++ b/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md @@ -94,6 +94,8 @@ Limited false positives in most environments, however tune as needed based on pa | 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download a file. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md b/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md index 3bba649773..fb296b4edf 100644 --- a/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md +++ b/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md @@ -94,6 +94,8 @@ Limited false positives in most environments, however tune as needed based on pa | 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download a file. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-23-certutil_with_decode_argument.md b/docs/_posts/2021-03-23-certutil_with_decode_argument.md index 1683a7cd83..2c9fe448d5 100644 --- a/docs/_posts/2021-03-23-certutil_with_decode_argument.md +++ b/docs/_posts/2021-03-23-certutil_with_decode_argument.md @@ -93,6 +93,8 @@ Typically seen used to `encode` files, but it is possible to see legitimate use | 40.0 | 50 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to decode a file. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-29-powershell_start-bitstransfer.md b/docs/_posts/2021-03-29-powershell_start-bitstransfer.md index 0fbed53d8f..074ac10e61 100644 --- a/docs/_posts/2021-03-29-powershell_start-bitstransfer.md +++ b/docs/_posts/2021-03-29-powershell_start-bitstransfer.md @@ -94,6 +94,8 @@ Limited false positives. It is possible administrators will utilize Start-BitsTr | 56.0 | 70 | 80 | A suspicious process $process_name$ with commandline $process$ that are related to bittransfer functionality in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md b/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md index 5dd055e378..0a87046c68 100644 --- a/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md +++ b/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md @@ -92,6 +92,8 @@ This detection will require tuning to provide high fidelity detection capabiltie | 5.0 | 10 | 50 | User $user_arn$ has sucessfully deleted mulitple groups $group_deleted$ from $src$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md b/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md index 638189f50e..63aee91568 100644 --- a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md +++ b/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md @@ -97,6 +97,8 @@ admin may disable firewall during testing or fixing network problem. | 25.0 | 50 | 50 | The Windows Firewall was disabled on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-03-31-dsquery_domain_discovery.md b/docs/_posts/2021-03-31-dsquery_domain_discovery.md index b8bcb7c42f..0a07116959 100644 --- a/docs/_posts/2021-03-31-dsquery_domain_discovery.md +++ b/docs/_posts/2021-03-31-dsquery_domain_discovery.md @@ -94,6 +94,8 @@ Limited false positives. If there is a true false positive, filter based on comm | 72.0 | 80 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified performing domain discovery on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md b/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md index c863e6d360..94e244fc3b 100644 --- a/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md +++ b/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md @@ -89,6 +89,8 @@ This detection will require tuning to provide high fidelity detection capabiltie | 28.0 | 40 | 70 | User $user_arn$ has caused multiple failures with errorCode $errorCode$, which potentially means adversary is attempting to identify a role name. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-01-aws_iam_delete_policy.md b/docs/_posts/2021-04-01-aws_iam_delete_policy.md index 7918c72dc9..86ff2df95a 100644 --- a/docs/_posts/2021-04-01-aws_iam_delete_policy.md +++ b/docs/_posts/2021-04-01-aws_iam_delete_policy.md @@ -84,6 +84,8 @@ This detection will require tuning to provide high fidelity detection capabiltie | 10.0 | 20 | 50 | User $user_arn$ has deleted AWS Policies from IP address $src$ by executing the following command $eventName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md b/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md index 38bc84981c..e6353a741a 100644 --- a/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md +++ b/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md @@ -84,6 +84,8 @@ This detection will require tuning to provide high fidelity detection capabiltie | 5.0 | 10 | 50 | User $user_arn$ has had mulitple failures while attempting to delete groups from $src$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md b/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md index 9ed093a7e9..d0fbf67a01 100644 --- a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md +++ b/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md @@ -100,6 +100,8 @@ Creating a hidden powershell service is rare and could key off of those instance | 72.0 | 90 | 80 | Identifies the abuse the Windows SC.exe to execute malicious powerShell as a service $Service_File_Name$ by $user$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md index 1f711a83ac..c7c5802ed9 100644 --- a/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md +++ b/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md @@ -92,6 +92,8 @@ A host failing to authenticate with multiple valid domain users is not a common | 49.0 | 70 | 70 | Potential Kerberos based password spraying attack from $Client_Address$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md index 207014cc67..aa21571d8a 100644 --- a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md +++ b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md @@ -101,6 +101,8 @@ False positives are possible if legitimate applications are allowed to register | 70.0 | 70 | 100 | A windows scheduled task was created (task name=$Task_Name$) on $dest$ by the following command: $Command$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-12-excel_spawning_powershell.md b/docs/_posts/2021-04-12-excel_spawning_powershell.md index 0e775ad60c..0f6a43a4e0 100644 --- a/docs/_posts/2021-04-12-excel_spawning_powershell.md +++ b/docs/_posts/2021-04-12-excel_spawning_powershell.md @@ -96,6 +96,8 @@ False positives should be limited, but if any are present, filter as needed. | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$, indicating potential suspicious macro execution. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md b/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md index 5159b09a09..46f2cd1029 100644 --- a/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md +++ b/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md @@ -91,6 +91,8 @@ False positives should be limited, but if any are present, filter as needed. In | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$, indicating potential suspicious macro execution. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md b/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md index 589fd0ecd7..269dec3e49 100644 --- a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md +++ b/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md @@ -99,6 +99,8 @@ False positives are possible if legitimate applications are allowed to register | 70.0 | 70 | 100 | A windows scheduled task was created (task name=$Task_Name$) on $dest$ by the following command: $Command$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-12-winword_spawning_powershell.md b/docs/_posts/2021-04-12-winword_spawning_powershell.md index cff7381200..c65d1d32a2 100644 --- a/docs/_posts/2021-04-12-winword_spawning_powershell.md +++ b/docs/_posts/2021-04-12-winword_spawning_powershell.md @@ -97,6 +97,8 @@ False positives should be limited, but if any are present, filter as needed. | 70.0 | 70 | 100 | $parent_process_name$ on $dest$ by $user$ launched the following powershell process: $process_name$ which is very common in spearphishing attacks | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md b/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md index 1329d297e5..b526cd1f1e 100644 --- a/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md +++ b/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md @@ -91,6 +91,8 @@ There will be limited false positives and it will be different for every environ | 70.0 | 70 | 100 | User $user$ on $dest$ spawned Windows Script Host from Winword.exe | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-13-aws_excessive_security_scanning.md b/docs/_posts/2021-04-13-aws_excessive_security_scanning.md index 7c16d020c3..e98981b401 100644 --- a/docs/_posts/2021-04-13-aws_excessive_security_scanning.md +++ b/docs/_posts/2021-04-13-aws_excessive_security_scanning.md @@ -86,6 +86,8 @@ While this search has no known false positives. | 18.0 | 30 | 60 | user $user$ has excessive number of api calls $dc_events$ from these IP addresses $src$, violating the threshold of 50, using the following commands $command$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md b/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md index bb808deb34..a10acfa092 100644 --- a/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md +++ b/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md @@ -95,6 +95,8 @@ A source user failing attempting to authenticate multiple users on a host is not | 49.0 | 70 | 70 | Potential password spraying attack from $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md index cc15e9b7f4..3606f1b8de 100644 --- a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md +++ b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md @@ -92,6 +92,8 @@ A host failing to authenticate with multiple valid domain users is not a common | 49.0 | 70 | 70 | Potential NTLM based password spraying attack from $Source_Workstation$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md index 17e38976e8..cc1f8cd7fa 100644 --- a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md +++ b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md @@ -96,6 +96,8 @@ A process failing to authenticate with multiple users is not a common behavior f | 49.0 | 70 | 70 | Potential password spraying attack from $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md b/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md index 530308b663..ca81a6baee 100644 --- a/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md +++ b/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md @@ -95,6 +95,8 @@ A host failing to authenticate with multiple valid users against a remote host i | 49.0 | 70 | 70 | Potential password spraying attack on $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md b/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md index be11100b30..03cc231ecf 100644 --- a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md +++ b/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md @@ -98,6 +98,8 @@ unknown | 63.0 | 70 | 90 | Office application spawning rundll32.exe on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md index 05ffe64130..16ed3b7b2d 100644 --- a/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md +++ b/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md @@ -92,6 +92,8 @@ A host failing to authenticate with multiple disabled domain users is not a comm | 49.0 | 70 | 70 | Potential Kerberos based password spraying attack from $Client_Address$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md index eefe7e5904..ce78cbe812 100644 --- a/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md +++ b/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md @@ -92,6 +92,8 @@ A host failing to authenticate with multiple invalid domain users is not a commo | 49.0 | 70 | 70 | Potential Kerberos based password spraying attack from $Client_Address$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md b/docs/_posts/2021-04-14-office_document_creating_schedule_task.md index 40a98dea08..d13530444c 100644 --- a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md +++ b/docs/_posts/2021-04-14-office_document_creating_schedule_task.md @@ -92,6 +92,8 @@ unknown | 49.0 | 70 | 70 | Office document creating a schedule task on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-14-office_document_executing_macro_code.md b/docs/_posts/2021-04-14-office_document_executing_macro_code.md index b81a360f72..1e321bbc7f 100644 --- a/docs/_posts/2021-04-14-office_document_executing_macro_code.md +++ b/docs/_posts/2021-04-14-office_document_executing_macro_code.md @@ -94,6 +94,8 @@ Normal Office Document macro use for automation | 35.0 | 70 | 50 | Office document executing a macro on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md b/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md index de950203dc..f945f2015f 100644 --- a/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md +++ b/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md @@ -95,6 +95,8 @@ admin nslookup usage | 72.0 | 90 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ performing activity related to DNS exfiltration. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md b/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md index 52737fa38b..4a964a2089 100644 --- a/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md +++ b/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md @@ -92,6 +92,8 @@ A host failing to authenticate with multiple invalid domain users is not a commo | 49.0 | 70 | 70 | Potential NTLM based password spraying attack from $Source_Workstation$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md index a111143787..81a406d4af 100644 --- a/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md +++ b/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md @@ -94,6 +94,8 @@ Limited false positives may be present in small environments. Tuning may be requ | 81.0 | 90 | 90 | Process gpupdate.exe with parent_process $parent_process_name$ is executed on $dest$ by user $user$, followed by an outbound network connection to $connection_to_CNC$ on port $dest_port$. This behaviour is seen with cobaltstrike. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md b/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md index 25a33b6e2e..4db68846fe 100644 --- a/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md +++ b/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md @@ -91,6 +91,8 @@ unknown | 63.0 | 70 | 90 | A suspicious powershell process $process_name$ that tries to create a remote thread on target process $TargetImage$ with eventcode $EventCode$ in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md b/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md index 35beaa31ba..ffa2466e24 100644 --- a/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md +++ b/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md @@ -91,6 +91,8 @@ unknown | 63.0 | 70 | 90 | A schedule task process commandline arguments $Arguments$ with http string on it in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md b/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md index 43f8ba7e70..71eb8d206a 100644 --- a/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md +++ b/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md @@ -93,6 +93,8 @@ unknown | 70.0 | 70 | 100 | A schedule task process commandline rundll32 arguments $Arguments$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md b/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md index 4353e4b153..cc86935ad6 100644 --- a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md +++ b/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md @@ -92,6 +92,8 @@ unknown | 56.0 | 70 | 80 | Wermgr.exe process connecting IP location web services on $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md b/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md index 5c49ee8e5a..e3d3c14052 100644 --- a/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md +++ b/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md @@ -86,6 +86,8 @@ unknown | 56.0 | 70 | 80 | Wermgr.exe writing executable files on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md b/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md index a669df4f04..e15ff1883b 100644 --- a/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md +++ b/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md @@ -94,6 +94,8 @@ unknown | 56.0 | 70 | 80 | Wermgr.exe spawning suspicious processes on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md b/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md index fa5d8c389a..39d91a7e1a 100644 --- a/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md +++ b/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md @@ -91,6 +91,8 @@ unknown | 28.0 | 40 | 70 | Excessive usage of nslookup.exe has been detected on $Computer$. This detection is triggered as as it violates the dynamic threshold | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md index df21da7db7..8b103739e9 100644 --- a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md +++ b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md @@ -97,6 +97,8 @@ Normal archive transfer via HTTP protocol may trip this detection. | 25.0 | 50 | 50 | A http post $http_method$ sending packet with possible archive bytes header 4form_data$ in uri path $uri_path$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md b/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md index 08ee666da8..f0dee5531a 100644 --- a/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md +++ b/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md @@ -95,6 +95,8 @@ False positives should be limited as this behavior is not normal for `rundll32.e | 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading of 7zip. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md b/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md index 004a7c1a84..5b2f4e0742 100644 --- a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md +++ b/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md @@ -97,6 +97,8 @@ False positives should be limited, but if any are present, filter as needed. | 63.0 | 70 | 90 | office parent process $parent_process_name$ will execute a suspicious child process $process_name$ with process id $process_id$ and no dll commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md index d37165e880..ab515ef8ad 100644 --- a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md +++ b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md @@ -91,6 +91,8 @@ unknown | 63.0 | 70 | 90 | A http post $http_method$ sending packet with plain text of information $form_data$ in uri path $uri_path$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-22-winword_spawning_cmd.md b/docs/_posts/2021-04-22-winword_spawning_cmd.md index 46ae09a583..8d92460f97 100644 --- a/docs/_posts/2021-04-22-winword_spawning_cmd.md +++ b/docs/_posts/2021-04-22-winword_spawning_cmd.md @@ -97,6 +97,8 @@ False positives should be limited, but if any are present, filter as needed. | 70.0 | 70 | 100 | $parent_process_name$ on $dest$ by $user$ launched command: $process_name$ which is very common in spearphishing attacks. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md index c4d8b8ac61..b31d96d2ec 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md +++ b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md @@ -97,6 +97,8 @@ No false positives known. Filter as needed. | 63.0 | 70 | 90 | office parent process $parent_process_name$ will execute a suspicious child process $process_name$ with process id $process_id$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-26-office_product_spawning_certutil.md b/docs/_posts/2021-04-26-office_product_spawning_certutil.md index 3f73b7a5ec..6cfc38751a 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_certutil.md +++ b/docs/_posts/2021-04-26-office_product_spawning_certutil.md @@ -97,6 +97,8 @@ No false positives known. Filter as needed. | 63.0 | 70 | 90 | office parent process $parent_process_name$ will execute a suspicious child process $process_name$ with process id $process_id$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-26-office_product_spawning_mshta.md b/docs/_posts/2021-04-26-office_product_spawning_mshta.md index 846a587b19..924affc261 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_mshta.md +++ b/docs/_posts/2021-04-26-office_product_spawning_mshta.md @@ -98,6 +98,8 @@ No false positives known. Filter as needed. | 63.0 | 70 | 90 | office parent process $parent_process_name$ will execute a suspicious child process $process_name$ with process id $process_id$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-26-trickbot_named_pipe.md b/docs/_posts/2021-04-26-trickbot_named_pipe.md index 5cc73b7267..3141c7a4bb 100644 --- a/docs/_posts/2021-04-26-trickbot_named_pipe.md +++ b/docs/_posts/2021-04-26-trickbot_named_pipe.md @@ -88,6 +88,8 @@ unknown | 42.0 | 70 | 60 | Possible Trickbot namedpipe created on $Computer$ by $Image$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-29-icacls_deny_command.md b/docs/_posts/2021-04-29-icacls_deny_command.md index 1121bb17b2..134253e594 100644 --- a/docs/_posts/2021-04-29-icacls_deny_command.md +++ b/docs/_posts/2021-04-29-icacls_deny_command.md @@ -87,6 +87,8 @@ Unknown. It is possible some administrative scripts use ICacls. Filter as needed | 72.0 | 90 | 80 | Process name $process_name$ with deny argument executed by $user$ to change security permission of a specific file or directory on host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md b/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md index e337b3ed4d..fc3daf6186 100644 --- a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md +++ b/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md @@ -92,6 +92,8 @@ Limited false positives will be present. Some applications do load drivers | 63.0 | 70 | 90 | Suspicious driver $ImageLoaded$ on $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-04-29-xmrig_driver_loaded.md b/docs/_posts/2021-04-29-xmrig_driver_loaded.md index 4257b5fd09..b0c6e51b57 100644 --- a/docs/_posts/2021-04-29-xmrig_driver_loaded.md +++ b/docs/_posts/2021-04-29-xmrig_driver_loaded.md @@ -92,6 +92,8 @@ False positives should be limited. | 80.0 | 80 | 100 | A driver $ImageLoaded$ related to xmrig crytominer loaded in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-04-deleting_of_net_users.md b/docs/_posts/2021-05-04-deleting_of_net_users.md index 8b92872002..f297fee0fe 100644 --- a/docs/_posts/2021-05-04-deleting_of_net_users.md +++ b/docs/_posts/2021-05-04-deleting_of_net_users.md @@ -93,6 +93,8 @@ System administrators or scripts may delete user accounts via this technique. Fi | 25.0 | 50 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to delete accounts. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-04-disabling_net_user_account.md b/docs/_posts/2021-05-04-disabling_net_user_account.md index 3e3d4f37f9..cfccd28f1a 100644 --- a/docs/_posts/2021-05-04-disabling_net_user_account.md +++ b/docs/_posts/2021-05-04-disabling_net_user_account.md @@ -93,6 +93,8 @@ unknown | 42.0 | 70 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified disabling a user account on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md b/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md index cdcb82b674..8a10b3294e 100644 --- a/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md +++ b/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md @@ -88,6 +88,8 @@ unknown | 80.0 | 80 | 100 | An excessive amount of $process_name$ was executed on $dest$ attempting to disable services. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-04-excessive_service_stop_attempt.md b/docs/_posts/2021-05-04-excessive_service_stop_attempt.md index 4def015984..e7d34373ff 100644 --- a/docs/_posts/2021-05-04-excessive_service_stop_attempt.md +++ b/docs/_posts/2021-05-04-excessive_service_stop_attempt.md @@ -95,6 +95,8 @@ unknown | 80.0 | 80 | 100 | An excessive amount of $process_name$ was executed on $dest$ attempting to disable services. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md b/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md index 9240227142..e2828848da 100644 --- a/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md +++ b/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md @@ -92,6 +92,8 @@ Unknown. Filter as needed. | 28.0 | 40 | 70 | Excessive usage of taskkill.exe with process id $process_id$ (more than 10 within 1m) has been detected on $dest$ with a parent process of $parent_process_name$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-04-icacls_grant_command.md b/docs/_posts/2021-05-04-icacls_grant_command.md index 62c96cb39f..bf9491acc9 100644 --- a/docs/_posts/2021-05-04-icacls_grant_command.md +++ b/docs/_posts/2021-05-04-icacls_grant_command.md @@ -88,6 +88,8 @@ Unknown. Filter as needed. | 49.0 | 70 | 70 | Process name $process_name$ with grant argument executed by $user$ to change security permission of a specific file or directory on host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md b/docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md index 08485be8ce..de7f112f59 100644 --- a/docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md +++ b/docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md @@ -87,6 +87,8 @@ administrators may use this command. Filter as needed. | 32.0 | 40 | 80 | Suspicious ACL permission modification on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md b/docs/_posts/2021-05-04-process_kill_base_on_file_path.md index 211503eced..09c1fb0bc7 100644 --- a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md +++ b/docs/_posts/2021-05-04-process_kill_base_on_file_path.md @@ -97,6 +97,8 @@ Unknown. | 56.0 | 70 | 80 | A process $process_name$ attempt to kill process by its file path using commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-05-suspicious_process_file_path.md b/docs/_posts/2021-05-05-suspicious_process_file_path.md index 8691db51ea..00920c2384 100644 --- a/docs/_posts/2021-05-05-suspicious_process_file_path.md +++ b/docs/_posts/2021-05-05-suspicious_process_file_path.md @@ -91,6 +91,8 @@ Administrators may allow execution of specific binaries in non-standard paths. F | 35.0 | 70 | 50 | Suspicioues process $Processes.process_path.file_path$ running from suspicious location | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-06-download_files_using_telegram.md b/docs/_posts/2021-05-06-download_files_using_telegram.md index 3f62040f18..9e9cc3d5d9 100644 --- a/docs/_posts/2021-05-06-download_files_using_telegram.md +++ b/docs/_posts/2021-05-06-download_files_using_telegram.md @@ -86,6 +86,8 @@ normal download of file in telegram app. (if it was a common app in network) | 49.0 | 70 | 70 | Suspicious files were downloaded with the Telegram application on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md b/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md index 3fe5bf838f..18250b4522 100644 --- a/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md +++ b/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md @@ -89,6 +89,8 @@ unknown | 80.0 | 80 | 100 | The Telegram application has been identified enumerating local groups on $ComputerName$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-06-excessive_usage_of_net_app.md b/docs/_posts/2021-05-06-excessive_usage_of_net_app.md index 9752b206bd..229ba6c348 100644 --- a/docs/_posts/2021-05-06-excessive_usage_of_net_app.md +++ b/docs/_posts/2021-05-06-excessive_usage_of_net_app.md @@ -95,6 +95,8 @@ unknown. Filter as needed. Modify the time span as needed. | 28.0 | 40 | 70 | Excessive usage of net1.exe or net.exe within 1m, with command line $process$ has been detected on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md b/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md index 2f7fd8871b..7a7af1f0e8 100644 --- a/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md +++ b/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md @@ -88,6 +88,8 @@ Administrators may allow creation of script or exe in the paths specified. Filte | 56.0 | 80 | 70 | Suspicious executable or scripts with file name $file_name$, $file_path$ and process_id $process_id$ executed in suspicious file path in Windows by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md b/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md index 01452a6d28..054c65a0ee 100644 --- a/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md +++ b/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md @@ -88,6 +88,8 @@ Administrators or administrative scripts may use this application. Filter as nee | 80.0 | 80 | 100 | An excessive amount of $process_name$ was executed on $dest$ attempting to modify permissions. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md b/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md index eaa197c8da..1ec915bc52 100644 --- a/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md +++ b/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md @@ -89,6 +89,8 @@ Administrators may use to debug Schedule Task entries. Filter as needed. | 48.0 | 60 | 80 | A "on demand" execution of schedule task process $process_name$ using commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md b/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md index 39ab169950..158a6dec91 100644 --- a/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md +++ b/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md @@ -86,6 +86,8 @@ unknown | 81.0 | 90 | 90 | An attempt to delete ShadowCopy was performed using PowerShell on $ComputerName$ by $User$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md b/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md index 1509e1564e..c91234d397 100644 --- a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md +++ b/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md @@ -92,6 +92,8 @@ Legitimate windows application that are not on the list loading this dll. Filter | 80.0 | 80 | 100 | The following module $ImageLoaded$ was loaded by a non-standard application on endpoint $Computer$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-13-slui_runas_elevated.md b/docs/_posts/2021-05-13-slui_runas_elevated.md index 01c0553f43..09404d7ea2 100644 --- a/docs/_posts/2021-05-13-slui_runas_elevated.md +++ b/docs/_posts/2021-05-13-slui_runas_elevated.md @@ -95,6 +95,8 @@ Limited false positives should be present as this is not commonly used by legiti | 63.0 | 70 | 90 | A slui process $process_name$ with elevated commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-13-slui_spawning_a_process.md b/docs/_posts/2021-05-13-slui_spawning_a_process.md index 8dfa9f720a..e5fd436a04 100644 --- a/docs/_posts/2021-05-13-slui_spawning_a_process.md +++ b/docs/_posts/2021-05-13-slui_spawning_a_process.md @@ -95,6 +95,8 @@ Certain applications may spawn from `slui.exe` that are legitimate. Filtering wi | 63.0 | 70 | 90 | A slui process $parent_process_name$ spawning child process $process_name$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-18-services_escalate_exe.md b/docs/_posts/2021-05-18-services_escalate_exe.md index 2aa133a5e1..34e3a3d9d2 100644 --- a/docs/_posts/2021-05-18-services_escalate_exe.md +++ b/docs/_posts/2021-05-18-services_escalate_exe.md @@ -90,6 +90,8 @@ False positives should be limited as `services.exe` should never spawn a process | 76.0 | 80 | 95 | A service process $parent_process_name$ with process path $process_path$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md b/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md index f0688b1330..04491499df 100644 --- a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md +++ b/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md @@ -88,6 +88,8 @@ administrator may allow inbound traffic in certain network or machine. | 3.0 | 10 | 30 | Suspicious firewall modification detected on endpoint $ComputerName$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-19-mailsniper_invoke_functions.md b/docs/_posts/2021-05-19-mailsniper_invoke_functions.md index 3543f22567..5f103be115 100644 --- a/docs/_posts/2021-05-19-mailsniper_invoke_functions.md +++ b/docs/_posts/2021-05-19-mailsniper_invoke_functions.md @@ -88,6 +88,8 @@ unknown | 72.0 | 90 | 80 | mailsniper.ps1 functions $Message$ executed on a $ComputerName$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md b/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md index 0f63afb952..b677ad5ad5 100644 --- a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md +++ b/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md @@ -108,6 +108,8 @@ Unknown. It is possible filtering may be required to ensure fidelity. | 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ potentially performing privilege escalation using named pipes related to Cobalt Strike and other frameworks. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-21-winrm_spawning_a_process.md b/docs/_posts/2021-05-21-winrm_spawning_a_process.md index 657ffff747..363830d202 100644 --- a/docs/_posts/2021-05-21-winrm_spawning_a_process.md +++ b/docs/_posts/2021-05-21-winrm_spawning_a_process.md @@ -87,6 +87,8 @@ Unknown. Add new processes or filter as needed. It is possible system management +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md b/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md index db302febaa..6b1cc44564 100644 --- a/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md +++ b/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md @@ -93,6 +93,8 @@ unknown | 80.0 | 80 | 100 | A secretdump process $process_name$ with secretdump commandline $process$ to dump credentials in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md b/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md index e3520f70ac..f534f940a2 100644 --- a/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md +++ b/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md @@ -111,6 +111,8 @@ False positives should be limited as the analytic is specific to a filename with | 24.0 | 30 | 80 | Potential SharpHound file modifications identified on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-05-27-detect_sharphound_usage.md b/docs/_posts/2021-05-27-detect_sharphound_usage.md index 9d5babeb3a..18cca8829c 100644 --- a/docs/_posts/2021-05-27-detect_sharphound_usage.md +++ b/docs/_posts/2021-05-27-detect_sharphound_usage.md @@ -117,6 +117,8 @@ False positives should be limited as this is specific to a file attribute not us | 24.0 | 30 | 80 | Potential SharpHound binary identified on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md b/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md index f8a9e9d194..1260b73b4a 100644 --- a/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md +++ b/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md @@ -116,6 +116,8 @@ Unknown. | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ using AzureHound to enumerate AzureAD. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md b/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md index f416331e92..f10997fc7d 100644 --- a/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md +++ b/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md @@ -110,6 +110,8 @@ False positives should be limited as the analytic is specific to a filename with | 63.0 | 70 | 90 | A file - $file_name$ was written to disk that is related to AzureHound, a AzureAD enumeration utility, has occurred on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md b/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md index 87b295e673..6bd725e733 100644 --- a/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md +++ b/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md @@ -113,6 +113,8 @@ False positives should be limited as the arguments used are specific to SharpHou | 24.0 | 30 | 80 | Possible SharpHound command-Line arguments identified on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-02-conti_common_exec_parameter.md b/docs/_posts/2021-06-02-conti_common_exec_parameter.md index 50acc69bf8..0b361de6c5 100644 --- a/docs/_posts/2021-06-02-conti_common_exec_parameter.md +++ b/docs/_posts/2021-06-02-conti_common_exec_parameter.md @@ -92,6 +92,8 @@ To successfully implement this search, you need to be ingesting logs with the pr | 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ executing specific Conti Ransomware related parameters. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-02-modification_of_wallpaper.md b/docs/_posts/2021-06-02-modification_of_wallpaper.md index b02c194e8a..40d1dac917 100644 --- a/docs/_posts/2021-06-02-modification_of_wallpaper.md +++ b/docs/_posts/2021-06-02-modification_of_wallpaper.md @@ -90,6 +90,8 @@ To successfully implement this search, you need to be ingesting logs with the Im | 54.0 | 60 | 90 | Wallpaper modification on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-02-revil_common_exec_parameter.md b/docs/_posts/2021-06-02-revil_common_exec_parameter.md index ae9c1e4b26..0c44b850b3 100644 --- a/docs/_posts/2021-06-02-revil_common_exec_parameter.md +++ b/docs/_posts/2021-06-02-revil_common_exec_parameter.md @@ -90,6 +90,8 @@ third party tool may have same command line parameters as revil ransomware. | 54.0 | 60 | 90 | A process $process_name$ with commandline $process$ related to revil ransomware in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md b/docs/_posts/2021-06-02-wbemprox_com_object_execution.md index 3509ede78c..61c4e7f489 100644 --- a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md +++ b/docs/_posts/2021-06-02-wbemprox_com_object_execution.md @@ -94,6 +94,8 @@ legitimate process that are not in the exception list may trigger this event. | 35.0 | 70 | 50 | Suspicious COM Object Execution on $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-03-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md b/docs/_posts/2021-06-03-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md index 9077068608..4bc2be732e 100644 --- a/docs/_posts/2021-06-03-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md +++ b/docs/_posts/2021-06-03-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md @@ -85,6 +85,8 @@ Many benign applications will create processes from executables in Windows\Temp, | 80.0 | 80 | 100 | Multiple processes were executed out of windows\temp within a short amount of time on $dest$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md b/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md index 3caa32ea9b..e10fee8891 100644 --- a/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md +++ b/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md @@ -85,6 +85,8 @@ Admin activities or installing related updates may do a sudden stop to list of s | 72.0 | 90 | 80 | Known services $Message$ terminated by a potential ransomware on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md b/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md index f351346665..b3fed5907a 100644 --- a/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md +++ b/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md @@ -90,6 +90,8 @@ Administrators, administrative actions or certain applications may run many inst | 56.0 | 80 | 70 | An excessive amount of $process_name$ was executed on $dest$ indicative of suspicious behavior. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md b/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md index 568d814110..2c53d899b3 100644 --- a/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md +++ b/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md @@ -96,6 +96,8 @@ Limited false positives. Filter as needed. | 48.0 | 60 | 80 | A suspicious powershell script contains GetProcAddress API in $Message$ with EventCode $EventCode$ in host $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md b/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md index 46337ba380..695de3dba9 100644 --- a/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md +++ b/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md @@ -96,6 +96,8 @@ False positives should be limited. Filter as needed. | 56.0 | 70 | 80 | A suspicious powershell script contains base64 command in $Message$ with EventCode $EventCode$ in host $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md b/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md index 3d7a47d2a4..0a0fd13466 100644 --- a/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md +++ b/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md @@ -90,6 +90,8 @@ False positives may only pertain to it not being related to Empire, but another | 81.0 | 90 | 90 | The following behavior was identified and typically related to PowerShell-Empire on $ComputerName$ by $User$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md b/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md index 5489a15211..8cc908c6cc 100644 --- a/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md +++ b/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md @@ -86,6 +86,8 @@ False positives should be limited as the commands being identifies are quite spe | 90.0 | 90 | 100 | The following behavior was identified and typically related to MimiKatz being loaded within the context of PowerShell on $ComputerName$ by $User$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md b/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md index 7ef9b9e832..bafcdd5b5a 100644 --- a/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md +++ b/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md @@ -86,6 +86,8 @@ Potential for some third party applications to disable AMSI upon invocation. Fil | 49.0 | 70 | 70 | Possible AMSI Unloading via Reflection using PowerShell on $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md b/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md index 5e47c3b203..f7c233a19d 100644 --- a/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md +++ b/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md @@ -96,6 +96,8 @@ administrator may execute this app to manage disk | 90.0 | 100 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to clear the unallocated sectors of a specific disk. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md b/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md index 46d74a004c..9ba31ccdc3 100644 --- a/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md +++ b/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md @@ -93,6 +93,8 @@ network operator may disable audit event logs for debugging purposes. | 24.0 | 30 | 80 | WevtUtil.exe used to disable Event Logging on $dest | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md b/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md index 4eabb47cd2..23c0b948e7 100644 --- a/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md +++ b/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md @@ -89,6 +89,8 @@ takeown.exe is a normal windows application that may used by network operator. | 56.0 | 70 | 80 | A suspicious of execution of $process_name$ with process id $process_id$ and commandline $process$ to modify permission of directory or files in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md b/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md index cd31a84c93..54b524c81c 100644 --- a/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md +++ b/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md @@ -87,6 +87,8 @@ powershell developer may used this function in their script for instance checkin | 40.0 | 50 | 80 | A suspicious powershell script contains Thread Mutex in $Message$ with EventCode $EventCode$ in host $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-10-powershell_domain_enumeration.md b/docs/_posts/2021-06-10-powershell_domain_enumeration.md index 334d3e75cf..549c86e31d 100644 --- a/docs/_posts/2021-06-10-powershell_domain_enumeration.md +++ b/docs/_posts/2021-06-10-powershell_domain_enumeration.md @@ -88,6 +88,8 @@ It is possible there will be false positives, filter as needed. | 42.0 | 60 | 70 | A suspicious powershell script contains domain enumeration command in $Message$ with EventCode $EventCode$ in host $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md b/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md index 7eb39b4055..6e6496fc80 100644 --- a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md +++ b/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md @@ -90,6 +90,8 @@ False positives should be limited as day to day scripts do not use this method. | 56.0 | 70 | 80 | A suspicious powershell script contains reflective class assembly command in $Message$ to load .net code in memory with EventCode $EventCode$ in host $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md b/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md index e96b448091..3ddd554733 100644 --- a/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md +++ b/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md @@ -88,6 +88,8 @@ powershell may used this function to process compressed data. | 40.0 | 50 | 80 | A suspicious powershell script contains stream command in $Message$ commonly for processing compressed or to decompressed binary file with EventCode $EventCode$ in host $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md b/docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md index 5eb7f0dd2c..8f83bb0ddd 100644 --- a/docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md +++ b/docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md @@ -83,6 +83,8 @@ powershell may used this function to store out object into memory. | 40.0 | 50 | 80 | A suspicious powershell script contains memorystream command in $Message$ as new object backstore with EventCode $EventCode$ in host $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md b/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md index 94f83aaf72..255a8f6b35 100644 --- a/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md +++ b/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md @@ -89,6 +89,8 @@ Administrators may modify the boot configuration ignore failure during testing a | 56.0 | 70 | 80 | A suspicious process $process_name$ with process id $process_id$ contains commandline $process$ to ignore all bcdedit execution failure in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md b/docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md index 0b5a793fd5..81a0d8d5bc 100644 --- a/docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md +++ b/docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md @@ -84,6 +84,8 @@ network administrator may used this command for checking purposes | 56.0 | 70 | 80 | A suspicious powershell script contains AV recon command in $Message$ with EventCode $EventCode$ in host $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-10-recon_using_wmi_class.md b/docs/_posts/2021-06-10-recon_using_wmi_class.md index 21b7da7740..5690b9ad1f 100644 --- a/docs/_posts/2021-06-10-recon_using_wmi_class.md +++ b/docs/_posts/2021-06-10-recon_using_wmi_class.md @@ -83,6 +83,8 @@ network administrator may used this command for checking purposes | 60.0 | 75 | 80 | A suspicious powershell script contains host recon command in $Message$ with EventCode $EventCode$ in host $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md b/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md index 4d52e52040..7c5d2b675f 100644 --- a/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md +++ b/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md @@ -83,6 +83,8 @@ network administrator may used this command for checking purposes | 30.0 | 30 | 100 | Suspicious powerShell script execution by $user$ on $ComputerName$ via EventCode 4104, where WMI is performing an event query looking for running processes or running services | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md b/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md index d9d9b7054f..ac0a37a013 100644 --- a/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md +++ b/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md @@ -91,6 +91,8 @@ The wevtutil.exe application is a legitimate Windows event log utility. Administ | 63.0 | 70 | 90 | A wevtutil process $process_name$ with commandline $cmd_line$ to clear event logs in host $dest_device_id$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md b/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md index 79213df4b7..908ec247b7 100644 --- a/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md +++ b/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md @@ -90,6 +90,8 @@ network operator may disable audit event logs for debugging purposes. | 63.0 | 70 | 90 | A wevtutil process $process_name$ with commandline $cmd_line$ to disable event logs in host $dest_device_id$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md b/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md index 5d825321fb..f9da351d22 100644 --- a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md +++ b/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md @@ -93,6 +93,8 @@ It is possible some applications will create a consumer and may be required to b | 63.0 | 70 | 90 | Possible malicious WMI Subscription created on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md b/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md index a13cfc3a1b..805acf7082 100644 --- a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md +++ b/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md @@ -87,6 +87,8 @@ It is possible the Event Logging service gets shut down due to system errors or | 9.0 | 30 | 30 | The Windows Event Log Service shutdown on $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md b/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md index 8fc395861a..d236afcf2f 100644 --- a/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md +++ b/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md @@ -92,6 +92,8 @@ unknown | 56.0 | 80 | 70 | Suspicious process of cscript.exe with a parent process $parent_process_name$ where it tries to execute javascript using jscript.encode CLSID (COM OBJ), detected on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md b/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md index 569ddd6cbc..119e29a6f6 100644 --- a/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md +++ b/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md @@ -83,6 +83,8 @@ network operator may enable or disable this windows feature. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md b/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md index b1f725b807..6d68aa0244 100644 --- a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md +++ b/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md @@ -91,6 +91,8 @@ network operator may use this batch command to delete recursively a directory or +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md b/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md index 6b8b382676..fbac458768 100644 --- a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md +++ b/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md @@ -91,6 +91,8 @@ network admin may modify this firewall feature that may cause this rule to be tr +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md b/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md index fac070cd18..01fd7fa0f4 100644 --- a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md +++ b/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md @@ -92,6 +92,8 @@ network admin may modify this firewall feature that may cause this rule to be tr +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md b/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md index 77d8807714..fdc2f0ded4 100644 --- a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md +++ b/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md @@ -86,6 +86,8 @@ excessive execution of sc.exe is quite suspicious since it can modify or execute +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md b/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md index 11b2d9b243..94cf2a5f87 100644 --- a/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md +++ b/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md @@ -93,6 +93,8 @@ Legitimate programs and administrators will execute sc.exe with the start disabl | 80.0 | 80 | 100 | An excessive amount of $process_name$ was executed on $dest$ attempting to disable services. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md b/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md index b2e1101642..2315e1b8c7 100644 --- a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md +++ b/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md @@ -94,6 +94,8 @@ Unknown. This may require filtering. | 72.0 | 80 | 90 | Suspicious print driver was loaded on endpoint $ComputerName$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md b/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md index 53ccf0ee6d..23f91b514b 100644 --- a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md +++ b/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md @@ -95,6 +95,8 @@ False positives are unknown and filtering may be required. | 72.0 | 80 | 90 | Suspicious printer spooler errors have occured on endpoint $ComputerName$ with EventCode $EventCode$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md b/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md index bf4ab7015b..bbe31b19cd 100644 --- a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md +++ b/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md @@ -100,6 +100,8 @@ Limited false positives have been identified. There are limited instances where | 72.0 | 80 | 90 | $parent_process$ has spawned $process_name$ on endpoint $ComputerName$. This behavior is suspicious and related to PrintNightmare. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md b/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md index 430cec0a0c..15d5421041 100644 --- a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md +++ b/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md @@ -92,6 +92,8 @@ unknown | 72.0 | 80 | 90 | $Image$ with process id $process_id$ has loaded a driver from $ImageLoaded$ on endpoint $Computer$. This behavior is suspicious and related to PrintNightmare. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md b/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md index 1cd3fe8f83..4b4395f9ca 100644 --- a/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md +++ b/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md @@ -86,6 +86,8 @@ Unknown. Filter as needed. | 72.0 | 80 | 90 | $SourceImage$ was GrantedAccess open access to $TargetImage$ on endpoint $Computer$. This behavior is suspicious and related to PrintNightmare. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md b/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md index fb89aafcde..67347664e8 100644 --- a/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md +++ b/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md @@ -99,6 +99,8 @@ Unknown. | 72.0 | 80 | 90 | $process_name$ has been identified writing dll's to $file_path$ on endpoint $dest$. This behavior is suspicious and related to PrintNightmare. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md b/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md index 8170d12dbf..9f5195caee 100644 --- a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md +++ b/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md @@ -93,6 +93,8 @@ Limited false positives. Filter as needed. | 72.0 | 80 | 90 | $process_name$ has been identified writing dll's to $file_path$ on endpoint $dest$. This behavior is suspicious and related to PrintNightmare. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md b/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md index 11ed468fdc..78f276378c 100644 --- a/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md +++ b/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md @@ -89,6 +89,8 @@ quite minimal false positive expected. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md b/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md index 46a1b16609..e9706d7112 100644 --- a/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md +++ b/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md @@ -92,6 +92,8 @@ Limited false positives. However, tune based on scripts that may perform this ac +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-12-net_profiler_uac_bypass.md b/docs/_posts/2021-07-12-net_profiler_uac_bypass.md index 5152615424..3bd0cb1643 100644 --- a/docs/_posts/2021-07-12-net_profiler_uac_bypass.md +++ b/docs/_posts/2021-07-12-net_profiler_uac_bypass.md @@ -91,6 +91,8 @@ limited false positive. It may trigger by some windows update that will modify t | 63.0 | 70 | 90 | Suspicious modification of registry $registry_path$ with possible payload path $registry_value_name$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md b/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md index b7757ae4cd..e9d1f804a4 100644 --- a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md +++ b/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md @@ -94,6 +94,8 @@ unknown. all of the dll loaded by mmc.exe is microsoft signed dll. | 63.0 | 70 | 90 | Suspicious unsigned $ImageLoaded$ loaded by $Image$ on endpoint $Computer$ with EventCode $EventCode$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md b/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md index 7d1b88b003..194840ecde 100644 --- a/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md +++ b/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md @@ -105,6 +105,8 @@ It's possible that a user will start to create compute instances for the fir | 18.0 | 30 | 60 | User $user$ is creating a new instance $dest$ for the first time | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-19-aws_createaccesskey.md b/docs/_posts/2021-07-19-aws_createaccesskey.md index 862fbaf211..44f1ca20d7 100644 --- a/docs/_posts/2021-07-19-aws_createaccesskey.md +++ b/docs/_posts/2021-07-19-aws_createaccesskey.md @@ -89,6 +89,8 @@ While this search has no known false positives, it is possible that an AWS admin | 63.0 | 70 | 90 | User $user_arn$ is attempting to create access keys for $requestParameters.userName$ from this IP $src$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-19-aws_createloginprofile.md b/docs/_posts/2021-07-19-aws_createloginprofile.md index d48f8143ce..40e193bd7d 100644 --- a/docs/_posts/2021-07-19-aws_createloginprofile.md +++ b/docs/_posts/2021-07-19-aws_createloginprofile.md @@ -93,6 +93,8 @@ While this search has no known false positives, it is possible that an AWS admin | 72.0 | 90 | 80 | User $user_arn$ is attempting to create a login profile for $requestParameters.userName$ and did a console login from this IP $src_ip$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-19-aws_updateloginprofile.md b/docs/_posts/2021-07-19-aws_updateloginprofile.md index b5ccdd8908..979d3810dc 100644 --- a/docs/_posts/2021-07-19-aws_updateloginprofile.md +++ b/docs/_posts/2021-07-19-aws_updateloginprofile.md @@ -89,6 +89,8 @@ While this search has no known false positives, it is possible that an AWS admin | 30.0 | 50 | 60 | From IP address $sourceIPAddress$, user agent $userAgent$ has trigged an event $eventName$ for updating the existing login profile, potentially giving user $user_arn$ more access privilleges | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md b/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md index b2f235ea1b..2fe745f183 100644 --- a/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md +++ b/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md @@ -97,6 +97,8 @@ While this search has no known false positives, it is possible that an AWS admin | 48.0 | 60 | 80 | User $user_arn$ has created an open/public bucket $bucketName$ with the following permissions $permission$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md b/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md index d9caebbd8a..7a9afa0ef8 100644 --- a/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md +++ b/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md @@ -93,6 +93,8 @@ While this search has no known false positives, it is possible that an AWS admin | 48.0 | 60 | 80 | User $userIdentity.userName$ has created an open/public bucket $bucketName$ using AWS CLI with the following permissions - $requestParameters.accessControlList.x-amz-grant-read$ $requestParameters.accessControlList.x-amz-grant-read-acp$ $requestParameters.accessControlList.x-amz-grant-write$ $requestParameters.accessControlList.x-amz-grant-write-acp$ $requestParameters.accessControlList.x-amz-grant-full-control$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md index 71f939d4e3..95bfaaa617 100644 --- a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md +++ b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md @@ -99,6 +99,8 @@ limitted. this anomaly behavior is not commonly seen in clean host. | 56.0 | 70 | 80 | a mshta parent process $parent_process_name$ spawn child process $process_name$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md b/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md index aba4219e77..795478bfdb 100644 --- a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md +++ b/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md @@ -97,6 +97,8 @@ IT or network admin may create an document automation that will run shell script | 56.0 | 70 | 80 | an office product parent process $parent_process_name$ spawn child process $process_name$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md b/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md index 7613b11d71..5b7a56a807 100644 --- a/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md +++ b/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md @@ -89,6 +89,8 @@ It is possible that an AWS admin has legitimately shared a snapshot with others | 48.0 | 60 | 80 | AWS EC2 snapshot from account $aws_account_id$ is shared with $requested_account_id$ by user $user_arn$ from $src_ip$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md b/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md index 51fdd631af..081a8e2250 100644 --- a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md +++ b/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md @@ -91,6 +91,8 @@ Limited false positives as the scope is limited to SAM, SYSTEM and SECURITY hive | 80.0 | 80 | 100 | PowerShell was identified running a script to capture the SAM hive on endpoint $ComputerName$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-07-23-sam_database_file_access_attempt.md b/docs/_posts/2021-07-23-sam_database_file_access_attempt.md index a4ad539c81..e5217eb727 100644 --- a/docs/_posts/2021-07-23-sam_database_file_access_attempt.md +++ b/docs/_posts/2021-07-23-sam_database_file_access_attempt.md @@ -86,6 +86,8 @@ Natively, `dllhost.exe` will access the files. Every environment will have addit | 80.0 | 80 | 100 | The following process $process_name$ accessed the object $Object_Name$ attempting to gain access to credentials on $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md b/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md index 1ac00fea96..ed1b4cc266 100644 --- a/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md +++ b/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md @@ -88,6 +88,8 @@ unknown | 70.0 | 70 | 100 | rundl32 process $SourceImage$ create a remote thread to browser process $TargetImage$ in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-26-rundll32_dnsquery.md b/docs/_posts/2021-07-26-rundll32_dnsquery.md index bfee752058..1181587c90 100644 --- a/docs/_posts/2021-07-26-rundll32_dnsquery.md +++ b/docs/_posts/2021-07-26-rundll32_dnsquery.md @@ -90,6 +90,8 @@ unknown | 56.0 | 70 | 80 | rundll32 process $process_name$ having a dns query to $QueryName$ in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md b/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md index e07ef82bcb..da6073a45d 100644 --- a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md +++ b/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md @@ -89,6 +89,8 @@ unknown | 80.0 | 80 | 100 | rundll32 process $process_name$ drops a file $TargetFilename$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md b/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md index d700ef8ebf..a4fe383fc7 100644 --- a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md +++ b/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md @@ -97,6 +97,8 @@ limitted. this parameter is not commonly used by windows application but can be | 56.0 | 70 | 80 | rundll32 process $process_name$ with commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md b/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md index 0100e04011..c48c73668b 100644 --- a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md +++ b/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md @@ -97,6 +97,8 @@ third party application may used this dll export name to execute function. | 42.0 | 60 | 70 | rundll32 process $process_name$ with commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-27-chcp_command_execution.md b/docs/_posts/2021-07-27-chcp_command_execution.md index 63e0565539..adf0957603 100644 --- a/docs/_posts/2021-07-27-chcp_command_execution.md +++ b/docs/_posts/2021-07-27-chcp_command_execution.md @@ -89,6 +89,8 @@ other tools or script may used this to change code page to UTF-* or others | 9.0 | 30 | 30 | parent process $parent_process_name$ spawning chcp process $process_name$ with parent command line $parent_process$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md b/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md index 2833a0dcdc..e0f2084b47 100644 --- a/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md +++ b/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md @@ -101,6 +101,8 @@ minimal. but network operator can use this application to load dll. | 56.0 | 70 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a DLL using the silent parameter. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md b/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md index 5d1269a72b..a45dc70dea 100644 --- a/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md +++ b/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md @@ -88,6 +88,8 @@ unknown | 56.0 | 70 | 80 | rundl32 process $SourceImage$ create a remote thread to process $TargetImage$ in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-30-drop_icedid_license_dat.md b/docs/_posts/2021-07-30-drop_icedid_license_dat.md index d0cafd705b..4179feddc6 100644 --- a/docs/_posts/2021-07-30-drop_icedid_license_dat.md +++ b/docs/_posts/2021-07-30-drop_icedid_license_dat.md @@ -84,6 +84,8 @@ unknown | 63.0 | 70 | 90 | process $SourceImage$ create a file $TargetImage$ in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md b/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md index 4ff251d2f7..1d73297a56 100644 --- a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md +++ b/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md @@ -89,6 +89,8 @@ unknown | 72.0 | 80 | 90 | process $SourceImage$ create a file $TargetImage$ in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md b/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md index 659d516f84..953cb6e2eb 100644 --- a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md +++ b/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md @@ -97,6 +97,8 @@ unknown | 63.0 | 70 | 90 | Office application spawning regsvr32.exe on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md b/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md index 6bec47116e..8a738ccbc3 100644 --- a/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md +++ b/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md @@ -85,6 +85,8 @@ unknown | 9.0 | 30 | 30 | process $SourceImage$ create a file $TargetImage$ in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md b/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md index b31658f923..b287fffbf3 100644 --- a/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md +++ b/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md @@ -88,6 +88,8 @@ unknown | 70.0 | 70 | 100 | process $SourceImage$ create a remote thread to shell app process $TargetImage$ in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md b/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md index 522faeeb2d..71c4261315 100644 --- a/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md +++ b/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md @@ -93,6 +93,8 @@ unknown. | 30.0 | 50 | 60 | process $process_name$ with a cmdline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-10-powershell_execute_com_object.md b/docs/_posts/2021-08-10-powershell_execute_com_object.md index 23d378ab9e..c99d3d9e87 100644 --- a/docs/_posts/2021-08-10-powershell_execute_com_object.md +++ b/docs/_posts/2021-08-10-powershell_execute_com_object.md @@ -87,6 +87,8 @@ network operrator may use this command. | 5.0 | 10 | 50 | A suspicious powershell script contains COM CLSID command in $Message$ with EventCode $EventCode$ in host $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-11-fsutil_zeroing_file.md b/docs/_posts/2021-08-11-fsutil_zeroing_file.md index a17491c0a5..7f5af18908 100644 --- a/docs/_posts/2021-08-11-fsutil_zeroing_file.md +++ b/docs/_posts/2021-08-11-fsutil_zeroing_file.md @@ -87,6 +87,8 @@ unknown | 54.0 | 60 | 90 | Possible file data deletion on $dest$ using $process$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md b/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md index 2bfa6c6f8b..0d83ccf517 100644 --- a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md +++ b/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md @@ -91,6 +91,8 @@ not so common. but 3rd part app may load this dll. | 48.0 | 60 | 80 | The following module $ImageLoaded$ was loaded by a non-standard application on endpoint $Computer$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md b/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md index 5a44e5978c..d0c3dda7c1 100644 --- a/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md +++ b/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md @@ -97,6 +97,8 @@ network admin or normal user may share files to customer and external team. | 72.0 | 80 | 90 | suspicious share gdrive from $parameters.owner$ to $email$ namely as $parameters.doc_title$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md b/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md index afee5a519f..46e118a824 100644 --- a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md +++ b/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md @@ -94,6 +94,8 @@ network admin and normal user may send this file attachment as part of their day | 49.0 | 70 | 70 | suspicious email from $source.address$ to $destination{}.address$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md b/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md index dcd885c546..08ccd93946 100644 --- a/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md +++ b/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md @@ -93,6 +93,8 @@ unknown | 25.0 | 50 | 50 | archive process $process_name$ with suspicious cmdline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md index 334c6b56ee..c71264bb1f 100644 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md +++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md @@ -100,6 +100,8 @@ unknown | 70.0 | 70 | 100 | Vulnerabilities with severity high found in image $image$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md index b2c980d11f..90e965f033 100644 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md +++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md @@ -100,6 +100,8 @@ unknown | 7.0 | 10 | 70 | Vulnerabilities with severity high found in repository $repositoryName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md index 47d4bd1059..3734e2b974 100644 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md +++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md @@ -100,6 +100,8 @@ unknown | 21.0 | 30 | 70 | Vulnerabilities with severity high found in image $image$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md b/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md index dc16a20838..5d68ed25cb 100644 --- a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md +++ b/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md @@ -91,6 +91,8 @@ network admin and normal user may send this file attachment as part of their day | 9.0 | 30 | 30 | suspicious email from $source.address$ to $destination{}.address$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-18-esentutl_sam_copy.md b/docs/_posts/2021-08-18-esentutl_sam_copy.md index 3cfadcc403..a51616375c 100644 --- a/docs/_posts/2021-08-18-esentutl_sam_copy.md +++ b/docs/_posts/2021-08-18-esentutl_sam_copy.md @@ -98,6 +98,8 @@ False positives should be limited. Filter as needed. | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user user$ attempting to capture credentials for offline cracking or observability. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-18-powershell_4104_hunting.md b/docs/_posts/2021-08-18-powershell_4104_hunting.md index d9a5c16157..a2090ba416 100644 --- a/docs/_posts/2021-08-18-powershell_4104_hunting.md +++ b/docs/_posts/2021-08-18-powershell_4104_hunting.md @@ -257,6 +257,8 @@ Limited false positives. May filter as needed. | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ executing suspicious commands. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md index 8c3389366b..311931c0c7 100644 --- a/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md +++ b/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md @@ -96,6 +96,8 @@ When your development is spreaded in different time zones, applying this rule ca | 49.0 | 70 | 70 | Container uploaded outside business hours from $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md index 56f58d649c..80759e0adc 100644 --- a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md +++ b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md @@ -97,6 +97,8 @@ unknown | 49.0 | 70 | 70 | Container uploaded from unknown user $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md b/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md index 32a1341f7f..4d05aae845 100644 --- a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md +++ b/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md @@ -83,6 +83,8 @@ normal user or normal transaction may contain the subject and file type attachme +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md index ca22152540..f624197c95 100644 --- a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md +++ b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md @@ -75,6 +75,8 @@ Some networks may use kerberized FTP or telnet servers, however, this is rare. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-20-github_commit_changes_in_master.md b/docs/_posts/2021-08-20-github_commit_changes_in_master.md index 8274787cf1..5939a739d2 100644 --- a/docs/_posts/2021-08-20-github_commit_changes_in_master.md +++ b/docs/_posts/2021-08-20-github_commit_changes_in_master.md @@ -83,6 +83,8 @@ admin can do changes directly to master branch | 9.0 | 30 | 30 | suspicious commit by $commit.commit.author.email$ to main branch | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md b/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md index e7338ae6a5..3d6a15c034 100644 --- a/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md +++ b/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md @@ -92,6 +92,8 @@ unknown | 49.0 | 70 | 70 | Local File Inclusion Attack detected on $host$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-23-getlocaluser_with_powershell.md b/docs/_posts/2021-08-23-getlocaluser_with_powershell.md index 6caea2987f..5a709ec9cb 100644 --- a/docs/_posts/2021-08-23-getlocaluser_with_powershell.md +++ b/docs/_posts/2021-08-23-getlocaluser_with_powershell.md @@ -85,6 +85,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md b/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md index 24ce365ed1..8bf13b7bf4 100644 --- a/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md +++ b/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md @@ -82,6 +82,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md index 5fa7a10b5b..3ee50b9d02 100644 --- a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md +++ b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md @@ -85,6 +85,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md index 3a824e441e..c9a6f0ad85 100644 --- a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md +++ b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md @@ -82,6 +82,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md b/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md index d47522863c..234e51385f 100644 --- a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md +++ b/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md @@ -83,6 +83,8 @@ normal email contains this link that are known application within the organizati +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md b/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md index b9967305d7..2ea358d35c 100644 --- a/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md +++ b/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md @@ -97,6 +97,8 @@ normal user or normal transaction may contain the subject and file type attachme | 21.0 | 30 | 70 | suspicious share gdrive from $parameters.owner$ to $email$ namely as $parameters.doc_title$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md b/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md index cb2534cf91..d867ce7fdf 100644 --- a/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md +++ b/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md @@ -87,6 +87,8 @@ unknown | 49.0 | 70 | 70 | Remote File Inclusion Attack detected on $host$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md b/docs/_posts/2021-08-24-adsisearcher_account_discovery.md index 0220668c50..c647310767 100644 --- a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md +++ b/docs/_posts/2021-08-24-adsisearcher_account_discovery.md @@ -87,6 +87,8 @@ Administrators or power users may use this command for troubleshooting. | 25.0 | 50 | 50 | powershell process having commandline $Message$ for user enumeration | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md b/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md index 1ced833dc0..64b17ddb4e 100644 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md +++ b/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md @@ -93,6 +93,8 @@ Administrators or power users may use this command for troubleshooting. | 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md b/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md index ce1b122f58..670eea9bd8 100644 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md +++ b/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md @@ -94,6 +94,8 @@ Administrators or power users may use this command for troubleshooting. | 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md b/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md index e74b409fa5..d88b40119a 100644 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md +++ b/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md @@ -93,6 +93,8 @@ Administrators or power users may use this command for troubleshooting. | 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md b/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md index dbe69057fa..6fd459041b 100644 --- a/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md +++ b/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md @@ -92,6 +92,8 @@ Limited false positives as this requires an active Administrator or adversary to | 12.0 | 30 | 40 | Suspicious PowerShell Get-DomainTrust was identified on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md b/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md index 91e4bf8798..b678040a32 100644 --- a/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md @@ -87,6 +87,8 @@ It is possible certain system management frameworks utilize this command to gath | 12.0 | 30 | 40 | Suspicious PowerShell Get-DomainTrust was identified on endpoint $ComputerName$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-get_aduser_with_powershell.md b/docs/_posts/2021-08-24-get_aduser_with_powershell.md index 002fb470d8..38c81abc56 100644 --- a/docs/_posts/2021-08-24-get_aduser_with_powershell.md +++ b/docs/_posts/2021-08-24-get_aduser_with_powershell.md @@ -93,6 +93,8 @@ Administrators or power users may use this command for troubleshooting. | 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md b/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md index 2f23d66fc2..3863094d15 100644 --- a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md @@ -87,6 +87,8 @@ Administrators or power users may use this command for troubleshooting. | 25.0 | 50 | 50 | powershell process having commandline $Message$ for user enumeration | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-get_domainuser_with_powershell.md b/docs/_posts/2021-08-24-get_domainuser_with_powershell.md index a77d223086..0fce4f455b 100644 --- a/docs/_posts/2021-08-24-get_domainuser_with_powershell.md +++ b/docs/_posts/2021-08-24-get_domainuser_with_powershell.md @@ -93,6 +93,8 @@ Administrators or power users may use this command for troubleshooting. | 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md b/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md index 46ab159e26..018bbcca06 100644 --- a/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md @@ -87,6 +87,8 @@ Administrators or power users may use this command for troubleshooting. | 25.0 | 50 | 50 | powershell process having commandline $Message$ for user enumeration | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md index e4493b0f9b..5d8cbfffd1 100644 --- a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md +++ b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md @@ -93,6 +93,8 @@ Administrators or power users may use this command for troubleshooting. | 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md index aae67add03..1a7ad97d66 100644 --- a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md @@ -87,6 +87,8 @@ Administrators or power users may use this command for troubleshooting. | 25.0 | 50 | 50 | powershell process having commandline $Message$ for user enumeration | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md b/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md index 8aa14886e6..7030f6f31a 100644 --- a/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md +++ b/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md @@ -91,6 +91,8 @@ unknown | 81.0 | 90 | 90 | Kubernetes Scanner image pulled on host $host$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md b/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md index 9662fc873f..127f2d4a26 100644 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md +++ b/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md @@ -86,6 +86,8 @@ Administrators or power users may use Adsisearcher for troubleshooting. | 18.0 | 30 | 60 | Domain group discovery enumeration using PowerShell on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_net.md b/docs/_posts/2021-08-25-domain_group_discovery_with_net.md index 2206509b90..e0521d1c60 100644 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_net.md +++ b/docs/_posts/2021-08-25-domain_group_discovery_with_net.md @@ -95,6 +95,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Domain group discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md b/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md index c04b837758..e8a4231b57 100644 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md +++ b/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md @@ -95,6 +95,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Domain group discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md index e1f29da27c..a33aabc871 100644 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md +++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md @@ -95,6 +95,8 @@ Administrators or power users may use this command for troubleshooting. | 21.0 | 30 | 70 | Elevated domain group discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md index 224c7c81cf..27316125e0 100644 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md +++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md @@ -86,6 +86,8 @@ Administrators or power users may use this PowerView for troubleshooting. | 21.0 | 30 | 70 | Elevated group discovery using PowerView on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md index b3600fc1a2..b02f6a2edc 100644 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md +++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md @@ -95,6 +95,8 @@ Administrators or power users may use this command for troubleshooting. | 21.0 | 30 | 70 | Elevated domain group discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-getadgroup_with_powershell.md b/docs/_posts/2021-08-25-getadgroup_with_powershell.md index 3f20aaac21..04189e415d 100644 --- a/docs/_posts/2021-08-25-getadgroup_with_powershell.md +++ b/docs/_posts/2021-08-25-getadgroup_with_powershell.md @@ -95,6 +95,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Domain group discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md b/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md index 52c911191b..d5fb9e7081 100644 --- a/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md +++ b/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md @@ -86,6 +86,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | Domain group discovery enumeration using PowerShell on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md b/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md index 5ad581318f..a6b52bd6ef 100644 --- a/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md +++ b/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md @@ -95,6 +95,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Domain group discovery with PowerView on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md b/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md index ed741820e3..deb4ecd7b7 100644 --- a/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md +++ b/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md @@ -91,6 +91,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Network Connection discovery on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md index 303544f962..b392b27e54 100644 --- a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md +++ b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md @@ -95,6 +95,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Domain group discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md index bff9af74a4..0e6aa72098 100644 --- a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md +++ b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md @@ -86,6 +86,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | Domain group discovery enumeration using PowerShell on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md index c561c75827..7f778d80e7 100644 --- a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md +++ b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md @@ -89,6 +89,8 @@ Administrators or power users may use this command for troubleshooting. | 9.0 | 30 | 30 | an instance of process $process_name$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md index 4896efdf6e..2bdb60818a 100644 --- a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md +++ b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md @@ -83,6 +83,8 @@ Administrators or power users may use this command for troubleshooting. | 9.0 | 30 | 30 | powershell process having commandline $Message$ to query domain password policy | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md index 75a973821b..09f7a7626b 100644 --- a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md +++ b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md @@ -89,6 +89,8 @@ Administrators or power users may use this command for troubleshooting. | 25.0 | 50 | 50 | an instance of process $process_name$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md index ddd7c2ab64..b645bc2992 100644 --- a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md +++ b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md @@ -83,6 +83,8 @@ Administrators or power users may use this command for troubleshooting. | 9.0 | 30 | 30 | powershell process having commandline $Message$ to query domain user password policy. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md index 14ebee4b0c..dd15fd6ac7 100644 --- a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md +++ b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md @@ -89,6 +89,8 @@ Administrators or power users may use this command for troubleshooting. | 30.0 | 50 | 60 | an instance of process $process_name$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md index d0232abe6a..5481d2ab36 100644 --- a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md +++ b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md @@ -83,6 +83,8 @@ Administrators or power users may use this command for troubleshooting. | 30.0 | 50 | 60 | powershell process having commandline $Message$ to query domain policy. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md b/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md index c2e3a8ba80..6b9495e9fd 100644 --- a/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md +++ b/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md @@ -86,6 +86,8 @@ Administrators or power users may use this PowerView functions for troubleshooti | 15.0 | 30 | 50 | Domain group discovery enumeration using PowerView on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-26-password_policy_discovery_with_net.md b/docs/_posts/2021-08-26-password_policy_discovery_with_net.md index e68f7fecf5..e437824df6 100644 --- a/docs/_posts/2021-08-26-password_policy_discovery_with_net.md +++ b/docs/_posts/2021-08-26-password_policy_discovery_with_net.md @@ -89,6 +89,8 @@ Administrators or power users may use this command for troubleshooting. | 9.0 | 30 | 30 | an instance of process $process_name$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md b/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md index a101c585c9..c0839aab80 100644 --- a/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md +++ b/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md @@ -100,6 +100,8 @@ This detection should yield little or no false positive results. It is uncommon | 63.0 | 70 | 90 | A process $process_name$ that launching .lnk file in $file_path$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md index 4e8434ac4c..943785b6be 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md +++ b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md @@ -90,6 +90,8 @@ Limited false positives, however, tune as needed. | 80.0 | 80 | 100 | Activity related to ProxyShell has been identified on $dest$. Review events and take action accordingly. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md index 4b93056cbc..3cd1f2c919 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md +++ b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md @@ -95,6 +95,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | Local user discovery enumeration using PowerShell on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md b/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md index f9387c85ff..847eff86d3 100644 --- a/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md +++ b/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md @@ -91,6 +91,8 @@ Administrators or power users may use this command for troubleshooting. | 21.0 | 30 | 70 | Domain controller discovery on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-30-remote_system_discovery_with_net.md b/docs/_posts/2021-08-30-remote_system_discovery_with_net.md index df1017057f..8848308f9b 100644 --- a/docs/_posts/2021-08-30-remote_system_discovery_with_net.md +++ b/docs/_posts/2021-08-30-remote_system_discovery_with_net.md @@ -91,6 +91,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md b/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md index 53f8824225..799420ec7f 100644 --- a/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md +++ b/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md @@ -90,6 +90,8 @@ False positives have been limited when the Anonymous Logon is used for Account N | 56.0 | 80 | 70 | A remote host is enumerating a $dest$ to identify permissions. This is a precursor event to CVE-2021-36942, PetitPotam. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md b/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md index b937fe2768..3f078d4371 100644 --- a/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md +++ b/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md @@ -86,6 +86,8 @@ False positives are possible if the environment is using certificates for authen | 56.0 | 80 | 70 | A Kerberos TGT was requested in a non-standard manner against $dest$, potentially related to CVE-2021-36942, PetitPotam. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md b/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md index 92cfbe683b..096780eb42 100644 --- a/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md +++ b/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md @@ -91,6 +91,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md b/docs/_posts/2021-09-01-circle_ci_disable_security_step.md index 7f7ef5a6dd..30fe4ad121 100644 --- a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md +++ b/docs/_posts/2021-09-01-circle_ci_disable_security_step.md @@ -96,6 +96,8 @@ unknown | 72.0 | 80 | 90 | disable security step $mandatory_step$ in job $job_name$ from user $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md b/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md index 259e79412f..43a2a3fbdd 100644 --- a/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md +++ b/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md @@ -91,6 +91,8 @@ Administrators or power users may use this command for troubleshooting. | 21.0 | 30 | 70 | Domain controller discovery on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md b/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md index bfd16b610e..0e2e1c35a5 100644 --- a/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md +++ b/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md @@ -95,6 +95,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Domain group discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md b/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md index 6bc415ea6a..09dd3c424b 100644 --- a/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md +++ b/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md @@ -82,6 +82,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md b/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md index 8edd5f6626..4aa3b5b543 100644 --- a/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md +++ b/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md @@ -82,6 +82,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-01-github_commit_in_develop.md b/docs/_posts/2021-09-01-github_commit_in_develop.md index 03e23b4378..7351856da8 100644 --- a/docs/_posts/2021-09-01-github_commit_in_develop.md +++ b/docs/_posts/2021-09-01-github_commit_in_develop.md @@ -81,6 +81,8 @@ admin can do changes directly to develop branch | 9.0 | 30 | 30 | suspicious commit by $commit.commit.author.email$ to develop branch | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-01-github_dependabot_alert.md b/docs/_posts/2021-09-01-github_dependabot_alert.md index ff70459260..f4873d8edd 100644 --- a/docs/_posts/2021-09-01-github_dependabot_alert.md +++ b/docs/_posts/2021-09-01-github_dependabot_alert.md @@ -97,6 +97,8 @@ unknown | 27.0 | 30 | 90 | Vulnerabilities found in packages used by GitHub repository $repository$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md index bda5a57f46..5e4f9ed1fb 100644 --- a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md +++ b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md @@ -99,6 +99,8 @@ unknown | 27.0 | 30 | 90 | Vulnerabilities found in packages used by GitHub repository $repository$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md b/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md index 1e1b6078f7..5a2653dfe6 100644 --- a/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md +++ b/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md @@ -82,6 +82,8 @@ Administrators or power users may use Adsisearcher for troubleshooting. | 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md b/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md index 85f2ed6cf3..1c7ce46ed1 100644 --- a/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md +++ b/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md @@ -91,6 +91,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md b/docs/_posts/2021-09-02-circle_ci_disable_security_job.md index 3cd5f359d5..8917082d82 100644 --- a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md +++ b/docs/_posts/2021-09-02-circle_ci_disable_security_job.md @@ -92,6 +92,8 @@ unknown | 72.0 | 80 | 90 | disable security job $mandatory_job$ in workflow $workflow_name$ from user $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md b/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md index 6135d3ff85..52fe1267b0 100644 --- a/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md +++ b/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md @@ -92,6 +92,8 @@ Limited false positives as this requires an active Administrator or adversary to | 12.0 | 30 | 40 | Suspicious PowerShell Get-ForestTrust was identified on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md b/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md index 8798939929..84729f94c0 100644 --- a/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md +++ b/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md @@ -87,6 +87,8 @@ UPDATE_KNOWN_FALSE_POSITIVES | 12.0 | 30 | 40 | Suspicious PowerShell Get-ForestTrust was identified on endpoint $ComputerName$ by user $User$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md b/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md index a9165718c1..7ab2ec6a6d 100644 --- a/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md +++ b/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md @@ -82,6 +82,8 @@ Administrators or power users may use PowerView for troubleshooting. | 24.0 | 30 | 80 | Remote system discovery with PowerView on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md b/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md index 0d005a322b..12b721e8bb 100644 --- a/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md +++ b/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md @@ -82,6 +82,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 24.0 | 30 | 80 | Remote system discovery with PowerView on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md b/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md index ee252b0c51..ad7530a633 100644 --- a/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md +++ b/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md @@ -87,6 +87,8 @@ unknown | 35.0 | 50 | 70 | bcdedit process with commandline $process$ to bring back to normal boot configuration the $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md b/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md index b2da8e3ec8..1764a1ae59 100644 --- a/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md +++ b/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md @@ -87,6 +87,8 @@ unknown | 25.0 | 50 | 50 | bcdedit process with commandline $process$ to force safemode boot the $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md b/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md index 13d47cb2a5..6838aea9e7 100644 --- a/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md +++ b/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md @@ -84,6 +84,8 @@ unknown | 70.0 | 70 | 100 | Correlation triggered for user $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-06-correlation_by_user_and_risk.md b/docs/_posts/2021-09-06-correlation_by_user_and_risk.md index 771bb4ebde..aabf2dbbf9 100644 --- a/docs/_posts/2021-09-06-correlation_by_user_and_risk.md +++ b/docs/_posts/2021-09-06-correlation_by_user_and_risk.md @@ -84,6 +84,8 @@ unknown | 70.0 | 70 | 100 | Correlation triggered for user $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-07-getadcomputer_with_powershell.md b/docs/_posts/2021-09-07-getadcomputer_with_powershell.md index 7e27aff516..b33a1501d3 100644 --- a/docs/_posts/2021-09-07-getadcomputer_with_powershell.md +++ b/docs/_posts/2021-09-07-getadcomputer_with_powershell.md @@ -91,6 +91,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Remote system discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md b/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md index a32b2e7a26..49ba2384b0 100644 --- a/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md +++ b/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md @@ -91,6 +91,8 @@ Administrators or power users may use PowerView for troubleshooting. | 24.0 | 30 | 80 | Remote system discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md b/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md index 416331b3f4..42d6fc980d 100644 --- a/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md +++ b/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md @@ -91,6 +91,8 @@ Administrators or power users may use PowerView for troubleshooting. | 24.0 | 30 | 80 | Remote system discovery using PowerView on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md b/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md index 99cb172d6b..67e00af893 100644 --- a/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md +++ b/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md @@ -91,6 +91,8 @@ Administrators or power users may use this command for troubleshooting. | 21.0 | 30 | 70 | Remote system discovery enumeration using WMI on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md b/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md index 1f92babcdc..1772cb517c 100644 --- a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md +++ b/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md @@ -90,6 +90,8 @@ normal application like mmc.exe and other ldap query tool may trigger this detec | 25.0 | 50 | 50 | process $Image$ create a file $TargetFilename$ in host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-07-system_information_discovery_detection.md b/docs/_posts/2021-09-07-system_information_discovery_detection.md index 6a1bd255d9..a6c3b1e7d8 100644 --- a/docs/_posts/2021-09-07-system_information_discovery_detection.md +++ b/docs/_posts/2021-09-07-system_information_discovery_detection.md @@ -88,6 +88,8 @@ Administrators debugging servers | 15.0 | 30 | 50 | Potential system information discovery behavior on $dest$ by $User$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md b/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md index 67dfdc58bb..2ddd90b4d4 100644 --- a/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md +++ b/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md @@ -96,6 +96,8 @@ Limited false positives will be present as control.exe does not natively load fr | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md b/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md index 3002f491e0..8fd0c88530 100644 --- a/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md +++ b/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md @@ -96,6 +96,8 @@ Administrators often leverage net.exe to create admin accounts. | 30.0 | 50 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to add a user to the local Administrators group. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-08-office_spawning_control.md b/docs/_posts/2021-09-08-office_spawning_control.md index 6a511dbd24..ce86e6cfd2 100644 --- a/docs/_posts/2021-09-08-office_spawning_control.md +++ b/docs/_posts/2021-09-08-office_spawning_control.md @@ -97,6 +97,8 @@ Limited false positives should be present. | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ clicking a suspicious attachment. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md b/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md index ec16b24478..936ae7674c 100644 --- a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md +++ b/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md @@ -98,6 +98,8 @@ This is a hunting detection, meant to provide a understanding of how voluminous | 15.0 | 30 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md b/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md index 93be658e45..aa6861016c 100644 --- a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md +++ b/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md @@ -98,6 +98,8 @@ This may be tuned, or a new one related, by adding .cpl to command-line. However | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-09-09-extraction_of_registry_hives.md b/docs/_posts/2021-09-09-extraction_of_registry_hives.md index 7d4cc63a1a..5a973f0015 100644 --- a/docs/_posts/2021-09-09-extraction_of_registry_hives.md +++ b/docs/_posts/2021-09-09-extraction_of_registry_hives.md @@ -98,6 +98,8 @@ It is possible some agent based products will generate false positives. Filter a | 56.0 | 80 | 70 | Suspicious use of `reg.exe` exporting Windows Registry hives containing credentials executed on $dest$ by user $user$, with a parent process of $parent_process_id$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md b/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md index d30f437095..8a0c141d71 100644 --- a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md +++ b/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md @@ -92,6 +92,8 @@ Limited false positives will be present, however, tune as necessary. | 80.0 | 80 | 100 | An instance of $process_name$ was identified on endpoint $dest$ loading mshtml.dll. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md b/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md index f07d0277af..4a74b6b373 100644 --- a/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md +++ b/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md @@ -82,6 +82,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | Network Connection discovery on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md b/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md index 4b635f489b..e39985d88d 100644 --- a/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md +++ b/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md @@ -91,6 +91,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Network Connection discovery on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_net.md b/docs/_posts/2021-09-10-network_connection_discovery_with_net.md index 02d79dedbd..96dc60f099 100644 --- a/docs/_posts/2021-09-10-network_connection_discovery_with_net.md +++ b/docs/_posts/2021-09-10-network_connection_discovery_with_net.md @@ -91,6 +91,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Network Connection discovery on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md b/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md index bd0baab169..e624431581 100644 --- a/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md +++ b/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md @@ -91,6 +91,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Network Connection discovery on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md b/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md index 8ecb1f8709..46c8ff94eb 100644 --- a/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md +++ b/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md @@ -96,6 +96,8 @@ The query is structured in a way that `action` (read, create) is not defined. Re | 80.0 | 80 | 100 | An instance of $process_name$ was identified on $dest$ writing an inf or cab file to this. This is not typical of $process_name$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md b/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md index 59766fa456..5c823d0e81 100644 --- a/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md +++ b/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md @@ -92,6 +92,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | System user discovery on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md b/docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md index 758d4468e1..5012ebfff5 100644 --- a/docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md +++ b/docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md @@ -84,6 +84,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | System user discovery on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md b/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md index 16b0dd71bf..8cb5e199aa 100644 --- a/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md +++ b/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md @@ -93,6 +93,8 @@ unknown | 49.0 | 70 | 70 | Process name $process_name$ with commandline $process$ to execute jscript in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md index d2492ef8c7..be3f442364 100644 --- a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md +++ b/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md @@ -91,6 +91,8 @@ automation scripting language may used by network operator to do ldap query. | 9.0 | 30 | 30 | $process_name$ loading ldap modules $ImageLoaded$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md index 6d4db48668..1152dea23c 100644 --- a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md +++ b/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md @@ -91,6 +91,8 @@ automation scripting language may used by network operator to do ldap query. | 9.0 | 30 | 30 | $process_name$ loading wmi modules $ImageLoaded$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-13-office_application_drop_executable.md b/docs/_posts/2021-09-13-office_application_drop_executable.md index e3fa4b0c50..f24d709974 100644 --- a/docs/_posts/2021-09-13-office_application_drop_executable.md +++ b/docs/_posts/2021-09-13-office_application_drop_executable.md @@ -95,6 +95,8 @@ office macro for automation may do this behavior | 64.0 | 80 | 80 | process $process_name$ drops a file $TargetFilename$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-13-system_user_discovery_with_query.md b/docs/_posts/2021-09-13-system_user_discovery_with_query.md index 96b5696496..81323a5aae 100644 --- a/docs/_posts/2021-09-13-system_user_discovery_with_query.md +++ b/docs/_posts/2021-09-13-system_user_discovery_with_query.md @@ -92,6 +92,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | System user discovery on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md b/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md index 68eddc60c9..86e4c88f94 100644 --- a/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md +++ b/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md @@ -92,6 +92,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | System user discovery on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md index ea24003b1f..7910d1b0a7 100644 --- a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md +++ b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md @@ -92,6 +92,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | System user discovery on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md index f7ec2bd4c4..bf04a57381 100644 --- a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md +++ b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md @@ -84,6 +84,8 @@ Administrators or power users may use this PowerShell commandlet for troubleshoo | 15.0 | 30 | 50 | System user discovery on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md b/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md index fbed846186..b789752ec5 100644 --- a/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md +++ b/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md @@ -90,6 +90,8 @@ unknown | 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing wmic to load a XSL script. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md b/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md index 02641b1c44..156be47415 100644 --- a/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md +++ b/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md @@ -96,6 +96,8 @@ A network operator or systems administrator may utilize an automated host discov | 56.0 | 70 | 80 | A non-standard parent process $parent_process_name$ spawned child process $process_name$ to execute command-line tool on $dest$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md b/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md index 235a750595..9fceb935a2 100644 --- a/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md +++ b/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md @@ -96,6 +96,8 @@ False positives may be present. Tune as needed. | 15.0 | 30 | 50 | System group discovery on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md b/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md index f0c96898df..7087f2751c 100644 --- a/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md +++ b/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md @@ -89,6 +89,8 @@ False positives may be present. Tune as needed. | 15.0 | 30 | 50 | System group discovery enumeration on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-14-net_localgroup_discovery.md b/docs/_posts/2021-09-14-net_localgroup_discovery.md index 9e9a107b61..07f6a05b92 100644 --- a/docs/_posts/2021-09-14-net_localgroup_discovery.md +++ b/docs/_posts/2021-09-14-net_localgroup_discovery.md @@ -97,6 +97,8 @@ False positives may be present. Tune as needed. | 15.0 | 30 | 50 | Local group discovery on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md index 9b38d568ab..cdd0f07d15 100644 --- a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md +++ b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md @@ -96,6 +96,8 @@ False positives may be present. Tune as needed. | 15.0 | 30 | 50 | Local group discovery on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md index fe31bcdbd5..a80fcddcc9 100644 --- a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md +++ b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md @@ -89,6 +89,8 @@ False positives may be present. Tune as needed. | 15.0 | 30 | 50 | Local group discovery on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-14-wmic_group_discovery.md b/docs/_posts/2021-09-14-wmic_group_discovery.md index 30b06ee6b9..e2888cceb1 100644 --- a/docs/_posts/2021-09-14-wmic_group_discovery.md +++ b/docs/_posts/2021-09-14-wmic_group_discovery.md @@ -98,6 +98,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Local group discovery on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md b/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md index a635f0d9c4..929db9d421 100644 --- a/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md +++ b/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md @@ -88,6 +88,8 @@ unknown | 56.0 | 70 | 80 | Process name $process_name$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md b/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md index dbd889a9a4..e6c7b04f01 100644 --- a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md +++ b/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md @@ -94,6 +94,8 @@ other browser not listed related to firefox may catch by this rule. | 35.0 | 50 | 70 | a non firefox browser process $process_name$ accessing $Object_Name$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md b/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md index f4f126f606..74b0f6d6a9 100644 --- a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md +++ b/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md @@ -94,6 +94,8 @@ other browser not listed related to firefox may catch by this rule. | 35.0 | 50 | 70 | a non firefox browser process $process_name$ accessing $Object_Name$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-account_discovery_with_net_app.md b/docs/_posts/2021-09-16-account_discovery_with_net_app.md index 7a6234c0e6..46c6cd04fd 100644 --- a/docs/_posts/2021-09-16-account_discovery_with_net_app.md +++ b/docs/_posts/2021-09-16-account_discovery_with_net_app.md @@ -99,6 +99,8 @@ admin or power user may used this series of command. | 5.0 | 10 | 50 | Suspicious $process_name$ usage detected on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md b/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md index 2cf72cb01b..cf214b666e 100644 --- a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md +++ b/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md @@ -95,6 +95,8 @@ There may be legitimate reasons for administrators to add a certificate to the u | 35.0 | 70 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified attempting to add a certificate to the store on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md b/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md index 5e802077d3..a0a9c637f9 100644 --- a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md +++ b/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md @@ -99,6 +99,8 @@ None identified. | 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-batch_file_write_to_system32.md b/docs/_posts/2021-09-16-batch_file_write_to_system32.md index 8bf9262b91..bcb1906175 100644 --- a/docs/_posts/2021-09-16-batch_file_write_to_system32.md +++ b/docs/_posts/2021-09-16-batch_file_write_to_system32.md @@ -95,6 +95,8 @@ It is possible for this search to generate a notable event for a batch file writ | 63.0 | 70 | 90 | A file - $file_name$ was written to system32 has occurred on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-bits_job_persistence.md b/docs/_posts/2021-09-16-bits_job_persistence.md index d713f8f681..7135294f6f 100644 --- a/docs/_posts/2021-09-16-bits_job_persistence.md +++ b/docs/_posts/2021-09-16-bits_job_persistence.md @@ -94,6 +94,8 @@ Limited false positives will be present. Typically, applications will use `BitsA | 56.0 | 70 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to persist using BITS. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-bitsadmin_download_file.md b/docs/_posts/2021-09-16-bitsadmin_download_file.md index 7196219fbc..3685064373 100644 --- a/docs/_posts/2021-09-16-bitsadmin_download_file.md +++ b/docs/_posts/2021-09-16-bitsadmin_download_file.md @@ -100,6 +100,8 @@ Limited false positives, however it may be required to filter based on parent pr | 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download a file. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md index 6d4d072e22..27c066e6a1 100644 --- a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md +++ b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md @@ -98,6 +98,8 @@ Legtimate administrator usage of wmic to create a shadow copy. | 81.0 | 90 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to create a shadow copy to perform offline password cracking. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md index 974ee7205c..d4ee075672 100644 --- a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md +++ b/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md @@ -97,6 +97,8 @@ unknown | 81.0 | 90 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to copy SAM and NTDS.dit for offline password cracking. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md index abd91061a1..1d0943cd3d 100644 --- a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md +++ b/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md @@ -97,6 +97,8 @@ unknown | 81.0 | 90 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to create symlink to a shadow copy to grab credentials. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-detect_html_help_renamed.md b/docs/_posts/2021-09-16-detect_html_help_renamed.md index af28233868..6780747255 100644 --- a/docs/_posts/2021-09-16-detect_html_help_renamed.md +++ b/docs/_posts/2021-09-16-detect_html_help_renamed.md @@ -97,6 +97,8 @@ Although unlikely a renamed instance of hh.exe will be used legitimately, filter | 80.0 | 80 | 100 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md b/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md index ac090719d8..032d1a6a5a 100644 --- a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md +++ b/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md @@ -97,6 +97,8 @@ Although unlikely, some legitimate applications may retrieve a CHM remotely, fil | 90.0 | 90 | 100 | An instance of $parent_proces_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ contacting a remote destination to potentally download a malicious payload. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md b/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md index a6f85b6f82..91f1717859 100644 --- a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md +++ b/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md @@ -97,6 +97,8 @@ It is rare to see instances of InfoTech Storage Handlers being used, but it does | 72.0 | 80 | 90 | $process_name$ has been identified using Infotech Storage Handlers to load a specific file within a CHM on $dest$ under user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md b/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md index 708d1b49e6..56bc87a09f 100644 --- a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md +++ b/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md @@ -97,6 +97,8 @@ Although unlikely, some legitimate applications may exhibit this behavior, trigg | 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ executing with inline HTA, indicative of defense evasion. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-detect_mshta_renamed.md b/docs/_posts/2021-09-16-detect_mshta_renamed.md index b196f3b186..ca21ca2717 100644 --- a/docs/_posts/2021-09-16-detect_mshta_renamed.md +++ b/docs/_posts/2021-09-16-detect_mshta_renamed.md @@ -97,6 +97,8 @@ Although unlikely, some legitimate applications may use a moved copy of mshta.ex | 80.0 | 80 | 100 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md b/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md index 29dd4b45c9..f5657de256 100644 --- a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md +++ b/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md @@ -97,6 +97,8 @@ It is possible legitimate applications may perform this behavior and will need t | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $est$ by user $user$ attempting to access a remote destination to download an additional payload. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md index 83b13b29d7..5cc45bb15d 100644 --- a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md +++ b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md @@ -101,6 +101,8 @@ Administrators can leverage PsExec for accessing remote systems and might pass ` | 35.0 | 50 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ running the utility for possibly the first time. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-detect_renamed_7-zip.md b/docs/_posts/2021-09-16-detect_renamed_7-zip.md index 7b44ca80d6..a5e08f0284 100644 --- a/docs/_posts/2021-09-16-detect_renamed_7-zip.md +++ b/docs/_posts/2021-09-16-detect_renamed_7-zip.md @@ -96,6 +96,8 @@ Limited false positives, however this analytic will need to be modified for each | 27.0 | 30 | 90 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-detect_renamed_psexec.md b/docs/_posts/2021-09-16-detect_renamed_psexec.md index 459161b747..63bad21aa7 100644 --- a/docs/_posts/2021-09-16-detect_renamed_psexec.md +++ b/docs/_posts/2021-09-16-detect_renamed_psexec.md @@ -103,6 +103,8 @@ Limited false positives should be present. It is possible some third party appli | 27.0 | 30 | 90 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-detect_renamed_rclone.md b/docs/_posts/2021-09-16-detect_renamed_rclone.md index d8e7711bd8..f5a43ff807 100644 --- a/docs/_posts/2021-09-16-detect_renamed_rclone.md +++ b/docs/_posts/2021-09-16-detect_renamed_rclone.md @@ -92,6 +92,8 @@ False positives should be limited as this analytic identifies renamed instances | 27.0 | 30 | 90 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-detect_renamed_winrar.md b/docs/_posts/2021-09-16-detect_renamed_winrar.md index baddec447a..e68b64db45 100644 --- a/docs/_posts/2021-09-16-detect_renamed_winrar.md +++ b/docs/_posts/2021-09-16-detect_renamed_winrar.md @@ -97,6 +97,8 @@ Unknown. It is possible third party applications use renamed instances of WinRAR | 27.0 | 30 | 90 | The following $process_name$ has been identified as renamed, spawning from $parent_process_name$ on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md b/docs/_posts/2021-09-16-dump_lsass_via_procdump.md index 6017caa1db..201ef1a9bc 100644 --- a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md +++ b/docs/_posts/2021-09-16-dump_lsass_via_procdump.md @@ -95,6 +95,8 @@ None identified. | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified attempting to dump lsass.exe on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-local_account_discovery_with_net.md b/docs/_posts/2021-09-16-local_account_discovery_with_net.md index bbe06b79de..b89fd78d8d 100644 --- a/docs/_posts/2021-09-16-local_account_discovery_with_net.md +++ b/docs/_posts/2021-09-16-local_account_discovery_with_net.md @@ -86,6 +86,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Local user discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md b/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md index c3318139ce..1d3ecad1dc 100644 --- a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md +++ b/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md @@ -86,6 +86,8 @@ Administrators or power users may use this command for troubleshooting. | 15.0 | 30 | 50 | Local user discovery enumeration on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-office_product_spawning_wmic.md b/docs/_posts/2021-09-16-office_product_spawning_wmic.md index 306a102f5b..39a7aa31a7 100644 --- a/docs/_posts/2021-09-16-office_product_spawning_wmic.md +++ b/docs/_posts/2021-09-16-office_product_spawning_wmic.md @@ -98,6 +98,8 @@ No false positives known. Filter as needed. | 63.0 | 70 | 90 | office parent process $parent_process_name$ will execute a suspicious child process $process_name$ with process id $process_id$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-16-processes_launching_netsh.md b/docs/_posts/2021-09-16-processes_launching_netsh.md index 5199390a43..3c2739d0fa 100644 --- a/docs/_posts/2021-09-16-processes_launching_netsh.md +++ b/docs/_posts/2021-09-16-processes_launching_netsh.md @@ -94,6 +94,8 @@ Some VPN applications are known to launch netsh.exe. Outside of these instances, | 42.0 | 60 | 70 | A process $process_name$ that tries to execute netsh commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md b/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md index a042c83e58..bff121d182 100644 --- a/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md @@ -98,6 +98,8 @@ Although unlikely, limited instances of regasm.exe or may cause a false positive | 49.0 | 70 | 70 | The process $process_name$ was spawned by $parent_process_name$ without any command-line arguments on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md b/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md index 4e02e40beb..4b784ba308 100644 --- a/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md @@ -98,6 +98,8 @@ Although unlikely, limited instances of regsvcs.exe may cause a false positive. | 49.0 | 70 | 70 | The process $process_name$ was spawned by $parent_process_name$ without any command-line arguments on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md b/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md index f40280c609..4b3403845e 100644 --- a/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md +++ b/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md @@ -96,6 +96,8 @@ Default browser not in the filter list. | 35.0 | 70 | 50 | Office document spawning suspicious child process on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md index e81b9d9387..252aad0b97 100644 --- a/docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md @@ -95,6 +95,8 @@ Limited false positives may be present in small environments. Tuning may be requ | 49.0 | 70 | 70 | Suspicious dllhost.exe process with no command line arguments executed on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md index 714d739582..60a84f8763 100644 --- a/docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md @@ -95,6 +95,8 @@ Limited false positives may be present in small environments. Tuning may be requ | 49.0 | 70 | 70 | Suspicious gpupdate.exe process with no command line arguments executed on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md b/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md index 7c754b0624..049ac746c1 100644 --- a/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md +++ b/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md @@ -103,6 +103,8 @@ Although unlikely, some legitimate applications may use a moved copy of microsof | 63.0 | 70 | 90 | Suspicious renamed microsoft.workflow.compiler.exe binary ran on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md index a0e27de3a3..e461aa4f88 100644 --- a/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md @@ -101,6 +101,8 @@ Although unlikely, some legitimate applications may use a moved copy of rundll32 | 49.0 | 70 | 70 | Suspicious rundll32.exe process with no command line arguments executed on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md index 8a65c5fdc7..f377cfe138 100644 --- a/docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md @@ -94,6 +94,8 @@ Limited false positives may be present in small environments. Tuning may be requ | 49.0 | 70 | 70 | Suspicious searchprotocolhost.exe process with no command line arguments executed on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md b/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md index 9a2ac51a22..d1614dd2d9 100644 --- a/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md +++ b/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md @@ -85,6 +85,8 @@ unknown | 100.0 | 100 | 100 | file $file_name$ created in $file_path$ of $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md b/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md index 53336ad314..4983339cc4 100644 --- a/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md +++ b/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md @@ -89,6 +89,8 @@ unknown | 49.0 | 70 | 70 | process $process_name$ creating image file $file_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md b/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md index 6b346c1cf3..fffb354cff 100644 --- a/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md +++ b/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md @@ -89,6 +89,8 @@ unknown | 49.0 | 70 | 70 | process $process_name$ creating image file $file_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-27-change_default_file_association.md b/docs/_posts/2021-09-27-change_default_file_association.md index 865c16553e..2d79910ed4 100644 --- a/docs/_posts/2021-09-27-change_default_file_association.md +++ b/docs/_posts/2021-09-27-change_default_file_association.md @@ -93,6 +93,8 @@ unknown | 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md b/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md index 08205164ff..e36a0295a0 100644 --- a/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md +++ b/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md @@ -93,6 +93,8 @@ unknown | 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md b/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md index e7fd1fc309..85153ef7c7 100644 --- a/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md +++ b/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md @@ -93,6 +93,8 @@ unknown | 72.0 | 80 | 90 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-28-print_processor_registry_autostart.md b/docs/_posts/2021-09-28-print_processor_registry_autostart.md index acb99d13c2..113f41dc00 100644 --- a/docs/_posts/2021-09-28-print_processor_registry_autostart.md +++ b/docs/_posts/2021-09-28-print_processor_registry_autostart.md @@ -95,6 +95,8 @@ possible new printer installation may add driver component on this registry. | 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-09-29-verclsid_clsid_execution.md b/docs/_posts/2021-09-29-verclsid_clsid_execution.md index 72d73f496f..5189626b50 100644 --- a/docs/_posts/2021-09-29-verclsid_clsid_execution.md +++ b/docs/_posts/2021-09-29-verclsid_clsid_execution.md @@ -97,6 +97,8 @@ windows can used this application for its normal COM object validation. | 25.0 | 50 | 50 | process $process_name$ to execute possible clsid commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md b/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md index 74931701d5..aab7338b44 100644 --- a/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md +++ b/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md @@ -97,6 +97,8 @@ unknown | 49.0 | 70 | 70 | Process name $process_name$ with commandline $process$ to execute vbsscript | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md b/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md index 7be85976e7..49f30f28c2 100644 --- a/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md +++ b/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md @@ -92,6 +92,8 @@ False positives should be limited as developers do not spawn MSBuild via a WSH. | 49.0 | 70 | 70 | Msbuild.exe process spawned by $parent_process_name$ on $dest$ executed by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md b/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md index 625222ba92..b531bb1dd1 100644 --- a/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md +++ b/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md @@ -100,6 +100,8 @@ Other third part application may used this parameter but not so common in base w | 36.0 | 60 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a DLL using the silent and dllinstall parameter. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-05-detect_exchange_web_shell.md b/docs/_posts/2021-10-05-detect_exchange_web_shell.md index 705f8bbeba..1f100eed7b 100644 --- a/docs/_posts/2021-10-05-detect_exchange_web_shell.md +++ b/docs/_posts/2021-10-05-detect_exchange_web_shell.md @@ -98,6 +98,8 @@ The query is structured in a way that `action` (read, create) is not defined. Re | 81.0 | 90 | 90 | A file - $file_name$ was written to disk that is related to IIS exploitation previously performed by HAFNIUM. Review further file modifications on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md b/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md index 626f555131..1c63814662 100644 --- a/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md +++ b/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md @@ -97,6 +97,8 @@ False positives should be limited, filter as needed. In our test case, Remcos us | 80.0 | 80 | 100 | The $process_name$ was identified on endpoint $dest$ modifying the registry with a known malicious clsid under InProcServer32. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md b/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md index b4961b4bf4..5527bafa73 100644 --- a/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md +++ b/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md @@ -96,6 +96,8 @@ False positives should be limited, however it is possible to filter by Processes | 80.0 | 80 | 100 | An instance of $process_name$ was identified on endpoint $dest$ downloading the DynamicWrapperX dll. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-05-rundll32_shimcache_flush.md b/docs/_posts/2021-10-05-rundll32_shimcache_flush.md index 17e8040214..abd2b246b9 100644 --- a/docs/_posts/2021-10-05-rundll32_shimcache_flush.md +++ b/docs/_posts/2021-10-05-rundll32_shimcache_flush.md @@ -93,6 +93,8 @@ unknown | 80.0 | 80 | 100 | rundll32 process execute $process$ to clear shim cache in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-05-suspicious_copy_on_system32.md b/docs/_posts/2021-10-05-suspicious_copy_on_system32.md index 53eb4d47e9..b31f4a0d39 100644 --- a/docs/_posts/2021-10-05-suspicious_copy_on_system32.md +++ b/docs/_posts/2021-10-05-suspicious_copy_on_system32.md @@ -97,6 +97,8 @@ every user may do this event but very un-ussual. | 63.0 | 70 | 90 | execution of copy exe to copy file from $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md b/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md index 8757d560f1..60bd4906c3 100644 --- a/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md +++ b/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md @@ -93,6 +93,8 @@ False positives should be limited as winhlp32.exe is typically not used with the | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$, and is not typical activity for this process. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md b/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md index 7a7f8a0542..351b227f6e 100644 --- a/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md +++ b/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md @@ -94,6 +94,8 @@ It's possible there can be long domain names that are legitimate. | 56.0 | 70 | 80 | A dns query $query$ with 2 time standard deviation of name len of the dns query in host $host$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-06-sdelete_application_execution.md b/docs/_posts/2021-10-06-sdelete_application_execution.md index 17dd343fb6..e678dfbd8e 100644 --- a/docs/_posts/2021-10-06-sdelete_application_execution.md +++ b/docs/_posts/2021-10-06-sdelete_application_execution.md @@ -101,6 +101,8 @@ user may execute and use this application | 49.0 | 70 | 70 | sdelete process $process_name$ executed in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md b/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md index fe2da0e523..bce5c13dd7 100644 --- a/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md +++ b/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md @@ -111,6 +111,8 @@ Administrators may create vbs or js script that use several tool as part of its | 49.0 | 70 | 70 | wscript or cscript parent process spawned $process_name$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md b/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md index eb1472ba59..1e90eb39bc 100644 --- a/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md +++ b/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md @@ -92,6 +92,8 @@ The wevtutil.exe application is a legitimate Windows event log utility. Administ | 28.0 | 40 | 70 | Wevtutil.exe being used to clear Event Logs on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md index ea6306a6ba..151e446b54 100644 --- a/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md +++ b/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md @@ -94,6 +94,8 @@ Although unlikely, some legitimate third party applications may use a moved copy | 49.0 | 70 | 70 | The process $process_name$ was spawned by $parent_image$ without any command-line arguments on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md index fb7c32d9f0..bd535dd110 100644 --- a/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md +++ b/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md @@ -106,6 +106,8 @@ Although unlikely, some legitimate applications may use a moved copy of rundll32 | 70.0 | 70 | 100 | A rundll32 process $process_name$ with no commandline argument like this process commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md b/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md index b5725c00b2..6f58db7fae 100644 --- a/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md +++ b/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md @@ -93,6 +93,8 @@ Limited false positives may be present in small environments. Tuning may be requ | 70.0 | 70 | 100 | A searchprotocolhost.exe process $process_name$ with no commandline in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md index b8057ac435..26fe0825ec 100644 --- a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md +++ b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md @@ -94,6 +94,8 @@ False positives should be limited, however filter as needed. | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to identify service principle names. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md index 9ecf2cfc66..511b4ad2ad 100644 --- a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md +++ b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md @@ -100,6 +100,8 @@ False positives may be caused by Administrators resetting SPNs or querying for S | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to identify service principle names. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-18-disable_schedule_task.md b/docs/_posts/2021-10-18-disable_schedule_task.md index 0db45ce047..c8d10ab8f4 100644 --- a/docs/_posts/2021-10-18-disable_schedule_task.md +++ b/docs/_posts/2021-10-18-disable_schedule_task.md @@ -89,6 +89,8 @@ admin may disable problematic schedule task | 56.0 | 70 | 80 | schtask process with commandline $process$ to disable schedule task in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md b/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md index 507cb31584..e9f38bd9df 100644 --- a/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md +++ b/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md @@ -96,6 +96,8 @@ It is possible Administrators or super users will use Curl for legitimate purpos | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ to download a file to a suspicious directory. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md b/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md index 2dece601df..ecab753146 100644 --- a/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md +++ b/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md @@ -89,6 +89,8 @@ False positives will be present. Filter based on ActionName paths or specify key | 80.0 | 80 | 100 | A Scheduled Task was scheduled and ran on $dest$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md b/docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md index 5e9045c2be..7f855e15a7 100644 --- a/docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md +++ b/docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md @@ -96,6 +96,8 @@ third party application may use this approach to uninstall there application | 25.0 | 50 | 50 | wmic $process$ with commandline $process$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md index 016c224585..4ee95eed34 100644 --- a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md +++ b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md @@ -81,6 +81,8 @@ This is an anomaly search, you must specify your domain in the parameters so it +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md index 2496d39e26..ca23020502 100644 --- a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md +++ b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md @@ -80,6 +80,8 @@ This search will also produce normal activity statistics. Fields such as email, +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-03-windows_adfind_exe.md b/docs/_posts/2021-11-03-windows_adfind_exe.md index 4ed539d0fd..eb973df8e2 100644 --- a/docs/_posts/2021-11-03-windows_adfind_exe.md +++ b/docs/_posts/2021-11-03-windows_adfind_exe.md @@ -83,6 +83,8 @@ administrators rarely use adfind, usually not used for legitimate reasons +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-04-attacker_tools_on_endpoint.md b/docs/_posts/2021-11-04-attacker_tools_on_endpoint.md index 7b59d413ea..d2701ad3d8 100644 --- a/docs/_posts/2021-11-04-attacker_tools_on_endpoint.md +++ b/docs/_posts/2021-11-04-attacker_tools_on_endpoint.md @@ -108,6 +108,8 @@ Some administrator activity can be potentially triggered, please add those users | 64.0 | 80 | 80 | An attacker tool $process_name$,listed in attacker_tools.csv is executed on host $dest$ by User $user$. This process $process_name$ is known to do- $description$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md b/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md index ad83a31865..4fdff5f2e4 100644 --- a/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md +++ b/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md @@ -98,6 +98,8 @@ Environments in which NTLM is used extremely rarely and for benign purposes (suc | 64.0 | 80 | 80 | Potential lateral movement and credential stealing via Pass the Token or Pass the Hash techniques. Operation is performed via credentials of the account $dest_user_id$ and observed by the logging device $origin_device_id$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md b/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md index c14550658c..a8c7241b23 100644 --- a/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md +++ b/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md @@ -97,6 +97,8 @@ False positives may be limited to source control applications and may be require | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ uploading a file to a remote destination. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md b/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md index 20e6085c62..49a3198ad0 100644 --- a/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md +++ b/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md @@ -98,6 +98,8 @@ Administrators may create Windows Services on remote systems, but this activity | 54.0 | 90 | 60 | A Windows Service was created on a remote endpoint from $dest | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md b/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md index 77f9fb15fa..d08314ddc3 100644 --- a/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md +++ b/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md @@ -98,6 +98,8 @@ Administrators may start Windows Services on remote systems, but this activity i | 54.0 | 90 | 60 | A Windows Service was started on a remote endpoint from $dest | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md b/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md index 965702e860..866953c7a2 100644 --- a/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md +++ b/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md @@ -96,6 +96,8 @@ Administrators may leverage WinRM and WinRs to start a process on remote systems | 54.0 | 90 | 60 | A process was started on a remote endpoint from $dest | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md b/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md index 6d651c9df5..2545c8637e 100644 --- a/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md +++ b/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md @@ -100,6 +100,8 @@ Administrators may create scheduled tasks on remote systems, but this activity i | 54.0 | 90 | 60 | A Windows Scheduled Task was created on a remote endpoint from $dest | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md b/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md index c934491637..76ab38b644 100644 --- a/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md +++ b/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md @@ -100,6 +100,8 @@ Administrators may start scheduled tasks on remote systems, but this activity is | 54.0 | 90 | 60 | A Windows Scheduled Task was ran on a remote endpoint from $dest | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md b/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md index f8ec11c32f..90d87dfbf8 100644 --- a/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md +++ b/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md @@ -95,6 +95,8 @@ Administrators may create scheduled tasks on remote systems, but this activity i | 63.0 | 70 | 90 | A schedule task process $process_name$ with remote job commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md b/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md index 5b31526a77..6da0616322 100644 --- a/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md +++ b/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md @@ -93,6 +93,8 @@ False positives are limited as legitimate applications typically do not download | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing wmic to download a remote XSL script. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md b/docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md index b6d405718a..b476e21d55 100644 --- a/docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md +++ b/docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md @@ -87,6 +87,8 @@ It is possible to start this detection will need to be tuned by source IP or use | 10.0 | 20 | 50 | User $userIdentity.arn$ is seen to perform excessive number of discovery related api calls- $failures$, within an hour where the access was denied. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md b/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md index d9e21dab7d..5b91cf651a 100644 --- a/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md +++ b/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md @@ -94,6 +94,8 @@ A network operator or systems administrator may utilize an automated powershell | 25.0 | 50 | 50 | csc.exe with commandline $process$ to compile .net code on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-12-firewall_allowed_program_enable.md b/docs/_posts/2021-11-12-firewall_allowed_program_enable.md index acc93ec128..f667a632f5 100644 --- a/docs/_posts/2021-11-12-firewall_allowed_program_enable.md +++ b/docs/_posts/2021-11-12-firewall_allowed_program_enable.md @@ -93,6 +93,8 @@ A network operator or systems administrator may utilize an automated or manual e | 25.0 | 50 | 50 | firewall allowed program commandline $process$ of $process_name$ on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md b/docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md index 14ea7c8552..a08514361f 100644 --- a/docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md +++ b/docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md @@ -94,6 +94,8 @@ A network operator or systems administrator may utilize an automated host discov | 9.0 | 30 | 30 | Network Connection discovery on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md b/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md index e52dfcd403..ea338a9ceb 100644 --- a/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md +++ b/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md @@ -95,6 +95,8 @@ The wmic.exe utility is a benign Windows application. It may be used legitimatel | 49.0 | 70 | 70 | A wmic.exe process $process$ contain process spawn commandline $process$ in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-12-runas_execution_in_commandline.md b/docs/_posts/2021-11-12-runas_execution_in_commandline.md index 8f685e0347..81a5081983 100644 --- a/docs/_posts/2021-11-12-runas_execution_in_commandline.md +++ b/docs/_posts/2021-11-12-runas_execution_in_commandline.md @@ -96,6 +96,8 @@ A network operator or systems administrator may utilize an automated or manual e | 25.0 | 50 | 50 | elevated process using runas on $dest$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-12-windows_installutil_credential_theft.md b/docs/_posts/2021-11-12-windows_installutil_credential_theft.md index cc3097ca71..3d3f8e7732 100644 --- a/docs/_posts/2021-11-12-windows_installutil_credential_theft.md +++ b/docs/_posts/2021-11-12-windows_installutil_credential_theft.md @@ -100,6 +100,8 @@ Typically this will not trigger as by it's very nature InstallUtil does not | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ loading samlib.dll and vaultcli.dll to potentially capture credentials in memory. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-12-windows_installutil_remote_network_connection.md b/docs/_posts/2021-11-12-windows_installutil_remote_network_connection.md index b2d5eead94..37e1e7a87b 100644 --- a/docs/_posts/2021-11-12-windows_installutil_remote_network_connection.md +++ b/docs/_posts/2021-11-12-windows_installutil_remote_network_connection.md @@ -109,6 +109,8 @@ Limited false positives should be present as InstallUtil is not typically used t | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ generating a remote download. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-12-windows_installutil_uninstall_option.md b/docs/_posts/2021-11-12-windows_installutil_uninstall_option.md index a5303ed25a..83b51bc752 100644 --- a/docs/_posts/2021-11-12-windows_installutil_uninstall_option.md +++ b/docs/_posts/2021-11-12-windows_installutil_uninstall_option.md @@ -102,6 +102,8 @@ Limited false positives should be present. Filter as needed by parent process or | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ performing an uninstall. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-12-windows_installutil_uninstall_option_with_network.md b/docs/_posts/2021-11-12-windows_installutil_uninstall_option_with_network.md index c7c35b0345..8ea6579420 100644 --- a/docs/_posts/2021-11-12-windows_installutil_uninstall_option_with_network.md +++ b/docs/_posts/2021-11-12-windows_installutil_uninstall_option_with_network.md @@ -110,6 +110,8 @@ Limited false positives should be present as InstallUtil is not typically used t | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ performing an uninstall. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md b/docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md index acd2e14fc3..b9ee2a0617 100644 --- a/docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md +++ b/docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md @@ -101,6 +101,8 @@ Limited false positives should be present as InstallUtil is not typically used t | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ passing a URL on the command-line. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md index 1d7efb8ccc..da83592d5c 100644 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md +++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md @@ -97,6 +97,8 @@ Administrators may leverage DCOM to start a process on remote systems, but this | 63.0 | 90 | 70 | A process was started on a remote endpoint from $dest by abusing DCOM using PowerShell.exe | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md index 31c362d421..2f8b64f447 100644 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md +++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md @@ -86,6 +86,8 @@ Administrators may leverage DCOM to start a process on remote systems, but this | 63.0 | 90 | 70 | A process was started on a remote endpoint from $ComputerName by abusing WMI using PowerShell.exe | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md index 650a366015..bdae3d1008 100644 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md +++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md @@ -93,6 +93,8 @@ Administrators may leverage WWMI and powershell.exe to start a process on remote | 63.0 | 90 | 70 | A process was started on a remote endpoint from $dest by abusing WMI using PowerShell.exe | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md index 49dd9cba40..6ccf682a67 100644 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md +++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md @@ -82,6 +82,8 @@ Administrators may leverage WWMI and powershell.exe to start a process on remote | 63.0 | 90 | 70 | A process was started on a remote endpoint from $ComputerName by abusing WMI using PowerShell.exe | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-15-sdelete_application_execution.md b/docs/_posts/2021-11-15-sdelete_application_execution.md index 3f17310abb..982e127ff0 100644 --- a/docs/_posts/2021-11-15-sdelete_application_execution.md +++ b/docs/_posts/2021-11-15-sdelete_application_execution.md @@ -94,6 +94,8 @@ False positives should be limited, filter as needed. | 42.0 | 60 | 70 | Sdelete process $process_name$ executed on $dest_device_id$ attempting to permanently delete files by $dest_user_id$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-15-windows_diskcryptor_usage.md b/docs/_posts/2021-11-15-windows_diskcryptor_usage.md index e45248901a..f0af880755 100644 --- a/docs/_posts/2021-11-15-windows_diskcryptor_usage.md +++ b/docs/_posts/2021-11-15-windows_diskcryptor_usage.md @@ -92,6 +92,8 @@ It is possible false positives may be present based on the internal name dcinst. | 35.0 | 70 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to encrypt disks. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md b/docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md index 41ed212657..2ea20b8fdd 100644 --- a/docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md +++ b/docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md @@ -90,6 +90,8 @@ this behavior may seen in normal transfer of file within network if network shar | 9.0 | 30 | 30 | high frequency copy of document in network share $Share_Name$ from $Source_Address$ by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md index af40fbb3a6..49d8188e00 100644 --- a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md +++ b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md @@ -97,6 +97,8 @@ Administrators may leverage WinRM and `Invoke-Command` to start a process on rem | 45.0 | 90 | 50 | A process was started on a remote endpoint from $dest by abusing WinRM using PowerShell.exe | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md index 1bcf227830..152434d386 100644 --- a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md +++ b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md @@ -86,6 +86,8 @@ Administrators may leverage WinRM and `Invoke-Command` to start a process on rem | 45.0 | 90 | 50 | A process was started on a remote endpoint from $ComputerName by abusing WinRM using PowerShell.exe | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-17-windows_dism_remove_defender.md b/docs/_posts/2021-11-17-windows_dism_remove_defender.md index 8e77df5f17..122bab8808 100644 --- a/docs/_posts/2021-11-17-windows_dism_remove_defender.md +++ b/docs/_posts/2021-11-17-windows_dism_remove_defender.md @@ -96,6 +96,8 @@ Some legitimate administrative tools leverage `dism.exe` to manipulate packages | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to disable Windows Defender. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md b/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md index b605ebb24c..431042e1cb 100644 --- a/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md +++ b/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md @@ -92,6 +92,8 @@ System Administrators may use looks like PsExec for troubleshooting or administr | 70.0 | 70 | 100 | $user$ dropped or created an executable file in known sensitive SMB share. Share name=$Share_Name$, Target name=$Relative_Target_Name$, and Access mask=$Access_Mask$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-18-interactive_session_on_remote_endpoint_with_powershell.md b/docs/_posts/2021-11-18-interactive_session_on_remote_endpoint_with_powershell.md index ad920c5640..5e6a7e2015 100644 --- a/docs/_posts/2021-11-18-interactive_session_on_remote_endpoint_with_powershell.md +++ b/docs/_posts/2021-11-18-interactive_session_on_remote_endpoint_with_powershell.md @@ -85,6 +85,8 @@ Administrators may leverage WinRM and `Enter-PSSession` for administrative and t | 45.0 | 90 | 50 | An interactive session was opened on a remote endpoint from $ComputerName | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md b/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md index ee29a20b83..5950c87e09 100644 --- a/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md +++ b/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md @@ -95,6 +95,8 @@ False positives should be limited, however it is possible to filter by Processes | 80.0 | 80 | 100 | dynwrapx.dll loaded by process $process_name$ on $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md b/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md index 490823f2f9..a7bf39af25 100644 --- a/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md +++ b/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md @@ -93,6 +93,8 @@ This commandline can be used by a network administrator to audit host machine sp | 25.0 | 50 | 50 | dxdiag.exe process with commandline $process$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-22-anomalous_usage_of_archive_tools.md b/docs/_posts/2021-11-22-anomalous_usage_of_archive_tools.md index 19f5b47965..4a75f7bfb1 100644 --- a/docs/_posts/2021-11-22-anomalous_usage_of_archive_tools.md +++ b/docs/_posts/2021-11-22-anomalous_usage_of_archive_tools.md @@ -90,6 +90,8 @@ False positives can be ligitmate usage of archive tools from the command line. | 42.0 | 70 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading of 7zip. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md b/docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md index 1c0e8720c5..2deb1507be 100644 --- a/docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md +++ b/docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md @@ -96,6 +96,8 @@ False positive is quite limited. Filter is needed | 16.0 | 40 | 40 | suspicious process $process_name$ contains commandline $process$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md index f9bbabd63d..0a307098e4 100644 --- a/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md +++ b/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md @@ -98,6 +98,8 @@ Legitimate applications may trigger this behavior, filter as needed. | 54.0 | 90 | 60 | Services.exe spawned a LOLBAS process on $dest | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md index 82c11e57f5..cee8423a0b 100644 --- a/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md +++ b/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md @@ -100,6 +100,8 @@ Legitimate applications may trigger this behavior, filter as needed. | 54.0 | 90 | 60 | Svchost.exe spawned a LOLBAS process on $dest | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md b/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md index 2634f0736c..6b37ce8b37 100644 --- a/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md +++ b/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md @@ -90,6 +90,8 @@ Legitimate applications may install services with uncommon services paths. | 56.0 | 70 | 80 | A service $Service_File_Name$ was created from a non-standard path using $Service_Name$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-22-windows_service_created_within_public_path.md b/docs/_posts/2021-11-22-windows_service_created_within_public_path.md index f62d5b2e57..33ee0b285d 100644 --- a/docs/_posts/2021-11-22-windows_service_created_within_public_path.md +++ b/docs/_posts/2021-11-22-windows_service_created_within_public_path.md @@ -90,6 +90,8 @@ Legitimate applications may install services with uncommon services paths. | 54.0 | 90 | 60 | A Windows Service $Service_File_Name$ with a public path was created on $ComputerName | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md index 0efbc2f49d..ea6a345e33 100644 --- a/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md +++ b/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md @@ -92,6 +92,8 @@ Legitimate applications may trigger this behavior, filter as needed. | 54.0 | 90 | 60 | Wmiprsve.exe spawned a LOLBAS process on $dest$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md index b0ebd18967..e3ccecabdc 100644 --- a/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md +++ b/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md @@ -96,6 +96,8 @@ Legitimate applications may trigger this behavior, filter as needed. | 54.0 | 90 | 60 | Wsmprovhost.exe spawned a LOLBAS process on $dest$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md index 6440895765..96f8975616 100644 --- a/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md +++ b/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md @@ -96,6 +96,8 @@ Legitimate applications may trigger this behavior, filter as needed. | 54.0 | 90 | 60 | Mmc.exe spawned a LOLBAS process on $dest | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-24-attempt_to_delete_services.md b/docs/_posts/2021-11-24-attempt_to_delete_services.md index 9302887f2d..20ebd11f9a 100644 --- a/docs/_posts/2021-11-24-attempt_to_delete_services.md +++ b/docs/_posts/2021-11-24-attempt_to_delete_services.md @@ -95,6 +95,8 @@ It is possible administrative scripts may start/stop/delete services. Filter as | 36.0 | 60 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-24-attempt_to_disable_services.md b/docs/_posts/2021-11-24-attempt_to_disable_services.md index fad2f00ae8..273b5a26d8 100644 --- a/docs/_posts/2021-11-24-attempt_to_disable_services.md +++ b/docs/_posts/2021-11-24-attempt_to_disable_services.md @@ -85,6 +85,8 @@ It is possible administrative scripts may start/stop/delete services. Filter as | 36.0 | 60 | 60 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md b/docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md index 265396e9d5..e7e3cedb19 100644 --- a/docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md +++ b/docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md @@ -98,6 +98,8 @@ Admin or user may choose to use this windows features. Filter as needed. | 64.0 | 80 | 80 | exclusion command $process$ executed on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md b/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md index 969349fd4d..dd39a2490b 100644 --- a/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md +++ b/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md @@ -90,6 +90,8 @@ admin or user may choose to use this windows features. | 64.0 | 80 | 80 | exclusion command $Message$ executed on $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md b/docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md index 516edaa1f9..0ff7add633 100644 --- a/docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md +++ b/docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md @@ -96,6 +96,8 @@ admin or user may choose to use this windows features. | 64.0 | 80 | 80 | exclusion registry $registry_path$ modified or added on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md b/docs/_posts/2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md index 9b79654157..7f140e4ff3 100644 --- a/docs/_posts/2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md +++ b/docs/_posts/2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md @@ -88,6 +88,8 @@ None identified. | 63.0 | 70 | 90 | An attempt to save registry keys storing credentials has been performed on $dest_device_id$ by $dest_user_id$ via process $process_name$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-29-deny_permission_using_cacls_utility.md b/docs/_posts/2021-11-29-deny_permission_using_cacls_utility.md index 457cc07576..aad5d24494 100644 --- a/docs/_posts/2021-11-29-deny_permission_using_cacls_utility.md +++ b/docs/_posts/2021-11-29-deny_permission_using_cacls_utility.md @@ -84,6 +84,8 @@ System administrators may use cacls utilities but this is not a common practice. | 35.0 | 50 | 70 | A cacls process $process_name$ with commandline $cmd_line$ try to deny a permission of a file or directory in host $dest_device_id$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-29-detect_dump_lsass_memory_using_comsvcs.md b/docs/_posts/2021-11-29-detect_dump_lsass_memory_using_comsvcs.md index 5baebdaf4d..6887c2bd67 100644 --- a/docs/_posts/2021-11-29-detect_dump_lsass_memory_using_comsvcs.md +++ b/docs/_posts/2021-11-29-detect_dump_lsass_memory_using_comsvcs.md @@ -85,6 +85,8 @@ False positives should be limited, filter as needed. | 70.0 | 70 | 100 | A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ by user $dest_device_user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md b/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md index 76cdac2964..20462fc6f6 100644 --- a/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md +++ b/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md @@ -91,6 +91,8 @@ False positives should be limited as this is restricted to the Rclone process na | 35.0 | 50 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to connect to a remote cloud service to move files or folders. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md b/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md index 86e05f4201..f604258041 100644 --- a/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md +++ b/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md @@ -121,6 +121,8 @@ Legitimate applications may spawn PowerShell as a child process of the the ident | 45.0 | 90 | 50 | A PowerShell process was spawned as a child process of typically abused processes on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md index e164fa1163..b8e71a5ef6 100644 --- a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md +++ b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md @@ -95,6 +95,8 @@ Legitimate applications may use random Scheduled Task names. | 45.0 | 90 | 50 | A windows scheduled task with a suspicious task name was created on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md index 5ba0161e69..3bc89d7f1b 100644 --- a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md +++ b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md @@ -93,6 +93,8 @@ Legitimate applications may use random Windows Service names. | 45.0 | 90 | 50 | A Windows Service with a suspicious service name was installed on $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-30-delete_a_net_user.md b/docs/_posts/2021-11-30-delete_a_net_user.md index 6421067430..e900f9596a 100644 --- a/docs/_posts/2021-11-30-delete_a_net_user.md +++ b/docs/_posts/2021-11-30-delete_a_net_user.md @@ -85,6 +85,8 @@ System administrators or scripts may delete user accounts via this technique. Fi | 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user account. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-30-disable_net_user_account.md b/docs/_posts/2021-11-30-disable_net_user_account.md index d1e27763ef..338948cfad 100644 --- a/docs/_posts/2021-11-30-disable_net_user_account.md +++ b/docs/_posts/2021-11-30-disable_net_user_account.md @@ -92,6 +92,8 @@ System administrators or automated scripts may disable an account but not a comm | 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-30-first_time_seen_command_line_argument.md b/docs/_posts/2021-11-30-first_time_seen_command_line_argument.md index 4176a5a754..772947375d 100644 --- a/docs/_posts/2021-11-30-first_time_seen_command_line_argument.md +++ b/docs/_posts/2021-11-30-first_time_seen_command_line_argument.md @@ -95,6 +95,8 @@ Legitimate programs use command-line arguments to execute. Verify the command-li | 30.0 | 50 | 60 | A process $process_name$ ha been identified in the environment with a command-line $cmd_line$ not previously seen before on host $dest_device_id$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-30-grant_permission_using_cacls_utility.md b/docs/_posts/2021-11-30-grant_permission_using_cacls_utility.md index b7ee185816..82e83d9b3e 100644 --- a/docs/_posts/2021-11-30-grant_permission_using_cacls_utility.md +++ b/docs/_posts/2021-11-30-grant_permission_using_cacls_utility.md @@ -84,6 +84,8 @@ System administrators may use cacls utilities but this is not a common practice. | 35.0 | 50 | 70 | A cacls process $process_name$ with commandline $cmd_line$ try to grant user a permission to a file or directory in host $dest_device_id$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-30-modify_acls_permission_of_files_or_folders.md b/docs/_posts/2021-11-30-modify_acls_permission_of_files_or_folders.md index 140d48235c..85e019e720 100644 --- a/docs/_posts/2021-11-30-modify_acls_permission_of_files_or_folders.md +++ b/docs/_posts/2021-11-30-modify_acls_permission_of_files_or_folders.md @@ -84,6 +84,8 @@ System administrators may use this windows utility. filter is needed. | 35.0 | 50 | 70 | A cacls process $process_name$ with commandline $cmd_line$ try to modify a permission of a file or directory in host $dest_device_id$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md b/docs/_posts/2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md index ec50ffb429..cb904cf6c1 100644 --- a/docs/_posts/2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md +++ b/docs/_posts/2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md @@ -98,6 +98,8 @@ Environments in which NTLM is used extremely rarely and for benign purposes (suc | 72.0 | 80 | 90 | Potential lateral movement and credential stealing via Pass the Token or Pass the Hash techniques. Operation is performed via credentials of the account $dest_user_id$ and observed by the destination device $dest_device_id$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-30-rare_parent-child_process_relationship.md b/docs/_posts/2021-11-30-rare_parent-child_process_relationship.md index 984825bc9c..c0f55a8d7b 100644 --- a/docs/_posts/2021-11-30-rare_parent-child_process_relationship.md +++ b/docs/_posts/2021-11-30-rare_parent-child_process_relationship.md @@ -101,6 +101,8 @@ Some custom tools used by administrators could be used rarely to launch remotely +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-11-30-resize_shadowstorage_volume.md b/docs/_posts/2021-11-30-resize_shadowstorage_volume.md index 799464a3c7..ce8824c5ba 100644 --- a/docs/_posts/2021-11-30-resize_shadowstorage_volume.md +++ b/docs/_posts/2021-11-30-resize_shadowstorage_volume.md @@ -85,6 +85,8 @@ System administrators may resize the shadowstorage for valid purposes. Filter as | 64.0 | 80 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow copy to perform offline password cracking. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md index 8dc2c055f3..14e7d69e3d 100644 --- a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md +++ b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md @@ -94,6 +94,8 @@ An single endpoint requesting a large number of computer service tickets is not | 42.0 | 70 | 60 | None | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md index e700f17467..869e1014d4 100644 --- a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md +++ b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md @@ -94,6 +94,8 @@ An single endpoint authenticating to a large number of hosts is not common behav | 42.0 | 70 | 60 | None | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-03-detect_rclone_command-line_usage.md b/docs/_posts/2021-12-03-detect_rclone_command-line_usage.md index 6b89f0a352..7290546680 100644 --- a/docs/_posts/2021-12-03-detect_rclone_command-line_usage.md +++ b/docs/_posts/2021-12-03-detect_rclone_command-line_usage.md @@ -87,6 +87,8 @@ False positives should be limited as this is restricted to the Rclone process na | 35.0 | 50 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a remote cloud service to move files or folders. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-03-short_lived_scheduled_task.md b/docs/_posts/2021-12-03-short_lived_scheduled_task.md index 2aa8452b36..21047f2129 100644 --- a/docs/_posts/2021-12-03-short_lived_scheduled_task.md +++ b/docs/_posts/2021-12-03-short_lived_scheduled_task.md @@ -88,6 +88,8 @@ Although uncommon, legitimate applications may create and delete a Scheduled Tas | 81.0 | 90 | 90 | A windows scheduled task was created and deleted in 30 seconds on $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md b/docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md index df2b4494c1..34494a69ee 100644 --- a/docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md +++ b/docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md @@ -92,6 +92,8 @@ False positives may be limited to source control applications and may be require | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote destination. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md b/docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md index 92781e721f..3c0d2cfbe9 100644 --- a/docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md +++ b/docs/_posts/2021-12-07-anomalous_usage_of_account_credentials.md @@ -88,6 +88,8 @@ Shared workstations can cause false positives | 6.0 | 20 | 30 | Multiple interactive logins detected on $device$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md b/docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md index 45f5ad0ac5..a4c08b68a6 100644 --- a/docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md +++ b/docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md @@ -85,6 +85,8 @@ Administrators may modify the boot configuration. | 80.0 | 100 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability to recover the endpoint. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md b/docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md index dc6f05edf9..c982c2c963 100644 --- a/docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md +++ b/docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md @@ -89,6 +89,8 @@ It is possible for some legitimate administrative utilities to use similar cmd_l | 72.0 | 90 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related to DNS exfiltration. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-07-excessive_number_of_office_files_copied.md b/docs/_posts/2021-12-07-excessive_number_of_office_files_copied.md index d737cce0e2..dab2b36dee 100644 --- a/docs/_posts/2021-12-07-excessive_number_of_office_files_copied.md +++ b/docs/_posts/2021-12-07-excessive_number_of_office_files_copied.md @@ -80,6 +80,8 @@ user may copy a lot of office fies from one folder to another +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-07-fsutil_zeroing_file.md b/docs/_posts/2021-12-07-fsutil_zeroing_file.md index 9d4f64b89a..7017500520 100644 --- a/docs/_posts/2021-12-07-fsutil_zeroing_file.md +++ b/docs/_posts/2021-12-07-fsutil_zeroing_file.md @@ -84,6 +84,8 @@ System administrators or scripts may delete user accounts via this technique. Fi | 54.0 | 60 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file deletion. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-07-high_file_deletion_frequency.md b/docs/_posts/2021-12-07-high_file_deletion_frequency.md index af592b6d9c..beb291bc14 100644 --- a/docs/_posts/2021-12-07-high_file_deletion_frequency.md +++ b/docs/_posts/2021-12-07-high_file_deletion_frequency.md @@ -87,6 +87,8 @@ user may delete bunch of pictures or files in a folder. | 72.0 | 90 | 80 | High frequency file deletion activity detected on host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-07-microsoft_exchange_mailbox_replication_service_writing_active_server_pages.md b/docs/_posts/2021-12-07-microsoft_exchange_mailbox_replication_service_writing_active_server_pages.md index 685850030a..a7dcb6e348 100644 --- a/docs/_posts/2021-12-07-microsoft_exchange_mailbox_replication_service_writing_active_server_pages.md +++ b/docs/_posts/2021-12-07-microsoft_exchange_mailbox_replication_service_writing_active_server_pages.md @@ -105,6 +105,8 @@ The query is structured in a way that `action` (read, create) is not defined. Re | 81.0 | 90 | 90 | A file - $file_name$ was written to disk that is related to IIS exploitation related to ProxyShell. Review further file modifications on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-07-wbadmin_delete_system_backups.md b/docs/_posts/2021-12-07-wbadmin_delete_system_backups.md index d4b331be14..8fe8ec4e3c 100644 --- a/docs/_posts/2021-12-07-wbadmin_delete_system_backups.md +++ b/docs/_posts/2021-12-07-wbadmin_delete_system_backups.md @@ -85,6 +85,8 @@ Administrators may modify the boot configuration. | 15.0 | 30 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system backups. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md b/docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md index 71de4d0d45..392f00aab3 100644 --- a/docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md +++ b/docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md @@ -92,6 +92,8 @@ False positives should be limited, however filter as needed. | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user user$ attempting to disable Raccines scheduled task. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-08-disable_defender_antivirus_registry.md b/docs/_posts/2021-12-08-disable_defender_antivirus_registry.md index e6a93e9ad7..3b4c5cea0f 100644 --- a/docs/_posts/2021-12-08-disable_defender_antivirus_registry.md +++ b/docs/_posts/2021-12-08-disable_defender_antivirus_registry.md @@ -89,6 +89,8 @@ Admin or user may choose to disable windows defender product | 49.0 | 70 | 70 | Modified/added/deleted registry entry $registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md b/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md index fd7f8bf0f0..9f1afde51e 100644 --- a/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md +++ b/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md @@ -98,6 +98,8 @@ It is possible some Administrative utilities will load msi.dll outside of normal | 56.0 | 80 | 70 | The following module $ImageLoaded$ was loaded by $Image$ outside of the normal system paths on endpoint $Computer$, potentally related to DLL side-loading. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-10-curl_download_and_bash_execution.md b/docs/_posts/2021-12-10-curl_download_and_bash_execution.md index c94eb70ab9..09180df532 100644 --- a/docs/_posts/2021-12-10-curl_download_and_bash_execution.md +++ b/docs/_posts/2021-12-10-curl_download_and_bash_execution.md @@ -94,6 +94,8 @@ False positives should be limited, however filtering may be required. | 80.0 | 80 | 100 | An instance of $process_name$ was identified on endpoint $dest$ attempting to download a remote file and run it with bash. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-11-wget_download_and_bash_execution.md b/docs/_posts/2021-12-11-wget_download_and_bash_execution.md index c851860a38..7b1f213d61 100644 --- a/docs/_posts/2021-12-11-wget_download_and_bash_execution.md +++ b/docs/_posts/2021-12-11-wget_download_and_bash_execution.md @@ -94,6 +94,8 @@ False positives should be limited, however filtering may be required. | 80.0 | 80 | 100 | An instance of $process_name$ was identified on endpoint $dest$ attempting to download a remote file and run it with bash. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md b/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md index 5ece6f277d..f4fc63f232 100644 --- a/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md +++ b/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md @@ -90,6 +90,8 @@ Unknown at this moment. Outbound LDAP traffic should not be allowed outbound thr | 56.0 | 70 | 80 | An outbound LDAP connection from $src_ip$ in your infrastructure connecting to dest ip $dest_ip$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md b/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md index 7183d921ee..91d5c3769f 100644 --- a/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md +++ b/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md @@ -87,6 +87,8 @@ Filtering may be required in some instances, filter as needed. | 40.0 | 80 | 50 | A Java user agent $http_user_agent$ was performing a $http_method$ to retrieve a remote class file. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-13-linux_java_spawning_shell.md b/docs/_posts/2021-12-13-linux_java_spawning_shell.md index 50fbcfd330..8626fec415 100644 --- a/docs/_posts/2021-12-13-linux_java_spawning_shell.md +++ b/docs/_posts/2021-12-13-linux_java_spawning_shell.md @@ -94,6 +94,8 @@ Filtering may be required on internal developer build systems or classify assets | 40.0 | 80 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ spawning a Linux shell, potentially indicative of exploitation. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md index e24ae67179..1abf4a9a91 100644 --- a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md +++ b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md @@ -97,6 +97,8 @@ If there is a vulnerablility scannner looking for log4shells this will trigger, | 15.0 | 50 | 30 | CVE-2021-44228 Log4Shell triggered for host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md index 974244c92d..1117da60dd 100644 --- a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md +++ b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md @@ -105,6 +105,8 @@ If there is a vulnerablility scannner looking for log4shells this will trigger, | 15.0 | 50 | 30 | CVE-2021-44228 Log4Shell triggered for host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md b/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md index 10b60d8dde..f67564e419 100644 --- a/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md +++ b/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md @@ -95,6 +95,8 @@ Legitimate Java applications may use perform outbound connections to these ports | 54.0 | 90 | 60 | Java performed outbound connections to default ports of LDAP or RMI on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-13-windows_java_spawning_shells.md b/docs/_posts/2021-12-13-windows_java_spawning_shells.md index 0cb9f72e70..109504d529 100644 --- a/docs/_posts/2021-12-13-windows_java_spawning_shells.md +++ b/docs/_posts/2021-12-13-windows_java_spawning_shells.md @@ -96,6 +96,8 @@ Filtering may be required on internal developer build systems or classify assets | 40.0 | 80 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ spawning a Windows shell, potentially indicative of exploitation. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-14-hunting_for_log4shell.md b/docs/_posts/2021-12-14-hunting_for_log4shell.md index 2803a88c41..a410fa6e1e 100644 --- a/docs/_posts/2021-12-14-hunting_for_log4shell.md +++ b/docs/_posts/2021-12-14-hunting_for_log4shell.md @@ -210,6 +210,8 @@ It is highly possible you will find false positives, however, the base score is | 40.0 | 80 | 50 | Hunting for Log4Shell exploitation has occurred. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md b/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md index 5152c627eb..c9ca7fa5a3 100644 --- a/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md +++ b/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md @@ -95,6 +95,8 @@ Administrator or network operator can create file in crontab folders for automat | 25.0 | 50 | 50 | a file $file_name$ is created in $file_path$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md b/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md index a3babaa500..4764bc6d90 100644 --- a/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md +++ b/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md @@ -95,6 +95,8 @@ Administrator or network operator can create this file for automation purposes. | 25.0 | 50 | 50 | A file $file_name$ is created in $file_path$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-17-linux_at_application_execution.md b/docs/_posts/2021-12-17-linux_at_application_execution.md index 67b8a675f7..cd14162883 100644 --- a/docs/_posts/2021-12-17-linux_at_application_execution.md +++ b/docs/_posts/2021-12-17-linux_at_application_execution.md @@ -97,6 +97,8 @@ Administrator or network operator can use this application for automation purpos | 9.0 | 30 | 30 | At application was executed in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md b/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md index 339978e964..418ec1462c 100644 --- a/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md +++ b/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md @@ -97,6 +97,8 @@ Administrator or network operator can use this application for automation purpos | 9.0 | 30 | 30 | A possible crontab edit command $process$ executed on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md b/docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md index a60a50b51c..4081d3f813 100644 --- a/docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md +++ b/docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md @@ -97,6 +97,8 @@ Administrator or network operator can use this commandline for automation purpos | 9.0 | 30 | 30 | A commandline $process$ that may modify at allow config file in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md b/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md index 71526a77d8..65d163f593 100644 --- a/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md +++ b/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md @@ -97,6 +97,8 @@ Administrator or network operator can use this commandline for automation purpos | 49.0 | 70 | 70 | A commandline $process$ that may modify cronjob file in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md b/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md index e4f17d7539..623009b971 100644 --- a/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md +++ b/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md @@ -97,6 +97,8 @@ Administrator or network operator can use this commandline for automation purpos | 6.0 | 20 | 30 | A commandline $process$ that may modify cronjob file using editor in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md b/docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md index 4793a21302..60c077cd42 100644 --- a/docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md +++ b/docs/_posts/2021-12-20-clear_unallocated_sector_using_cipher_app.md @@ -93,6 +93,8 @@ administrator may execute this app to manage disk | 90.0 | 90 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to clear the unallocated sectors of a specific disk. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md b/docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md index d62effeb2c..1e044103fd 100644 --- a/docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md +++ b/docs/_posts/2021-12-20-hiding_files_and_directories_with_attrib_exe.md @@ -83,6 +83,8 @@ Some applications and users may legitimately use attrib.exe to interact with the | 72.0 | 80 | 90 | Attrib.exe with +h flag to hide files on $dest$ executed by $user$ is detected. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md b/docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md index 70ca9d5667..08718fdfe8 100644 --- a/docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md +++ b/docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md @@ -93,6 +93,8 @@ Administrator or network operator can create file in this folders for automation | 49.0 | 70 | 70 | A file $file_name$ is created in $file_path$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md b/docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md index 3a31074eb1..35c1b258cc 100644 --- a/docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md +++ b/docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md @@ -93,6 +93,8 @@ Administrator or network operator can create file in profile.d folders for autom | 56.0 | 70 | 80 | A file $file_name$ is created in $file_path$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md b/docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md index 489b2c3aee..5ea02084c6 100644 --- a/docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md +++ b/docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md @@ -95,6 +95,8 @@ Administrator or network operator can use this commandline for automation purpos | 49.0 | 70 | 70 | a commandline $process$ that may modify profile files in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md b/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md index b5e9a04920..ccc9a36100 100644 --- a/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md +++ b/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md @@ -95,6 +95,8 @@ Administrator or network operator can create file in systemd folders for automat | 64.0 | 80 | 80 | A service file named as $file_path$ is created in systemd folder on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-20-linux_service_restarted.md b/docs/_posts/2021-12-20-linux_service_restarted.md index d3f0e5daa0..85e0c4bdb7 100644 --- a/docs/_posts/2021-12-20-linux_service_restarted.md +++ b/docs/_posts/2021-12-20-linux_service_restarted.md @@ -97,6 +97,8 @@ Administrator or network operator can use this commandline for automation purpos | 25.0 | 50 | 50 | A commandline $process$ that may create or start a service on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-20-linux_service_started_or_enabled.md b/docs/_posts/2021-12-20-linux_service_started_or_enabled.md index f569401d66..3c0e0e66d9 100644 --- a/docs/_posts/2021-12-20-linux_service_started_or_enabled.md +++ b/docs/_posts/2021-12-20-linux_service_started_or_enabled.md @@ -97,6 +97,8 @@ Administrator or network operator can use this commandline for automation purpos | 42.0 | 60 | 70 | a commandline $process$ that may create or start a service on $dest | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md b/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md index bc8b5448c2..44799e7a11 100644 --- a/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md +++ b/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md @@ -94,6 +94,8 @@ Renaming a computer account name to a name that not end with '$' is high | 70.0 | 100 | 70 | A computer account $Old_Account_Name$ was renamed with a suspicious computer name | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md b/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md index d9971c5334..904e4e32cd 100644 --- a/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md +++ b/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md @@ -96,6 +96,8 @@ We have tested this detection logic with ~2 million 4769 events and did not iden | 60.0 | 100 | 60 | A suspicious Kerberos Service Ticket was requested by $Account_Name$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2021-12-21-linux_add_user_account.md b/docs/_posts/2021-12-21-linux_add_user_account.md index f4e3ac46f6..d3a0bfe619 100644 --- a/docs/_posts/2021-12-21-linux_add_user_account.md +++ b/docs/_posts/2021-12-21-linux_add_user_account.md @@ -93,6 +93,8 @@ Administrator or network operator can execute this command. Please update the fi | 25.0 | 50 | 50 | A commandline $process$ that may create user account on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md b/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md index 3d8943df40..e9bb5b99fa 100644 --- a/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md +++ b/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md @@ -93,6 +93,8 @@ Administrator or network operator can execute this command. Please update the fi | 64.0 | 80 | 80 | A commandline $process$ that may change ownership to root on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md b/docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md index f17c0891e8..69d1b236c2 100644 --- a/docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md +++ b/docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md @@ -95,6 +95,8 @@ Administrator or network operator can execute this command. Please update the fi | 64.0 | 80 | 80 | a commandline $process$ executed on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md b/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md index 201372e990..87d9ca9071 100644 --- a/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md +++ b/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md @@ -95,6 +95,8 @@ Administrator or network operator can execute this command. Please update the fi | 49.0 | 70 | 70 | a commandline $process$ that may set suid or sgid on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md b/docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md index 585594f569..cdddbcfb93 100644 --- a/docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md +++ b/docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md @@ -95,6 +95,8 @@ Administrator or network operator can execute this command. Please update the fi | 49.0 | 70 | 70 | A commandline $process$ that may set suid or sgid on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-21-linux_visudo_utility_execution.md b/docs/_posts/2021-12-21-linux_visudo_utility_execution.md index ce41fed013..4800fadf07 100644 --- a/docs/_posts/2021-12-21-linux_visudo_utility_execution.md +++ b/docs/_posts/2021-12-21-linux_visudo_utility_execution.md @@ -95,6 +95,8 @@ Administrator or network operator can execute this command. Please update the fi | 16.0 | 40 | 40 | A commandline $process$ executed on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md b/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md index 596365663c..90bc4ad1e6 100644 --- a/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md +++ b/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md @@ -96,6 +96,8 @@ A computer account name change event inmediately followed by a kerberos TGT requ | 60.0 | 100 | 60 | A suspicious TGT was requested was requested | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md b/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md index 0091309750..2aa016963a 100644 --- a/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md +++ b/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md @@ -93,6 +93,8 @@ Administrator or network operator can create file in this folders for automation | 72.0 | 80 | 90 | A file $file_name$ is created in $file_path$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md b/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md index cc743a6317..dcc364812c 100644 --- a/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md +++ b/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md @@ -95,6 +95,8 @@ Administrator or network operator can execute this command. Please update the fi | 64.0 | 80 | 80 | A commandline $process$ that may install kernel module on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md b/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md index 354a4a0097..6512abe6fd 100644 --- a/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md +++ b/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md @@ -95,6 +95,8 @@ Administrator or network operator can execute this command. Please update the fi | 64.0 | 80 | 80 | A commandline $process$ that may install kernel module on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md b/docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md index 1c9c29e949..81d48ae8ad 100644 --- a/docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md +++ b/docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md @@ -97,6 +97,8 @@ Administrator or network operator can execute this command. Please update the fi | 64.0 | 80 | 80 | A commandline $process$ that may hijack library function on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md b/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md index 118d20e4bd..77a3d7c5b0 100644 --- a/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md +++ b/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md @@ -95,6 +95,8 @@ Administrator or network operator can execute this command. Please update the fi | 9.0 | 30 | 30 | A commandline $process$ with process $process_name$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md b/docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md index d7a906592f..cb9ef23d9b 100644 --- a/docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md +++ b/docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md @@ -93,6 +93,8 @@ administrator or network operator can execute this command. Please update the fi | 72.0 | 80 | 90 | A file $file_name$ is created in $file_path$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-04-linux_sudo_or_su_execution.md b/docs/_posts/2022-01-04-linux_sudo_or_su_execution.md index f207019a9a..89ffa17595 100644 --- a/docs/_posts/2022-01-04-linux_sudo_or_su_execution.md +++ b/docs/_posts/2022-01-04-linux_sudo_or_su_execution.md @@ -95,6 +95,8 @@ Administrator or network operator can execute this command. Please update the fi | 9.0 | 30 | 30 | A commandline $process$ that execute sudo or su in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-05-linux_doas_conf_file_creation.md b/docs/_posts/2022-01-05-linux_doas_conf_file_creation.md index 2d4edd907c..5318b75d2d 100644 --- a/docs/_posts/2022-01-05-linux_doas_conf_file_creation.md +++ b/docs/_posts/2022-01-05-linux_doas_conf_file_creation.md @@ -93,6 +93,8 @@ Administrator or network operator can execute this command. Please update the fi | 49.0 | 70 | 70 | A file $file_name$ is created in $file_path$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-05-linux_doas_tool_execution.md b/docs/_posts/2022-01-05-linux_doas_tool_execution.md index a2e7aad807..1f0f1d2c32 100644 --- a/docs/_posts/2022-01-05-linux_doas_tool_execution.md +++ b/docs/_posts/2022-01-05-linux_doas_tool_execution.md @@ -95,6 +95,8 @@ Administrator or network operator can execute this command. Please update the fi | 49.0 | 70 | 70 | A doas $process_name$ with commandline $process$ was executed on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md b/docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md index 7f6f7490d2..5c6249f0ed 100644 --- a/docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md +++ b/docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md @@ -93,6 +93,8 @@ Administrator or network operator can execute this command. Please update the fi | 25.0 | 50 | 50 | A commandline $process$ executed on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md b/docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md index bf9dcbd7b4..0df3228295 100644 --- a/docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md +++ b/docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md @@ -95,6 +95,8 @@ administrator or network operator can execute this command. Please update the fi | 25.0 | 50 | 50 | A commandline $process$ executed on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md b/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md index 68c2684609..6c5e71d0a5 100644 --- a/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md +++ b/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md @@ -93,6 +93,8 @@ Administrator or network operator can use this commandline for automation purpos | 25.0 | 50 | 50 | a commandline $process$ executed on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md b/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md index 3f204e6358..6bcf9ae8f2 100644 --- a/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md +++ b/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md @@ -91,6 +91,8 @@ Administrator or network operator can create file in ~/.ssh folders for automati | 36.0 | 60 | 60 | A file $file_name$ is created in $file_path$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md b/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md index d2132781db..24d8c4ed20 100644 --- a/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md +++ b/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md @@ -101,6 +101,8 @@ Legitimate process can have this combination of command-line options, but it' | 81.0 | 90 | 90 | PowerShell processes $process$ started with parameters to modify the execution policy of the run, run in a hidden window, and connect to the Internet on host $dest$ executed by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md b/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md index 45bcd24b33..13cddd2ebb 100644 --- a/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md +++ b/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md @@ -91,6 +91,8 @@ False positives will occur based on GrantedAccess and SourceUser, filter based o | 64.0 | 80 | 80 | A process, $SourceImage$, has loaded $ImageLoaded$ that are typically related to credential dumping on $dest$. Review for further details. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md b/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md index fa3994bf8b..a559fea6bd 100644 --- a/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md +++ b/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md @@ -91,6 +91,8 @@ False positives will occur based on legitimate application requests, filter base | 64.0 | 80 | 80 | A process, $SourceImage$, has loaded $ImageLoaded$ that are typically related to credential dumping on $dest$. Review for further details. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md b/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md index 397fd6e0a5..0bc4821944 100644 --- a/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md +++ b/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md @@ -94,6 +94,8 @@ This model is an anomaly detector that identifies usage of APIs and scripting co | 12.0 | 60 | 20 | Unusual command-line execution with hallmarks of malicious activity run by $user$ found on $dest$ with commandline $process$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md b/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md index a891f74f40..0a8920ab37 100644 --- a/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md +++ b/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md @@ -98,6 +98,8 @@ False positives may be high based on legitimate scripted code in any environment | 30.0 | 60 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting spawn a new process. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md b/docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md index f97c07a952..50250df870 100644 --- a/docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md +++ b/docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md @@ -110,6 +110,8 @@ Although uncommon, Administrators may leverage Impackets tools to start a proces | 63.0 | 90 | 70 | Suspicious command line parameters on $dest may represent a lateral movement attack with Impackets tools | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md b/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md index a3a7cb6c84..77aa316328 100644 --- a/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md +++ b/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md @@ -99,6 +99,8 @@ System administrators may use this option, but it's not common. | 35.0 | 70 | 50 | Powershell.exe running potentially malicious encodede commands on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md b/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md index c700b9ca00..69982e4121 100644 --- a/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md +++ b/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md @@ -91,6 +91,8 @@ Noise and false positive can be seen if the following instant messaging is allow | 64.0 | 80 | 80 | suspicious process $process_name$ has a dns query in $QueryName$ on $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md b/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md index 7b91a5acff..2f3c7b3e7a 100644 --- a/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md +++ b/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md @@ -91,6 +91,8 @@ Noise and false positive can be seen if the following instant messaging is allow | 64.0 | 80 | 80 | suspicious process $process_name$ has a dns query in $QueryName$ on $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md b/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md index bf057bff01..c6d6de98c3 100644 --- a/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md +++ b/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md @@ -116,6 +116,8 @@ False positives may be present and filtering may be required. Certain utilities | 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ from a non-standard path was identified on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md b/docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md index 4b1368edc5..d087f2627b 100644 --- a/docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md +++ b/docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md @@ -109,6 +109,8 @@ False positives may be present and filtering may be required. Certain utilities | 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ from a non-standard path was identified on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md b/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md index fc05fc993f..3b440cbe14 100644 --- a/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md +++ b/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md @@ -87,6 +87,8 @@ Windows Defender AV updates may cause this alert. Please update the filter macro | 25.0 | 50 | 50 | High frequency file deletion activity detected on host $Computer$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-20-ping_sleep_batch_command.md b/docs/_posts/2022-01-20-ping_sleep_batch_command.md index 029d6e3423..0f1c56ccbc 100644 --- a/docs/_posts/2022-01-20-ping_sleep_batch_command.md +++ b/docs/_posts/2022-01-20-ping_sleep_batch_command.md @@ -99,6 +99,8 @@ Administrator or network operator may execute this command. Please update the fi | 36.0 | 60 | 60 | suspicious $process$ commandline run in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-20-powershell_remove_windows_defender_directory.md b/docs/_posts/2022-01-20-powershell_remove_windows_defender_directory.md index de45894194..a38401c6af 100644 --- a/docs/_posts/2022-01-20-powershell_remove_windows_defender_directory.md +++ b/docs/_posts/2022-01-20-powershell_remove_windows_defender_directory.md @@ -88,6 +88,8 @@ unknown | 90.0 | 100 | 90 | suspicious powershell script $Message$ was executed on the $ComputerName$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md b/docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md index 43706a9f76..54cc011861 100644 --- a/docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md +++ b/docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md @@ -94,6 +94,8 @@ False positives should be limited as it is specific to AdvancedRun. Filter as ne | 60.0 | 60 | 100 | An instance of advancedrun.exe, $process_name$, was spawned by $parent_process_name$ on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-24-windows_nirsoft_utilities.md b/docs/_posts/2022-01-24-windows_nirsoft_utilities.md index c961456605..f2892c1250 100644 --- a/docs/_posts/2022-01-24-windows_nirsoft_utilities.md +++ b/docs/_posts/2022-01-24-windows_nirsoft_utilities.md @@ -99,6 +99,8 @@ False positives may be present. Filtering may be required before setting to aler | 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ related to NiRSoft software usage. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-active_setup_registry_autostart.md b/docs/_posts/2022-01-26-active_setup_registry_autostart.md index 460bf6c2e2..bf1875433b 100644 --- a/docs/_posts/2022-01-26-active_setup_registry_autostart.md +++ b/docs/_posts/2022-01-26-active_setup_registry_autostart.md @@ -97,6 +97,8 @@ Active setup installer may add or modify this registry. | 64.0 | 80 | 80 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md b/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md index ca6a157521..a636171be5 100644 --- a/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md +++ b/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md @@ -93,6 +93,8 @@ unknown | 25.0 | 50 | 50 | modified registry key $registry_key_name$ with registry value $registry_value_name$ to prepare autoadminlogon | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md b/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md index a7b15e6750..da2dc82e98 100644 --- a/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md +++ b/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md @@ -101,6 +101,8 @@ network admin may add/remove/modify public inbound firewall rule that may cause | 3.0 | 10 | 30 | Suspicious firewall modifications were detected via the registry on endpoint $dest$ by user $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md b/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md index 80f33518a0..f0d97fc718 100644 --- a/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md +++ b/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md @@ -90,6 +90,8 @@ unknown | 25.0 | 50 | 50 | Suspicious registry modification was performed on endpoint $dest$ by user $user$. This behavior is indicative of privilege escalation. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-disable_amsi_through_registry.md b/docs/_posts/2022-01-26-disable_amsi_through_registry.md index 0621aa8625..cdcbed47d0 100644 --- a/docs/_posts/2022-01-26-disable_amsi_through_registry.md +++ b/docs/_posts/2022-01-26-disable_amsi_through_registry.md @@ -88,6 +88,8 @@ network operator may disable this feature of windows but not so common. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md b/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md index 65057953af..9b8e7ed29a 100644 --- a/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md +++ b/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md @@ -95,6 +95,8 @@ admin or user may choose to disable windows defender product | 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md b/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md index a09d6314d3..e8d4c467b3 100644 --- a/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md +++ b/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md @@ -95,6 +95,8 @@ admin or user may choose to disable windows defender product | 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md b/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md index c52614d3b8..e0b4a40c50 100644 --- a/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md +++ b/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md @@ -95,6 +95,8 @@ user may choose to disable windows defender AV | 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md b/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md index b0a530f68a..80e4228df7 100644 --- a/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md +++ b/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md @@ -95,6 +95,8 @@ admin or user may choose to disable windows defender product | 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md b/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md index e51092b463..9cf104cbad 100644 --- a/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md +++ b/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md @@ -95,6 +95,8 @@ admin or user may choose to disable windows defender product | 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md b/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md index f05592e28b..be48656b1f 100644 --- a/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md +++ b/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md @@ -95,6 +95,8 @@ admin or user may choose to disable windows defender product | 49.0 | 70 | 70 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md b/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md index 294978966c..c18fc7f288 100644 --- a/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md +++ b/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md @@ -103,6 +103,8 @@ There are many legitimate applications that must execute on system startup and w | 76.0 | 80 | 95 | A registry activity in $registry_path$ related to persistence in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md b/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md index 7dfdde8d2f..390580e235 100644 --- a/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md +++ b/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md @@ -96,6 +96,8 @@ There are many legitimate applications that must execute upon system startup and | 76.0 | 80 | 95 | A registry activity in $registry_path$ related to privilege escalation in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md b/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md index bfea23a4ad..ebba1879a8 100644 --- a/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md +++ b/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md @@ -90,6 +90,8 @@ unknown | 90.0 | 90 | 100 | A registry entry $registry_path$ with registry keyname $registry_key_name$ related to Remcos RAT in host $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md b/docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md index e3efff97ef..9398b4fa95 100644 --- a/docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md +++ b/docs/_posts/2022-01-26-start_up_during_safe_mode_boot.md @@ -95,6 +95,8 @@ updated windows application needed in safe boot may used this registry | 42.0 | 60 | 70 | Safeboot registry $registry_path$ was added or modified with a new value $registry_value_name$ on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-26-time_provider_persistence_registry.md b/docs/_posts/2022-01-26-time_provider_persistence_registry.md index 0ca7694ccd..5058d02a31 100644 --- a/docs/_posts/2022-01-26-time_provider_persistence_registry.md +++ b/docs/_posts/2022-01-26-time_provider_persistence_registry.md @@ -97,6 +97,8 @@ unknown | 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-27-disable_etw_through_registry.md b/docs/_posts/2022-01-27-disable_etw_through_registry.md index 45cf120da4..d6c9352ab5 100644 --- a/docs/_posts/2022-01-27-disable_etw_through_registry.md +++ b/docs/_posts/2022-01-27-disable_etw_through_registry.md @@ -88,6 +88,8 @@ network operator may disable this feature of windows but not so common. +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-27-disable_registry_tool.md b/docs/_posts/2022-01-27-disable_registry_tool.md index 4ac46cd21e..a6e93d7800 100644 --- a/docs/_posts/2022-01-27-disable_registry_tool.md +++ b/docs/_posts/2022-01-27-disable_registry_tool.md @@ -94,6 +94,8 @@ admin may disable this application for non technical user. | 40.0 | 40 | 100 | Disabled Registry Tools on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md b/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md index 016237d022..167db9fe4f 100644 --- a/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md +++ b/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md @@ -91,6 +91,8 @@ Unknown. | 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-27-disable_show_hidden_files.md b/docs/_posts/2022-01-27-disable_show_hidden_files.md index 4b7389618c..5cf447c922 100644 --- a/docs/_posts/2022-01-27-disable_show_hidden_files.md +++ b/docs/_posts/2022-01-27-disable_show_hidden_files.md @@ -102,6 +102,8 @@ unknown | 40.0 | 40 | 100 | Disabled 'Show Hidden Files' on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-27-disable_uac_remote_restriction.md b/docs/_posts/2022-01-27-disable_uac_remote_restriction.md index faaf0f4fe8..6c90d86a71 100644 --- a/docs/_posts/2022-01-27-disable_uac_remote_restriction.md +++ b/docs/_posts/2022-01-27-disable_uac_remote_restriction.md @@ -98,6 +98,8 @@ admin may set this policy for non-critical machine. | 80.0 | 80 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md b/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md index 1cc4d3a015..3f01672b0b 100644 --- a/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md +++ b/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md @@ -93,6 +93,8 @@ unknown | 40.0 | 40 | 100 | Disabled 'Windows App Hotkeys' on $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md b/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md index 136c3add9e..f43a20aa48 100644 --- a/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md +++ b/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md @@ -96,6 +96,8 @@ admin or user may choose to disable this windows features. | 40.0 | 40 | 100 | Windows Defender real time behavior monitoring disabled on $dest | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md b/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md index 3c6e276535..ec9382e96e 100644 --- a/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md +++ b/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md @@ -94,6 +94,8 @@ admin or user may choose to disable this windows features. | 25.0 | 50 | 50 | The Windows Smartscreen was disabled on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-27-disabling_cmd_application.md b/docs/_posts/2022-01-27-disabling_cmd_application.md index 73e7642282..f9c5fb91cd 100644 --- a/docs/_posts/2022-01-27-disabling_cmd_application.md +++ b/docs/_posts/2022-01-27-disabling_cmd_application.md @@ -94,6 +94,8 @@ admin may disable this application for non technical user. | 25.0 | 50 | 50 | The Windows command prompt was disabled on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-27-disabling_controlpanel.md b/docs/_posts/2022-01-27-disabling_controlpanel.md index 52838b09fa..09083edf53 100644 --- a/docs/_posts/2022-01-27-disabling_controlpanel.md +++ b/docs/_posts/2022-01-27-disabling_controlpanel.md @@ -94,6 +94,8 @@ admin may disable this application for non technical user. | 25.0 | 50 | 50 | The Windows Control Panel was disabled on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-27-windows_possible_credential_dumping.md b/docs/_posts/2022-01-27-windows_possible_credential_dumping.md index 26844d786a..99535d0a00 100644 --- a/docs/_posts/2022-01-27-windows_possible_credential_dumping.md +++ b/docs/_posts/2022-01-27-windows_possible_credential_dumping.md @@ -97,6 +97,8 @@ False positives will occur based on GrantedAccess 0x1010 and 0x1400, filter base | 64.0 | 80 | 80 | A process, $SourceImage$, has loaded $ImageLoaded$ that are typically related to credential dumping on $dest$. Review for further details. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-28-disabling_defender_services.md b/docs/_posts/2022-01-28-disabling_defender_services.md index f81b37212a..734a7fedfc 100644 --- a/docs/_posts/2022-01-28-disabling_defender_services.md +++ b/docs/_posts/2022-01-28-disabling_defender_services.md @@ -95,6 +95,8 @@ admin or user may choose to disable windows defender product | 49.0 | 70 | 70 | modified/added/deleted registry entry $registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md b/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md index 4358b4c47e..5728ad355a 100644 --- a/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md +++ b/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md @@ -94,6 +94,8 @@ admin may disable this application for non technical user. | 25.0 | 50 | 50 | The Windows Folder Options, to hide files, was disabled on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-28-disabling_norun_windows_app.md b/docs/_posts/2022-01-28-disabling_norun_windows_app.md index 6d80b7dc70..b280e211fd 100644 --- a/docs/_posts/2022-01-28-disabling_norun_windows_app.md +++ b/docs/_posts/2022-01-28-disabling_norun_windows_app.md @@ -94,6 +94,8 @@ admin may disable this application for non technical user. | 25.0 | 50 | 50 | The Windows registry was modified to disable run application in window start menu on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md b/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md index 5e417a47c8..2a79f3d72c 100644 --- a/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md +++ b/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md @@ -94,6 +94,8 @@ in some cases admin can disable systemrestore on a machine. | 49.0 | 70 | 70 | The Windows registry was modified to disable system restore on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-28-disabling_task_manager.md b/docs/_posts/2022-01-28-disabling_task_manager.md index e31d7f2223..7fb480fba5 100644 --- a/docs/_posts/2022-01-28-disabling_task_manager.md +++ b/docs/_posts/2022-01-28-disabling_task_manager.md @@ -94,6 +94,8 @@ admin may disable this application for non technical user. | 42.0 | 70 | 60 | The Windows Task Manager was disabled on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md b/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md index fdc3707321..f628fad846 100644 --- a/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md +++ b/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md @@ -89,6 +89,8 @@ unknown | 80.0 | 80 | 100 | RDP was moved to a non-standard port on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md b/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md index 8f7d038d05..151a0fbeb0 100644 --- a/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md +++ b/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md @@ -95,6 +95,8 @@ unknown | 80.0 | 80 | 100 | wdigest registry $registry_path$ was modified in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-28-etw_registry_disabled.md b/docs/_posts/2022-01-28-etw_registry_disabled.md index 8748cce5b2..45e15fbea7 100644 --- a/docs/_posts/2022-01-28-etw_registry_disabled.md +++ b/docs/_posts/2022-01-28-etw_registry_disabled.md @@ -100,6 +100,8 @@ unknown | 90.0 | 90 | 100 | modified/added/deleted registry entry $Registry.registry_path$ in $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-28-eventvwr_uac_bypass.md b/docs/_posts/2022-01-28-eventvwr_uac_bypass.md index 2bde8515cf..91ef50283e 100644 --- a/docs/_posts/2022-01-28-eventvwr_uac_bypass.md +++ b/docs/_posts/2022-01-28-eventvwr_uac_bypass.md @@ -98,6 +98,8 @@ Some false positives may be present and will need to be filtered. | 80.0 | 80 | 100 | Registry values were modified to bypass UAC using Event Viewer on $dest$ by $user$. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md b/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md index 9779d2edd5..1b269f9c8a 100644 --- a/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md +++ b/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md @@ -93,6 +93,8 @@ Unknown. Filter as needed. | 72.0 | 90 | 80 | Suspicious registry modification ($registry_value_name$) which is used go hide a user account on the Windows Login screen detected on $dest$ executed by $user$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md b/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md index 70fec62f2d..bf36b695d2 100644 --- a/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md +++ b/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md @@ -94,6 +94,8 @@ False positives may be present, filter as needed. | 56.0 | 80 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ related to a local privilege escalation in polkit pkexec. | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### CVE diff --git a/docs/_posts/2022-02-03-o365_added_service_principal.md b/docs/_posts/2022-02-03-o365_added_service_principal.md index 103f6f4c37..0636183fc1 100644 --- a/docs/_posts/2022-02-03-o365_added_service_principal.md +++ b/docs/_posts/2022-02-03-o365_added_service_principal.md @@ -92,6 +92,8 @@ The creation of a new Federation is not necessarily malicious, however these eve | 42.0 | 70 | 60 | User $Actor.ID$ created a new federation setting on $Target.ID$ and added service principal credentials from IP Address $ActorIpAddress$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md b/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md index d8bd5c3b46..b3daa88f8a 100644 --- a/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md +++ b/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md @@ -98,6 +98,8 @@ Unless it is a special case, it is uncommon to continually update Trusted IPs to | 42.0 | 70 | 60 | User $user_id$ has added new IP addresses $ip_addresses_new_added$ to a list of trusted IPs to bypass MFA | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_posts/2022-02-03-o365_disable_mfa.md b/docs/_posts/2022-02-03-o365_disable_mfa.md index 37cc71ff03..1f26ebba0a 100644 --- a/docs/_posts/2022-02-03-o365_disable_mfa.md +++ b/docs/_posts/2022-02-03-o365_disable_mfa.md @@ -89,6 +89,8 @@ Unless it is a special case, it is uncommon to disable MFA or Strong Authenticat | 64.0 | 80 | 80 | User $user$ has executed an operation $Operation$ for this destination $dest$ | +Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100` + #### Reference diff --git a/docs/_stories/credential_dumping.md b/docs/_stories/credential_dumping.md index 99b0828fa0..a3f454b5e4 100644 --- a/docs/_stories/credential_dumping.md +++ b/docs/_stories/credential_dumping.md @@ -35,8 +35,8 @@ The detection searches in this Analytic Story monitor access to the Local Securi | Name | Technique | Type | | ----------- | ----------- |--------------| | [Access LSASS Memory for Dump Creation](/endpoint/access_lsass_memory_for_dump_creation/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [OS Credential Dumping](/tags/#os-credential-dumping), [Security Account Manager](/tags/#security-account-manager) | TTP | +| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Create Remote Thread into LSASS](/endpoint/create_remote_thread_into_lsass/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Creation of Shadow Copy](/endpoint/creation_of_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Creation of Shadow Copy with wmic and powershell](/endpoint/creation_of_shadow_copy_with_wmic_and_powershell/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | diff --git a/docs/_stories/windows_defense_evasion_tactics.md b/docs/_stories/windows_defense_evasion_tactics.md index 670239b265..001a481dac 100644 --- a/docs/_stories/windows_defense_evasion_tactics.md +++ b/docs/_stories/windows_defense_evasion_tactics.md @@ -51,8 +51,8 @@ Defense evasion is a tactic--identified in the MITRE ATT&CK framework--that adve | [Excessive number of service control start as disabled](/endpoint/excessive_number_of_service_control_start_as_disabled/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | Anomaly | | [Firewall Allowed Program Enable](/endpoint/firewall_allowed_program_enable/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | Anomaly | | [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | -| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | | [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | +| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | | [NET Profiler UAC bypass](/endpoint/net_profiler_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Powershell Windows Defender Exclusion Commands](/endpoint/powershell_windows_defender_exclusion_commands/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [SLUI RunAs Elevated](/endpoint/slui_runas_elevated/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | diff --git a/docs/_stories/windows_persistence_techniques.md b/docs/_stories/windows_persistence_techniques.md index b40b5b83ea..6643cec58e 100644 --- a/docs/_stories/windows_persistence_techniques.md +++ b/docs/_stories/windows_persistence_techniques.md @@ -36,8 +36,8 @@ Maintaining persistence is one of the first steps taken by attackers after the i | [Change Default File Association](/endpoint/change_default_file_association/) | [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [Detect Path Interception By Creation Of program exe](/endpoint/detect_path_interception_by_creation_of_program_exe/) | [Path Interception by Unquoted Path](/tags/#path-interception-by-unquoted-path), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | | [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses) | TTP | -| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | | [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification), [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | +| [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | | [Logon Script Event Trigger Execution](/endpoint/logon_script_event_trigger_execution/) | [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)) | TTP | | [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP |