Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2023-09-20 12:56:51 -07:00
committed by GitHub
15 changed files with 1777 additions and 1316 deletions
+1 -1
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
@@ -5,7 +5,7 @@
"id": {
"group": null,
"name": "DA-ESS-ContentUpdate",
"version": "4.11.1"
"version": "4.12.0"
},
"author": [
{
+606 -524
View File
File diff suppressed because one or more lines are too long
+2 -2
View File
@@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 16958
build = 17107
[triggers]
reload.analytic_stories = simple
@@ -20,7 +20,7 @@ reload.es_investigations = simple
[launcher]
author = Splunk
version = 4.11.1
version = 4.12.0
description = Explore the Analytic Stories included with ES Content Updates.
[ui]
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-05T22:20:53 UTC
# On Date: 2023-09-20T19:43:15 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,2 +1,2 @@
[content-version]
version = 4.11.1
version = 4.12.0
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-05T22:20:53 UTC
# On Date: 2023-09-20T19:43:15 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+33 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-05T22:20:53 UTC
# On Date: 2023-09-20T19:43:15 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -2237,6 +2237,14 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[headless_browser_mockbin_or_mocky_request_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[headless_browser_usage_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[hide_user_account_from_sign_in_screen_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -3757,6 +3765,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_ad_abnormal_object_access_activity_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_ad_adminsdholder_acl_modified_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -3789,6 +3801,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_ad_privileged_object_access_activity_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_ad_replication_request_initiated_by_user_account_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -4125,10 +4141,22 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_find_domain_organizational_units_with_getdomainou_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_find_interesting_acl_with_findinterestingdomainacl_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_findstr_gpp_discovery_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_forest_discovery_with_getforestdomain_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_gather_victim_host_information_camera_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -4145,6 +4173,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_get_local_admin_with_findlocaladminaccess_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_group_policy_object_created_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
+1117 -775
View File
File diff suppressed because it is too large Load Diff
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-05T22:20:53 UTC
# On Date: 2023-09-20T19:43:15 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-05T22:20:53 UTC
# On Date: 2023-09-20T19:43:15 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+9 -4
View File
@@ -81,8 +81,8 @@
},
{
"techniqueID": "T1087",
"score": 29,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_account_discovery_drilldown_dashboard_disclosure.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_special_privileged_logon_on_multiple_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml"
"score": 35,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_account_discovery_drilldown_dashboard_disclosure.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_abnormal_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_privileged_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_special_privileged_logon_on_multiple_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml"
},
{
"techniqueID": "T1210",
@@ -481,8 +481,8 @@
},
{
"techniqueID": "T1087.002",
"score": 20,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml"
"score": 26,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_abnormal_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_privileged_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml"
},
{
"techniqueID": "T1547.014",
@@ -814,6 +814,11 @@
"score": 8,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_with_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_with_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_common_abused_cmd_shell_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_post_exploitation_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_network_connections_discovery_netsh.yml"
},
{
"techniqueID": "T1564.003",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/headless_browser_usage.yml"
},
{
"techniqueID": "T1222.001",
"score": 2,